Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability was identified in elecV2 elecV2P up to 3.8.3. This affects the function eAxios of the file /mock of the component URL Handler. Such manipulation of the argument req leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 21:45:11 UTC Added: 03/28/2026, 22:00:28 UTC |
0 A vulnerability was determined in elecV2 elecV2P up to 3.8.3. The impacted element is an unknown function of the file /logs of the component Endpoint. This manipulation of the argument filename causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 21:00:16 UTC Added: 03/28/2026, 21:15:26 UTC |
0 A vulnerability was found in elecV2 elecV2P up to 3.8.3. The affected element is the function path.join of the file /log/ of the component Wildcard Handler. The manipulation results in path traversal. The attack may be performed from remote. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 21:00:13 UTC Added: 03/28/2026, 21:15:26 UTC |
0 A vulnerability has been found in elecV2 elecV2P up to 3.8.3. Impacted is the function path.join of the file /store/:key. The manipulation of the argument URL leads to path traversal. The attack is possible to be carried out remotely. The exploit has been disclosed to the public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 20:00:13 UTC Added: 03/28/2026, 20:38:39 UTC |
0 A flaw has been found in elecV2 elecV2P up to 3.8.3. This issue affects the function pm2run of the file /rpc. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been published and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 19:15:11 UTC Added: 03/28/2026, 19:20:59 UTC |
0 A vulnerability was detected in elecV2 elecV2P up to 3.8.3. This vulnerability affects the function runJSFile of the file /webhook of the component JSON Parser. Performing a manipulation of the argument rawcode results in code injection. Remote exploitation of the attack is possible. The exploit is now public and may be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 03/28/2026, 18:30:15 UTC Added: 03/28/2026, 18:51:00 UTC |
0 CVE-2026-3955 is a medium-severity code injection vulnerability affecting elecV2P versions up to 3.8.3. The flaw exists in the runJSFile function within the jsfile endpoint, allowing remote attackers to inject and execute arbitrary code without authentication or user interaction. Although the vulnerability has a CVSS score of 5.3, exploitation requires low privileges but no user interaction, and impacts confidentiality, integrity, and availability to a limited extent. The vulnerability was responsibly disclosed but remains unpatched as of the publication date. No known exploits are currently observed in the wild. Organizations using elecV2P should prioritize mitigating this risk due to the potential for remote code execution. Countries with significant elecV2P usage and strategic interest in automation or IoT deployments are most at risk. Join the discussion | CVE Database V5 | 03/11/2026, 20:32:08 UTC Added: 03/11/2026, 20:44:50 UTC |
Showing 1 to 7 of 7 results