Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-108684 is a SQL injection vulnerability in erzhongxmu Jeewms affecting versions 3.0 through 3.7. The flaw exists in the getTreeData function of the JeecgFormDemoController.java file, specifically in the Autocomplete Data Handler component. An attacker can remotely manipulate the searchVal argument to perform SQL injection. A patch identified by commit 6e29bd57972a499e9c8a81a2dbe94d0d5cf23af0 is available to fix this issue. The vulnerability has a medium severity rating with a CVSS 4.0 score of 5.3. Join the discussion | CVE Database V5 | 10/11/2026, 14:45:14 UTC Added: 10/11/2026, 14:49:06 UTC |
0 A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the argument myEditor results in cross site scripting. The attack can be launched remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 02/23/2026, 21:02:08 UTC Added: 02/23/2026, 21:17:15 UTC |
0 JEEWMS 1.0 is vulnerable to SQL Injection. Attackers can inject malicious SQL statements through the id1 and id2 parameters in the /systemControl.do interface for attack. Join the discussion | CVE Database V5 | 02/03/2026, 00:00:00 UTC Added: 02/04/2026, 08:01:26 UTC |
0 A vulnerability, which was classified as critical, was found in JeeWMS up to 20250504. This affects the function filedeal of the file /systemController/filedeal.do of the component File Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Join the discussion | CVE Database V5 | 05/31/2025, 19:00:08 UTC Added: 05/31/2025, 19:13:39 UTC |
0 A vulnerability, which was classified as critical, has been found in JeeWMS up to 20250504. Affected by this issue is the function dogenerateOne2Many of the file /generateController.do?dogenerateOne2Many of the component File Handler. The manipulation leads to improper access controls. The attack may be launched remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Join the discussion | CVE Database V5 | 05/31/2025, 18:31:06 UTC Added: 05/31/2025, 18:43:22 UTC |
0 A vulnerability classified as critical was found in JeeWMS up to 20250504. Affected by this vulnerability is the function dogenerate of the file /generateController.do?dogenerate. The manipulation leads to sql injection. The attack can be launched remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. Join the discussion | CVE Database V5 | 05/31/2025, 18:00:09 UTC Added: 05/31/2025, 18:13:35 UTC |
0 A vulnerability classified as critical has been found in JeeWMS up to 20250504. Affected is the function dogenerate of the file /generateController.do?dogenerate of the component File Handler. The manipulation leads to improper access controls. It is possible to launch the attack remotely. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Join the discussion | CVE Database V5 | 05/31/2025, 17:31:06 UTC Added: 05/31/2025, 17:43:12 UTC |
0 A vulnerability was found in JeeWMS up to 20250504. It has been rated as critical. This issue affects the function transEditor of the file /cgformTransController.do?transEditor. The manipulation leads to sql injection. The attack may be initiated remotely. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. Join the discussion | CVE Database V5 | 05/31/2025, 17:00:07 UTC Added: 05/31/2025, 17:13:09 UTC |
0 A vulnerability was found in JeeWMS up to 20250504. It has been declared as critical. This vulnerability affects the function doAdd of the file /cgformTemplateController.do?doAdd. The manipulation leads to path traversal. The attack can be initiated remotely. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. Join the discussion | CVE Database V5 | 05/31/2025, 16:31:06 UTC Added: 05/31/2025, 16:43:12 UTC |
0 A vulnerability was found in JeeWMS up to 20250504. It has been classified as critical. This affects the function CgAutoListController of the file /cgAutoListController.do?datagrid. The manipulation leads to sql injection. It is possible to initiate the attack remotely. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. Join the discussion | CVE Database V5 | 05/31/2025, 16:00:09 UTC Added: 05/31/2025, 16:13:15 UTC |
Showing 1 to 10 of 12 results