Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Vaultwarden versions prior to 1.35.4 contain a vulnerability that allows attackers to bypass brute-force login protections when email two-factor authentication (2FA) is enabled. The vulnerability arises because the 2FA email function send_email_login acts as an oracle to verify username-password correctness without rate limiting. This flaw enables brute-force password attempts even against accounts without email 2FA configured. The issue is fixed in version 1.35.4. The CVSS score is 7.3, indicating a high severity vulnerability. Join the discussion | CVE Database V5 | 05/11/2026, 22:03:58 UTC Added: 05/12/2026, 01:49:55 UTC |
Vaultwarden versions prior to 1.35.5 contain an improper authorization vulnerability that allows an attacker with admin privileges in one organization and low privileges in another to escalate access across organizations. The flaw arises because group-management endpoints do not verify that membership and collection IDs belong to the same organization, enabling unauthorized access and modification of vault data from another organization. This vulnerability is fixed in version 1.35.5. Join the discussion | CVE Database V5 | 05/11/2026, 21:56:30 UTC Added: 05/12/2026, 01:49:55 UTC |
Vaultwarden versions prior to 1.35.5 contain a vulnerability where refresh tokens are not invalidated after certain security-sensitive user actions, such as password changes or key rotations. This allows an attacker with a previously obtained refresh token to maintain session access despite the user attempting to secure their account. The issue is identified as insufficient session expiration (CWE-613) and has a CVSS score of 6.8 (medium severity). The vulnerability is fixed in version 1.35.5. Join the discussion | CVE Database V5 | 05/11/2026, 21:54:41 UTC Added: 05/12/2026, 01:49:55 UTC |
Vaultwarden versions 1.35.4 and earlier contain a missing authorization check in the get_org_collections_details API endpoint. This flaw allows users with Manager role but restricted access (accessAll=False and no collection assignments) to retrieve sensitive organizational collection metadata, including names, UUIDs, and user/group-to-collection mappings. The issue was resolved in version 1.35.5. Join the discussion | CVE Database V5 | 05/05/2026, 19:12:24 UTC Added: 05/05/2026, 19:36:24 UTC |
0 Vaultwarden versions 1.35.4 and earlier contain a vulnerability in the WebAuthn authentication flow where persistent credential metadata flags are updated based on unverified authenticator data before signature validation. An attacker who knows a user's password but cannot produce a valid WebAuthn signature can modify these backup flags, causing a persistent denial of service for WebAuthn two-factor authentication on that user's credential. The issue is fixed in version 1.35.5. Join the discussion | CVE Database V5 | 05/05/2026, 18:51:35 UTC Added: 05/05/2026, 19:06:26 UTC |
Vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Prior to version 1.35.4, when a Manager has manage=false for a given collection, they can still perform several management operations as long as they have access to the collection. This issue has been patched in version 1.35.4. Join the discussion | CVE Database V5 | 03/04/2026, 21:40:33 UTC Added: 03/04/2026, 22:03:18 UTC |
0 Vaultwarden v1.32.5 was discovered to contain an authenticated reflected cross-site scripting (XSS) vulnerability via the component /api/core/mod.rs. Join the discussion | CVE Database V5 | 01/09/2025, 00:00:00 UTC Added: 02/25/2026, 21:38:20 UTC |
0 An issue in the component src/api/identity.rs of Vaultwarden prior to v1.32.5 allows attackers to impersonate users, including Administrators, via a crafted authorization request. Join the discussion | CVE Database V5 | 01/09/2025, 00:00:00 UTC Added: 02/25/2026, 21:38:20 UTC |
0 An HTML injection vulnerability in Vaultwarden prior to v1.32.5 allows attackers to execute arbitrary code via injecting a crafted payload into the username field of an e-mail message. Join the discussion | CVE Database V5 | 01/09/2025, 00:00:00 UTC Added: 02/25/2026, 21:38:20 UTC |
Showing 1 to 9 of 9 results