Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Crater Invoice versions up to 6.0.6 have a path traversal vulnerability in the self-update API. Authenticated company owners can exploit this by submitting crafted ZIP archives with directory traversal sequences to the unzip endpoint. This allows writing arbitrary files outside the intended directory, including PHP files in the web-accessible public directory, potentially leading to remote code execution on the server. Join the discussion | CVE Database V5 | 08/25/2026, 12:52:11 UTC Added: 08/25/2026, 13:22:42 UTC |
0 Crater's NotePolicy checks only a blanket Bouncer ability (manage-all-notes / view-all-notes) with no company-ownership comparison, unlike InvoicePolicy and other sibling policies which additionally verify ->hasCompany(->company_id). Any authenticated user of one company can read, edit, or delete another company's notes by ID. Join the discussion | CVE Database V5 | 08/05/2026, 10:56:45 UTC Added: 08/05/2026, 11:12:01 UTC |
0 Crater isolates data per company_id, and its Invoice/Estimate/Payment/Expense policies enforce both a Bouncer ability check and ->hasCompany(->company_id). CustomerPolicy's view/update/delete methods omit the company-ownership check entirely, checking only the blanket ability. Route-model-bound customer lookups and the bulk Customer::deleteCustomers method are similarly unscoped (self::find with no company filter). Join the discussion | CVE Database V5 | 08/05/2026, 06:58:38 UTC Added: 08/05/2026, 07:27:02 UTC |
A weakness has been identified in crater-invoice-inc crater up to 6.0.6. This affects the function getFormattedString of the file app/Http/Requests/InvoicesRequest.php of the component Invoice Note Handler. Executing a manipulation of the argument notes can lead to cross site scripting. The attack may be launched remotely. The exploit has been made available to the public and could be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 07/06/2026, 02:30:11 UTC Added: 07/06/2026, 02:52:11 UTC |
0 A vulnerability in Crater Invoice allows an unauthenticated attacker with knowledge of the APP_KEY to achieve remote command execution on the server by manipulating the laravel_session cookie, exploiting arbitrary deserialization through the encrypted session data. The exploitation vector of this vulnerability relies on an attacker obtaining Laravel's secret APP_KEY, which would allow them to decrypt and manipulate session cookies (laravel_session) containing serialized data. By altering this data and re-encrypting it with the APP_KEY, the attacker could trigger arbitrary deserialization on the server, potentially leading to remote command execution (RCE). The vulnerability is primarily exploited by accessing an exposed cookie and manipulating it using the secret key to gain malicious access to the server. Join the discussion | CVE Database V5 | 01/07/2025, 00:00:00 UTC Added: 02/25/2026, 21:38:24 UTC |
Showing 1 to 5 of 5 results