Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/fuyang_lipengjun/platform

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Huly Platform through 0.7.423, fixed in commit 68cbf8a contains an authenticated server-side request forgery vulnerability in the /import endpoint of front pod that allows workspace users to make arbitrary server requests. Attackers can exploit this by supplying malicious URLs to fetch internal services, exfiltrate responses, and replay credentials against backend systems.

Join the discussion

CVE-2026-5379 is an authorization vulnerability in the runZero Platform that allowed MCP agents to access certificate information beyond their authorized organizational scope. This issue is classified as CWE-863: Incorrect Authorization. The vulnerability has a low CVSS score of 3.0 and was fixed in version 4.0.260203.0 of the runZero Platform.

Join the discussion

CVE-2026-5376 is a medium severity vulnerability in the runZero Platform where session inactivity timeouts may fail to trigger due to automatic page reloading. This is classified as CWE-613, indicating insufficient control of resources after expiration or release. The issue could allow continued access beyond intended session limits, impacting confidentiality and integrity but not availability. The vulnerability has been fixed in version 4.0.260203.0 of the runZero Platform. No known exploits are reported in the wild. Patch status is confirmed by the vendor's version update, though no direct patch link or advisory text is provided.

Join the discussion

CVE-2026-5372 is a medium severity SQL injection vulnerability in the runZero Platform version 4.0.260123.0. It involves improper neutralization of special elements in saved queries, allowing an attacker with high privileges and user interaction to potentially execute unauthorized SQL commands. The issue was fixed in version 4.0.260123.1.

Join the discussion
CVE-2025-57213: n/aCVE-2025-57213
0

Incorrect access control in the component orderService.queryObject of platform v1.0.0 allows attackers to access sensitive information via a crafted request.

Join the discussion
0

A weakness has been identified in lsfusion platform up to 6.1. This vulnerability affects the function unpackFile of the file server/src/main/java/lsfusion/server/physics/dev/integration/external/to/file/ZipUtils.java. This manipulation causes path traversal. It is possible to initiate the attack remotely.

Join the discussion
0

A vulnerability was determined in lsfusion platform up to 6.1. Affected by this vulnerability is the function UploadFileRequestHandler of the file platform/web-client/src/main/java/lsfusion/http/controller/file/UploadFileRequestHandler.java. Executing manipulation of the argument sid can lead to path traversal. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized.

Join the discussion
0

A vulnerability was found in lsfusion platform up to 6.1. Affected is the function DownloadFileRequestHandler of the file web-client/src/main/java/lsfusion/http/controller/file/DownloadFileRequestHandler.java. Performing manipulation of the argument Version results in path traversal. Remote exploitation of the attack is possible. The exploit has been made public and could be used.

Join the discussion
CVE-2025-61876: n/aCVE-2025-61876
0

Insecure Direct Object Reference (IDOR) in /tenants/{id} API endpoint in Inforcer Platform version 2.0.153 allows an authenticated user with low privileges to enumerate and access tenant information belonging to other clients via modification of the tenant ID in the request URL.

Join the discussion
CVE-2024-49211: n/aCVE-2024-49211
0

Reflected XSS was discovered in a Dashboard Listing Archer Platform UX page in Archer Platform 6.x before version 2024.08. A remote unauthenticated attacker could potentially exploit this by tricking a victim application user into supplying malicious HTML or JavaScript code to the vulnerable web application; the malicious code is then reflected back to the victim and executed by the web browser in the context of the vulnerable web application.

Join the discussion

Showing 1 to 10 of 12 results

Filters:Package: pkg:github/fuyang_lipengjun/platform
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses