Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/combodo/iTop

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Combodo iTop versions prior to 3.2.3 contain a vulnerability in the user preference functionality that allows PHP object injection, potentially leading to remote code execution. This vulnerability is identified as CWE-502 (Deserialization of Untrusted Data) and CWE-94 (Code Injection). The issue has been resolved in version 3.2.3.

Join the discussion

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, iTop is vulnerable to Reflected Cross-Site Scripting (XSS) in the dashboard revert functionality. This issue has been fixed in version 3.2.3.

Join the discussion

Combodo iTop is a web-based IT service management tool. Prior to 3.2.3, unauthenticated users could delete the .readonly file on iTop instances, leading to code execution. This file, created during the setup process, prevents users from performing write actions. This issue has been fixed in version 3.2.3.

Join the discussion

CVE-2026-34949 is a vulnerability in Combodo iTop, a web-based IT service management tool. Versions prior to 3.2.3 allow an unauthenticated user to delete the .readonly file, which is created during setup to prevent write actions. This missing authentication for a critical function could enable unauthorized modification of the system. The issue is fixed in version 3.2.3.

Join the discussion

CVE-2026-34948 is a vulnerability in Combodo iTop, a web-based IT service management tool, where sensitive information could be exposed to unauthorized actors due to incomplete access checks in Object Query Language (OQL). Versions prior to 3.2.3 are affected. The issue has been fixed in version 3.2.3.

Join the discussion

Combodo iTop versions prior to 3.2.3 contain an authorization bypass vulnerability in ajax.render.php and ajax.document.php. This flaw allows unauthorized users to access documents without proper permission checks. The issue was fixed in version 3.2.3.

Join the discussion

Combodo iTop versions prior to 3.2.3 contain a vulnerability that allows unauthenticated remote attackers to bypass authentication and execute arbitrary PHP files from the env-production directory on new iTop instances in production environments. This issue has been fixed in version 3.2.3.

Join the discussion

A vulnerability in Combodo iTop prior to version 3.2.3 allows sensitive information to be disclosed through error messages. This issue is classified under CWE-209, which involves generation of error messages containing sensitive information. The vulnerability has a low severity score and has been fixed in version 3.2.3.

Join the discussion

Combodo iTop versions prior to 3.2.3 contain a reflected Cross-Site Scripting (XSS) vulnerability in the foreign key search criteria API. This vulnerability allows an attacker to inject malicious scripts that could be executed in the context of a user's browser. The issue has been fixed in version 3.2.3.

Join the discussion

Combodo iTop is a web based IT service management tool. Prior to 3.2.3, an object can be locked by a user who is not assigned write permissions. This issue has been fixed in version 3.2.3.

Join the discussion

Showing 1 to 10 of 29 results

Filters:Package: pkg:github/combodo/iTop
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses