Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73604: Exposure of Sensitive Information to an Unauthorized Actor in FlowiseAI FlowiseCVE-2026-73604 0 Flowise before 3.1.3 contains an incomplete credential redaction vulnerability in the GET /api/v1/credentials/:id endpoint that returns decrypted secrets in plaintext. Authenticated users with credentials:view permission can retrieve sensitive data including database connection URLs with embedded passwords, cloud service account JSON with private keys, and API keys by calling this endpoint. Join the discussion | CVE Database V5 | 08/13/2026, 11:28:10 UTC Added: 08/13/2026, 12:52:08 UTC |
CVE-2026-73603: Missing Authorization in FlowiseAI FlowiseCVE-2026-73603 0 Flowise before 3.1.4 fails to validate chatflow visibility in the unauthenticated text-to-speech endpoint, allowing attackers to abuse private chatflow TTS credentials. Unauthenticated attackers can generate unlimited text-to-speech audio using stored OpenAI or ElevenLabs API keys by providing a valid chatflow UUID, incurring costs on the chatflow owner's account. Join the discussion | CVE Database V5 | 08/13/2026, 12:31:09 UTC Added: 08/13/2026, 12:52:08 UTC |
CVE-2026-73487: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73487 0 Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate datasets, perform SSRF against internal services, or achieve code execution through the unauthenticated prediction API. Join the discussion | CVE Database V5 | 08/13/2026, 12:31:09 UTC Added: 08/13/2026, 12:52:07 UTC |
CVE-2026-73486: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73486 0 Flowise before 3.1.3 contains a code injection vulnerability in the CSV Agent node's customReadCSV parameter that allows authenticated attackers to execute arbitrary Python code. The validator uses a static regex blocklist that can be bypassed through obfuscation techniques, enabling attackers to execute code in the unsandboxed pyodide environment with full system access. Join the discussion | CVE Database V5 | 08/13/2026, 12:31:09 UTC Added: 08/13/2026, 12:52:07 UTC |
CVE-2026-73485: Improper Control of Generation of Code ('Code Injection') in FlowiseAI FlowiseCVE-2026-73485 0 Flowise before 3.1.3 contains a code injection vulnerability in the Airtable Agent node that allows unauthenticated attackers to execute arbitrary Python code by bypassing the pythonCodeValidator blocklist through obfuscation techniques. Attackers can send crafted prompts to a chatflow using the Airtable Agent node to inject malicious Python code that executes in an unsandboxed pyodide environment with full access to the host operating system. Join the discussion | CVE Database V5 | 08/13/2026, 12:31:09 UTC Added: 08/13/2026, 12:52:07 UTC |
CVE-2026-73484: Incomplete List of Disallowed Inputs in FlowiseAI FlowiseCVE-2026-73484 0 Flowise before 3.1.3 contains a sandbox escape vulnerability in pythonCodeValidator.ts that fails to block native Pandas DataFrame methods like to_csv, to_json, pipe, and query. Authenticated attackers can exploit this to exfiltrate uploaded CSV data or write arbitrary files to the server filesystem. Join the discussion | CVE Database V5 | 08/13/2026, 12:31:09 UTC Added: 08/13/2026, 12:52:07 UTC |
CVE-2026-71962: Missing Authorization in FlowiseAI FlowiseCVE-2026-71962 0 Flowise versions 2.2.4 through 3.1.4 contain a missing authorization vulnerability in the POST /api/v1/openai-assistants-file/download endpoint that allows unauthenticated attackers to access private files by exploiting the endpoint's inclusion in the global authentication whitelist, which bypasses all session and API key verification. Attackers can supply valid chatflowId, chatId, and fileName identifiers to retrieve files from any chatflow on the instance, including private chatflows belonging to other workspaces or organizations. Join the discussion | CVE Database V5 | 08/10/2026, 18:26:18 UTC Added: 08/10/2026, 18:42:03 UTC |
Showing 1 to 7 of 7 results