Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability was determined in dgtlmoon Changedetection.io up to 0.55.8. This issue affects the function setCurrentSelectedText of the file changedetectionio/static/js/visual-selector.js of the component Visual Selector. Executing a manipulation of the argument s can lead to cross site scripting. The attack can be launched remotely. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.60.1 is capable of addressing this issue. This patch is called aac6fcfa594f17511b8ff73e5eaa4f6c33899de0. It is suggested to upgrade the affected component. Join the discussion | CVE Database V5 | 09/22/2026, 17:45:11 UTC Added: 09/22/2026, 18:03:29 UTC |
A vulnerability was found in dgtlmoon changedetection.io up to 50389b07. This vulnerability affects the function add_watch_ui_snapshot of the file changedetectionio/blueprint/add_watch_ui/__init__.py of the component Preview Endpoint. Performing a manipulation of the argument url results in server-side request forgery. The attack can be initiated remotely. The exploit has been made public and could be used. Upgrading to version 0.60.1 is able to resolve this issue. The patch is named 71d332d5a0d3da2a0fe89a392413bf4b7d27c84e. The affected component should be upgraded. Was fixed upstream. Join the discussion | CVE Database V5 | 09/22/2026, 17:15:11 UTC Added: 09/22/2026, 17:33:23 UTC |
changedetection.io versions up to and including 0.60.6 contain a Server-Side Request Forgery (SSRF) vulnerability. This flaw allows unauthenticated attackers to supply arbitrary internal URLs via the Goto URL action in browser steps, potentially accessing restricted internal network resources. The vulnerability arises from insufficient validation of the optional_value parameter. The CVSS 4.0 base score is 8.7, indicating high severity. Join the discussion | CVE Database V5 | 09/16/2026, 20:33:00 UTC Added: 09/16/2026, 20:47:33 UTC |
0 changedetection.io versions up to 0.60.6 contain a cross-site scripting (XSS) vulnerability due to improper escaping of scraped page titles in HTML notifications. This allows attackers to inject arbitrary markup into notification channels such as email and Telegram when the watch_title token is used in templates. The vulnerability has a low severity score and no known exploits in the wild. Join the discussion | CVE Database V5 | 09/16/2026, 20:32:59 UTC Added: 09/16/2026, 20:47:33 UTC |
0 changedetection.io's /login route checks the submitted password against a single PBKDF2-HMAC-SHA256 hash with no per-IP or per-session rate limiting, failed-attempt counter, or lockout (no rate-limiting library is present in requirements.txt). Join the discussion | CVE Database V5 | 08/05/2026, 06:59:03 UTC Added: 08/05/2026, 07:27:07 UTC |
changedetection.io's /settings save handler builds an update dict from form.data['application'] and blind-merges it into the stored application settings via .update. Join the discussion | CVE Database V5 | 08/05/2026, 06:59:00 UTC Added: 08/05/2026, 07:27:07 UTC |
0 changedetection.io's REST API resources are protected by an @auth.check_token decorator validating the caller's x-api-key header, except the Spec resource registered at /api/v1/full-spec (changedetectionio/api/Spec.py), whose get method carries neither @auth.check_token nor @validate_openapi_request. Join the discussion | CVE Database V5 | 08/05/2026, 06:58:56 UTC Added: 08/05/2026, 07:27:07 UTC |
0 CVE-2026-43891 is a high-severity vulnerability in changedetection.io versions prior to 0.55.1. It involves external control of file name or path during the backup restore process. An attacker can craft a backup ZIP archive with maliciously controlled snapshot paths that, when restored, cause the application to copy attacker-controlled files into the live datastore. This leads to the application parsing and returning contents of targeted local files, potentially exposing sensitive data. The vulnerability is fixed in version 0.55.1. Join the discussion | CVE Database V5 | 05/12/2026, 16:56:33 UTC Added: 05/12/2026, 17:37:40 UTC |
0 changedetection.io is a free open source web page change detection tool. In 0.54.9 and earlier, xpath_filter() switches to XML mode for XML/RSS content and creates etree.XMLParser(strip_cdata=False) without explicitly disabling external entity resolution, external DTD loading, or network-backed entity lookup. The helper then parses untrusted XML bytes directly with etree.fromstring(...). Join the discussion | CVE Database V5 | 05/12/2026, 16:52:23 UTC Added: 05/12/2026, 17:37:38 UTC |
changedetection.io is a free open source web page change detection tool. Prior to 0.54.8, the @login_optionally_required decorator is placed before (outer to) @blueprint.route() instead of after it. In Flask, @route() must be the outermost decorator because it registers the function it receives. When the order is reversed, @route() registers the original undecorated function, and the auth wrapper is never in the call chain. This silently disables authentication on these routes. This vulnerability is fixed in 0.54.8. Join the discussion | CVE Database V5 | 04/07/2026, 14:55:24 UTC Added: 04/07/2026, 15:31:16 UTC |
Showing 1 to 10 of 19 results