Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A vulnerability was identified in feelec-yishu feelcrm-os 1.0.0. This vulnerability affects the function GroupController::index of the file App/Feelcrm/Index/Controller/GroupController.class.php of the component Department Search Endpoint. The manipulation of the argument keyword leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and might be used. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 10/05/2026, 10:45:11 UTC Added: 10/05/2026, 10:49:26 UTC |
CVE-2026-105290 is a server-side request forgery (SSRF) vulnerability in feelcrm-os version 1.0.0. The flaw exists in the getCurlData endpoint within the GoogleController.class.php file. An attacker can remotely manipulate the 'url' argument to cause the server to make unauthorized requests. The vulnerability has a medium severity with a CVSS score of 6.9. The issue was reported to the project but no response or patch has been provided yet. Public exploit details are available, though no active exploitation in the wild is confirmed. Join the discussion | CVE Database V5 | 10/05/2026, 10:30:15 UTC Added: 10/05/2026, 10:49:26 UTC |
0 CVE-2026-105289 is a cross-site scripting (XSS) vulnerability in feelcrm-os version 1.0.0. The issue exists in the htmlspecialchars_decode function within the Create Customer Endpoint, specifically in the file App/Feelcrm/Common/Model/CrmDefineFormModel.class.php. An attacker can remotely manipulate the customer_form[remark] argument to execute XSS attacks. The vulnerability has a medium severity score of 5.1 and an exploit has been publicly disclosed. The vendor has been informed but has not yet responded or issued a patch. Join the discussion | CVE Database V5 | 10/05/2026, 10:15:16 UTC Added: 10/05/2026, 10:49:26 UTC |
0 CVE-2026-105288 is a cross-site scripting (XSS) vulnerability in feelcrm-os version 1.0.0. The flaw exists in the IndexController::index function within the App/ThinkPHP/Common/functions.php file, specifically in the handling of the redirect_url argument. This vulnerability allows remote attackers to inject malicious scripts. The issue has been publicly disclosed, but the vendor has not yet responded or provided a fix. Join the discussion | CVE Database V5 | 10/05/2026, 10:00:10 UTC Added: 10/05/2026, 10:18:59 UTC |
0 CVE-2026-105287 is a medium severity SQL injection vulnerability in feelcrm-os version 1.0.0. The flaw exists in the getMemberByGroups endpoint within the file App/Feelcrm/Crm/Controller/AjaxRequestController.class.php. It allows remote attackers to manipulate the groups[] argument to perform SQL injection. An exploit has been published, but no vendor response or patch is currently available. Join the discussion | CVE Database V5 | 10/05/2026, 09:45:12 UTC Added: 10/05/2026, 10:03:51 UTC |
Showing 1 to 5 of 5 results