Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/freysolareye/OpenEclass

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-24669 is a high-severity vulnerability in the Open eClass platform versions prior to 4.2, caused by insufficient session expiration in the password reset mechanism. It allows local attackers to reuse a valid password reset token after it has already been used, enabling unauthorized password changes and potential account takeover. Exploitation requires local access and user interaction but no privileges. The vulnerability impacts confidentiality, integrity, and availability of user accounts. A patch is available in version 4.2. European organizations using Open eClass should prioritize upgrading to mitigate risks. Countries with significant academic and research institutions using Open eClass are most at risk. No known exploits are currently reported in the wild.

Join the discussion

CVE-2026-24668 is an improper access control vulnerability in the Open eClass platform versions prior to 4.2. Authenticated students can exploit this flaw to add content to existing course units, an action normally restricted to instructors or administrators. The vulnerability does not affect confidentiality or availability but allows unauthorized modification of course content, impacting data integrity. It requires authentication but no user interaction beyond login, and can be exploited remotely over the network. The issue has been patched in version 4.2. European educational institutions using vulnerable versions are at risk of unauthorized content manipulation, which could undermine course integrity and trust. Mitigation involves upgrading to version 4.2 or later and auditing user permissions.

Join the discussion

CVE-2026-24667 is a medium-severity vulnerability in the Open eClass platform versions prior to 4.2, where active user sessions are not invalidated after a password change. This insufficient session expiration (CWE-613) allows attackers who have access to existing session tokens to maintain unauthorized access even after the user updates their password. The vulnerability does not require user interaction but does require low privileges and has a network attack vector with high attack complexity. It impacts confidentiality, integrity, and availability to a limited extent. The issue has been patched in version 4.2, and no known exploits are currently reported in the wild. European organizations using Open eClass should prioritize upgrading to the patched version to mitigate risks associated with session hijacking post-password change.

Join the discussion

CVE-2026-24666 is a Cross-Site Request Forgery (CSRF) vulnerability affecting Open eClass versions prior to 4.2. This vulnerability allows attackers to trick authenticated teachers into executing unintended actions, such as modifying assignment grades, by sending crafted requests. The flaw exists in multiple teacher-restricted endpoints and requires the victim to be authenticated and interact with a malicious link or page. The vulnerability has been patched in version 4.2. With a CVSS score of 6.5, it is classified as medium severity. There are no known exploits in the wild currently. European educational institutions using Open eClass versions before 4.

Join the discussion

CVE-2026-24665 is a high-severity stored Cross-Site Scripting (XSS) vulnerability in the Open eClass platform versions prior to 4.2. Authenticated students can inject malicious JavaScript code into uploaded assignment files, which executes when instructors view these submissions. This vulnerability allows attackers to compromise the confidentiality and integrity of instructor sessions, potentially leading to credential theft or unauthorized actions within the platform. The flaw requires authentication and user interaction (instructor viewing the submission) but can have a widespread impact due to the sensitive academic environment. The issue has been patched in version 4.2, and no known exploits are currently reported in the wild. European educational institutions using Open eClass should prioritize upgrading to mitigate this risk. Countries with significant adoption of Open eClass and large academic sectors are most at risk. Immediate mitigation involves patching, restricting file upload types, and monitoring for suspicious activity.

Join the discussion

CVE-2026-24774 is a medium severity business logic vulnerability in the Open eClass platform versions prior to 4.2. Authenticated students can exploit this flaw to mark themselves as present in attendance activities, including those that have already expired, by manipulating a crafted URL. This improper enforcement of behavioral workflow (CWE-841) does not impact confidentiality or availability but affects the integrity of attendance records. The vulnerability requires low attack complexity and no user interaction beyond authentication. It has not been observed exploited in the wild and was patched in version 4.2. European educational institutions using Open eClass versions before 4.2 are primarily at risk. Mitigation involves upgrading to version 4.

Join the discussion

CVE-2026-24773 is a high-severity Insecure Direct Object Reference (IDOR) vulnerability in the Open eClass platform versions prior to 4.2. It allows unauthenticated remote attackers to bypass authorization controls by manipulating user-controlled keys to access personal files of other users. The vulnerability arises from predictable user identifiers that can be directly requested without proper access checks. Exploitation does not require authentication or user interaction and impacts confidentiality but not integrity or availability. The issue has been patched in version 4.2. European educational institutions using Open eClass versions before 4.2 are at risk, especially in countries with widespread adoption of this platform. Organizations should upgrade to version 4.

Join the discussion

CVE-2026-24674 is a Reflected Cross-Site Scripting (XSS) vulnerability in the Open eClass platform versions prior to 4.2. It allows remote attackers to execute arbitrary JavaScript in the context of authenticated users by crafting malicious URLs and tricking victims into clicking them. The vulnerability affects the web page generation process where user input is not properly neutralized. The issue has been patched in version 4.2. Exploitation requires user interaction and has a medium CVSS score of 4.7. While no known exploits are reported in the wild, the vulnerability poses risks to confidentiality and integrity of user sessions. European educational institutions using Open eClass versions before 4.

Join the discussion

CVE-2026-24673 is a medium-severity vulnerability in the Open eClass platform versions prior to 4.2 that allows attackers to bypass file upload restrictions by embedding disallowed file types inside ZIP archives. The platform’s built-in decompression extracts these files without proper validation, enabling potentially dangerous file uploads. Although the vulnerability does not directly impact confidentiality or availability, it can lead to integrity issues if malicious files are uploaded and executed. Exploitation requires network access and low privileges but no user interaction. The issue has been patched in version 4.2. European educational institutions using vulnerable Open eClass versions should prioritize updating to mitigate risks. Countries with widespread adoption of Open eClass and significant educational infrastructure are most at risk. Mitigations include upgrading to version 4.

Join the discussion

CVE-2026-24672 is a high-severity Stored Cross-Site Scripting (XSS) vulnerability in the Open eClass platform versions prior to 4.2. Authenticated students can inject malicious JavaScript into user profile fields, which executes when other users with viewing privileges access the affected pages. This vulnerability can lead to the compromise of user confidentiality and integrity, such as session hijacking or unauthorized actions on behalf of users. The vulnerability requires authentication and user interaction (viewing the affected profile pages) but does not impact availability. The issue has been patched in version 4.2, and no known exploits are currently reported in the wild. European educational institutions using Open eClass versions below 4.2 are at risk, especially in countries with widespread adoption of this platform. Mitigation involves upgrading to version 4.

Join the discussion

Showing 1 to 10 of 16 results

Filters:Package: pkg:github/freysolareye/OpenEclass
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses