Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Dify is an open-source LLM app development platform. Prior to 1.13.0, the /console/api/remote-files/upload endpoint in api/controllers/web/remote_files.py accepted an attacker-controlled URL without authentication and caused the Dify server to retrieve it. A remote attacker could use the endpoint to send requests to internal services or cloud metadata endpoints, potentially exposing sensitive data and using the server as a network pivot. This issue is fixed in version 1.13.0. Join the discussion | CVE Database V5 | 10/05/2026, 23:04:58 UTC Added: 10/05/2026, 23:33:54 UTC |
0 Dify is an open-source LLM app development platform. Prior to 1.16.0, the PUT /console/api/apps/<app_id>/server endpoint in api/controllers/console/app/mcp_server.py used AppMCPServerController.put() to retrieve an AppMCPServer by the client-supplied server ID without verifying that the server belonged to the requested application and tenant. An authenticated workspace member could therefore change another application's MCP server status and parameters, potentially redirecting data or disabling the service. This issue is fixed in version 1.16.0. Join the discussion | CVE Database V5 | 10/05/2026, 23:03:44 UTC Added: 10/05/2026, 23:18:59 UTC |
0 Dify AI Workflow oauth_redirect_url Open Redirect Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Dify. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the OAuth flow handling in the AppInitializer component. An attacker can force a redirection to a site that serves malicious content. An attacker can leverage this vulnerability to disclose information in the context of the application. Was ZDI-CAN-29196. Join the discussion | CVE Database V5 | 07/29/2026, 19:05:20 UTC Added: 07/29/2026, 19:23:01 UTC |
0 Dify before 1.16.0-rc1 contains a SQL injection vulnerability in the MyScale vector store backend that allows attackers to execute arbitrary SQL by supplying unsanitized search parameters to the search_by_full_text method without escaping or parameterization. Attackers can inject malicious SQL through the search parameters to read, modify, or delete data in the underlying ClickHouse database. Join the discussion | CVE Database V5 | 07/10/2026, 18:10:35 UTC Added: 07/10/2026, 18:33:18 UTC |
Dify before version 1.14.2 contains an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document across all tenants and workspaces using only the file's UUID. Attackers can access the /console/api/files/{file_id}/preview endpoint with an intercepted file UUID to extract sensitive content from documents without ownership or workspace permission verification. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker. Join the discussion | CVE Database V5 | 05/18/2026, 13:52:03 UTC Added: 05/18/2026, 14:22:16 UTC |
0 Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficient URL path sanitization. Attackers can traverse out of their authorized tenant path using unencoded dot sequences in task identifiers or manipulated filename parameters to access internal endpoints such as debug interfaces, requiring only knowledge of the victim tenant's UUID. NOTE: Dify Cloud allows unauthenticated free self-registration, making account creation trivially accessible to any attacker. Join the discussion | CVE Database V5 | 05/18/2026, 13:50:21 UTC Added: 05/18/2026, 14:22:16 UTC |
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplying an arbitrary file UUID in the files array of a chat-messages request. Attackers can exploit insufficient permission verification in the chat-messages endpoints to access files without ownership validation, bypassing workspace separation and signed URL protections to retrieve sensitive file contents through workflow processing. Join the discussion | CVE Database V5 | 05/05/2026, 20:35:56 UTC Added: 05/05/2026, 20:51:52 UTC |
0 Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/files/upload, which requires authentication through the application API, is also vulnerable. This issue has been patched in version 1.13.1. Join the discussion | CVE Database V5 | 05/04/2026, 17:34:36 UTC Added: 05/04/2026, 17:51:29 UTC |
CVE-2026-34082 is a medium severity vulnerability in the open-source LLM app development platform Dify (langgenius). Before version 1.13.1, the DELETE API endpoint for removing conversations lacks proper authorization checks, allowing any authenticated user to delete chat histories belonging to other users. This issue is fixed in version 1.13.1. The vulnerability is classified under CWE-863 (Incorrect Authorization) and CWE-284 (Improper Access Control). Join the discussion | CVE Database V5 | 04/20/2026, 23:03:18 UTC Added: 04/20/2026, 23:16:06 UTC |
0 Dify is an open-source LLM app development platform. Prior to 1.11.2, Dify is vulnerable to a stored XSS issue when rendering Mermaid diagrams within chats. This occurs because Dify’s default Mermaid configuration uses securityLevel: loose, which allows potentially unsafe content to execute. This vulnerability is fixed in 1.11.2. Join the discussion | CVE Database V5 | 03/03/2026, 21:42:25 UTC Added: 03/03/2026, 22:03:17 UTC |
Showing 1 to 10 of 22 results