Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-76846: Insufficiently Protected Credentials in getgrav gravCVE-2026-76846 0 Grav before 2.0.16 contains an incomplete default denylist in the Twig sandbox configuration that fails to block access to system configuration secrets. Attackers with page-edit permission can use config.get() or config.toArray() in Twig templates to retrieve sensitive values like system.cache.redis.password when config_access is enabled. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:31 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-76839: Insufficiently Protected Credentials in getgrav gravCVE-2026-76839 0 Grav before 2.0.16 allows sandboxed Twig templates to access sensitive User fields through allow-listed offsetGet() and offsetexists() methods that lack field filtering. Attackers with page-edit permissions can call offsetGet() on User objects to extract hashed passwords and 2FA secrets, enabling offline password cracking and authentication bypass. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:31 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-72702: Origin Validation Error in getgrav gravCVE-2026-72702 0 Grav CMS before 2.0.16 contains an origin validation bypass in the Uri::referrer() and Pages::referrerRoute() methods, which validate the Referer header using an unanchored string prefix match (str_starts_with($referrer, $base)) with no trailing delimiter. An attacker who controls a domain that begins with the victim site's origin (e.g. https://example.com.attacker.tld) can send a request with such a Referer to be treated as same-origin, bypassing the Referer-based origin check. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:25 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-72701: Observable Timing Discrepancy in getgrav gravCVE-2026-72701 0 Grav CMS before 2.0.16 contains a timing vulnerability in Utils::verifyNonce() that uses non-constant-time string comparison with the === operator instead of hash_equals() for CSRF nonce validation. Attackers can measure response timing differences to recover valid nonce values byte-by-byte through multiple requests, weakening CSRF protection below its intended security margin. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:23 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-72698: Exposure of Sensitive Information to an Unauthorized Actor in getgrav gravCVE-2026-72698 0 Grav CMS before 2.0.16 fails to filter system, site, and theme configuration arrays in sandboxed Twig renders, allowing content editors to read sensitive configuration values. Attackers with page-content edit access can access raw configuration arrays including secrets like cache credentials by using dot notation in Twig templates, bypassing the config_denied_paths restrictions. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:21 UTC Added: 08/25/2026, 01:52:59 UTC |
CVE-2026-72697: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in getgrav gravCVE-2026-72697 0 Grav CMS before 2.0.16 contains a path traversal vulnerability in the media_directory() Twig function that fails to validate filesystem paths, allowing authenticated users to enumerate and access files outside intended scope. Attackers with page authoring privileges can supply arbitrary filesystem paths to media_directory() and use the allow-listed filepath accessor on Medium objects to read file contents of any file matching configured media extensions that the web server process can access. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:18 UTC Added: 08/25/2026, 01:52:58 UTC |
CVE-2026-72695: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in getgrav gravCVE-2026-72695 0 Grav before 2.0.16 contains a path traversal vulnerability in MediaUploadTrait::deleteFile() that allows authenticated users with media management permissions to delete arbitrary files by supplying filenames with directory traversal sequences. The method validates only the basename portion of the filename while preserving unvalidated directory paths containing ../ sequences that are passed to unlink(), enabling deletion of files outside the intended media storage directory. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:11 UTC Added: 08/25/2026, 01:52:58 UTC |
CVE-2026-56709: Reliance on Reverse DNS Resolution for a Security-Critical Action in getgrav gravCVE-2026-56709 0 Grav before 3.9.2 fails to validate untrusted Host headers in the sendInvitationEmail() function when constructing token-bearing invitation links. Attackers can manipulate the Host header to poison invitation links and redirect users to attacker-controlled domains, bypassing the require_trusted_host protection which only covers password reset flows. Join the discussion | CVE Database V5 | 08/25/2026, 01:30:10 UTC Added: 08/25/2026, 01:52:58 UTC |
CVE-2026-64850: CWE-94: Improper Control of Generation of Code ('Code Injection') in getgrav gravCVE-2026-64850 0 Grav is a file-based Web platform. Prior to 2.0.7, Grav Blueprint::dynamicData() in system/src/Grav/Common/Data/Blueprint.php sends an editor-controlled Class::method provider and arguments to call_user_func_array() without rejecting dangerous callback parameters. An account with admin.pages or api.pages.write can use Grav\Common\Utils::arrayFilterRecursive() as a trampoline with system as the callback, place a command in page frontmatter, and execute that command as the web server user when the page is viewed. This issue is fixed in version 2.0.7. Join the discussion | CVE Database V5 | 08/19/2026, 15:58:02 UTC Added: 08/19/2026, 16:08:13 UTC |
CVE-2026-62673: CWE-178: Improper Handling of Case Sensitivity in getgrav gravCVE-2026-62673 0 Grav is a file-based Web platform. Prior to 2.0.4, the Grav .htaccess and webserver-configs/htaccess.txt security rules omit the Apache [NC] flag and therefore compare sensitive directory and file-extension patterns case-sensitively. On a case-insensitive filesystem, an unauthenticated requester can use uppercase directory or extension variants to bypass the rules and retrieve files under user/accounts or user/config, including password hashes and security configuration. This issue is fixed in version 2.0.4. Join the discussion | CVE Database V5 | 08/19/2026, 15:46:59 UTC Added: 08/19/2026, 16:08:13 UTC |
Showing 1 to 10 of 26 results