Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Froxlor versions prior to 2.3.12 have a vulnerability in the DirProtections.listing API command that allows authenticated API users to retrieve bcrypt password hashes from htpasswd files. This exposure enables offline cracking attempts and risks credential reuse compromise. Join the discussion | GCVE Database | 09/26/2026, 15:31:24 UTC Added: 09/27/2026, 04:30:14 UTC |
0 Froxlor versions 2.0.0 through 2.3.10 contain a stored cross-site scripting (XSS) vulnerability. This occurs when a customer uploads an SSL certificate, and the issuer organization field is stored without sanitization. The vulnerability allows attacker-supplied script to execute in the session of privileged users such as administrators or resellers. Exploitation can lead to full administrator account takeover and potential root command execution on the managed server. The issue is resolved in Froxlor version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:24 UTC Added: 09/27/2026, 04:30:14 UTC |
Froxlor versions through 2.3.10 have an issue where sensitive columns, specifically the dkim_privkey field, are not filtered from API responses in certain domain-related API calls. This allows authenticated non-superadmin admins with the delegated customers_see_all flag to access DKIM private keys of other tenants' domains. The vulnerability enables unauthorized reading of private signing keys, which could be used to sign emails that pass DKIM verification and DMARC alignment. The issue was fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:17 UTC |
froxlor versions up to 2.3.10 contain a vulnerability where an unauthenticated GET request to the two-factor authentication (2FA) management page disables a user's 2FA without confirmation or re-authentication. This occurs because the global CSRF protection does not cover GET requests, and the session cookie's SameSite=Lax setting allows cross-site navigation to carry the session, enabling silent 2FA disablement. Both customer and admin 2FA handlers are affected. The issue is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:17 UTC |
0 Froxlor versions 2.3.10 and earlier have a time-of-check time-of-use (TOCTOU) race condition in the SSH key synchronization cron job. This flaw allows a local user with shell access to exploit a race between symlink validation and file write operations, potentially leading to root-level compromise of the host running the Froxlor panel. The vulnerability is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:17 UTC |
Froxlor versions up to and including 2.3.10 have a critical vulnerability where the system.letsencryptchallengepath setting is not properly restricted or escaped. This allows an administrator or any actor able to write settings to inject arbitrary command-line options into the acme.sh command executed by root via cron, leading to arbitrary command execution or file writes as root. The issue is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:15 UTC |
0 Froxlor versions up to 2.3.10 have a vulnerability where the mail.allow_external_domains policy is not enforced in the EmailSender.add API command. This allows an authenticated customer with API access to register arbitrary external sender addresses despite policy settings that should prevent this. The issue creates a bypass between the administrator UI configuration and the API, enabling sender spoofing by authorizing sender identities outside the hosted domains. The vulnerability is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:15 UTC |
Froxlor versions through 2.3.10 have a vulnerability in their two-factor authentication (2FA) remembered-token mechanism. The system stores only a numeric user ID in remembered-2FA tokens without recording the account namespace, causing token lookups to be ambiguous between customer and administrator accounts. This allows an attacker who controls a customer account with a colliding ID and a valid remembered-2FA token, and who knows the administrator's password, to bypass the administrator's TOTP second factor and gain an authenticated administrator session. This vulnerability affects only the second-factor authentication step and does not bypass password authentication. The issue is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:15 UTC |
In froxlor versions 2.3.10 and earlier, the URL validation function Validate::validateUrl does not properly inspect the userinfo component of URLs for carriage return and line feed characters. This allows an authenticated low-privilege user with subdomain creation rights to inject malicious payloads into the web server configuration. The injected directives can execute with root privileges, enabling server-wide impact such as response hijacking or local file reading. The vulnerability is fixed in version 2.3.12. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:15 UTC |
Froxlor versions before 2.3.13 expose the raw PEM TLS private key content in JSON API responses for certificate-related commands. This occurs because the ssl_key_file column is returned verbatim without filtering, allowing low-privileged authenticated API users to access private keys of their own domains. Reseller and admin accounts with broader privileges can access private keys of other users. Exposure of these private keys can lead to domain impersonation, passive decryption of TLS traffic, and man-in-the-middle attacks. Join the discussion | GCVE Database | 09/26/2026, 15:31:23 UTC Added: 09/27/2026, 04:30:15 UTC |
Showing 1 to 10 of 15 results