Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
FreePBX versions prior to 17.0.8 contain a vulnerability in the api module's OAuth2 implementation where client credentials are not properly validated during token issuance. Specifically, the validateClient() method in ClientRepository.php always returns true, allowing an attacker who knows a valid client_id to obtain OAuth2 access tokens without the correct client_secret. This weakness enables unauthorized access to the system's OAuth2 tokens. The issue is fixed in version 17.0.8. Join the discussion | CVE Database V5 | 05/29/2026, 12:46:22 UTC Added: 05/29/2026, 13:48:38 UTC |
CVE-2026-44238 is a high-severity SQL injection vulnerability in the FreePBX CDR Reports module page. It affects versions prior to 16.0.50 and versions from 17.0.1 up to but not including 17.0.11. The vulnerability allows SQL injection via the order and sort POST parameters. Exploitation requires authentication with a FreePBX Administration Control Panel account that has access to the CDR section, but full administrator privileges are not necessary. Join the discussion | CVE Database V5 | 05/29/2026, 12:44:26 UTC Added: 05/29/2026, 13:48:38 UTC |
FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST['rawname'] parameter is concatenated into an include() call with a .class.php suffix, allowing path traversal via ../ sequences to include arbitrary .class.php files from the filesystem. The included file's PHP code executes before the subsequent class instantiation error occurs. This vulnerability is fixed in 16.0.22 and 17.0.5. Join the discussion | CVE Database V5 | 05/29/2026, 12:42:32 UTC Added: 05/29/2026, 13:48:38 UTC |
0 FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup contains carefully crafted hostile data. During backup restore operations, FreePBX extracts selected files from a user-supplied tar archive. If a malicious file exists in the archive, it is read and passed directly to unserialize() without validation, class restrictions, or integrity checks. This issue allows Remote Code Execution during restoration of the backup as the web server user (typically asterisk or www-data). The attack does not require shell access, CLI access, or filesystem write permissions beyond the normal restore workflow. Authentication with a known username that has sufficient access permissions and/or write access to backup files is required. This issue has been fixed in versions 16.0.71 and 17.0.6. Join the discussion | CVE Database V5 | 05/18/2026, 20:49:04 UTC Added: 05/18/2026, 21:21:39 UTC |
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, multiple command injection vulnerabilities exist in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5. Join the discussion | CVE Database V5 | 03/05/2026, 18:25:54 UTC Added: 03/05/2026, 18:54:35 UTC |
FreePBX is an open source IP PBX. Prior to versions 16.0.10 and 17.0.5, the FreePBX logfiles module contains several authenticated SQL injection vulnerabilities. This issue has been patched in versions 16.0.10 and 17.0.5. Join the discussion | CVE Database V5 | 03/05/2026, 18:24:50 UTC Added: 03/05/2026, 18:54:35 UTC |
FreePBX is an open source IP PBX. Prior to versions 16.0.49 and 17.0.7, FreePBX module cdr (Call Data Record) is vulnerable to SQL query injection. This issue has been patched in versions 16.0.49 and 17.0.7. Join the discussion | CVE Database V5 | 03/05/2026, 18:24:06 UTC Added: 03/05/2026, 18:54:35 UTC |
FreePBX is an open source IP PBX. From versions 16.0.17.2 to before 16.0.20 and from version 17.0.2.4 to before 17.0.5, a command injection vulnerability exists in FreePBX when using the ElevenLabs Text-to-Speech (TTS) engine in the recordings module. This issue has been patched in versions 16.0.20 and 17.0.5. Join the discussion | CVE Database V5 | 03/05/2026, 18:22:38 UTC Added: 03/05/2026, 18:54:35 UTC |
Showing 1 to 8 of 8 results