Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Netmaker versions up to 1.6.0 disable TLS certificate verification when connecting to the configured mail server. This unconditional skip of certificate validation allows an attacker positioned between Netmaker and its mail relay to intercept and read sensitive emails, including password reset tokens and user invitations. The vulnerability arises because no configuration or code path enforces certificate verification in production, exposing sensitive data in transit. Join the discussion | CVE Database V5 | 08/26/2026, 15:45:01 UTC Added: 08/26/2026, 15:53:01 UTC |
Netmaker makes networks with WireGuard. Prior to version 1.5.0, a user assigned the platform-user role can retrieve WireGuard private keys of all wireguard configs in a network by calling GET /api/extclients/{network} or GET /api/nodes/{network}. While the Netmaker UI restricts visibility, the API endpoints return full records, including private keys, without filtering based on the requesting user's ownership. This issue has been patched in version 1.5.0. Join the discussion | CVE Database V5 | 03/07/2026, 16:15:08 UTC Added: 03/07/2026, 16:31:11 UTC |
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the user update handler (PUT /api/users/{username}) lacks validation to prevent an admin-role user from assigning the super-admin role during account updates. While the code correctly blocks an admin from assigning the admin role to another user, it does not include an equivalent check for the super-admin role. This issue has been patched in version 1.5.0. Join the discussion | CVE Database V5 | 03/07/2026, 16:14:06 UTC Added: 03/07/2026, 16:31:11 UTC |
Netmaker makes networks with WireGuard. Prior to version 1.5.0, the Authorize middleware in Netmaker incorrectly validates host JWT tokens. When a route permits host authentication (hostAllowed=true), a valid host token bypasses all subsequent authorization checks without verifying that the host is authorized to access the specific requested resource. Any entity possessing knowledge of object identifiers (node IDs, host IDs) can craft a request with an arbitrary valid host token to access, modify, or delete resources belonging to other hosts. Affected endpoints include node info retrieval, host deletion, MQTT signal transmission, fallback host updates, and failover operations. This issue has been patched in version 1.5.0. Join the discussion | CVE Database V5 | 03/07/2026, 16:12:51 UTC Added: 03/07/2026, 16:16:11 UTC |
Netmaker makes networks with WireGuard. Prior to version 1.2.0, the /api/server/shutdown endpoint allows termination of the Netmaker server process via syscall.SIGINT. This allows any user to repeatedly shut down the server, causing cyclic denial of service with approximately 3-second restart intervals. This issue has been patched in version 1.2.0. Join the discussion | CVE Database V5 | 03/07/2026, 15:14:38 UTC Added: 03/07/2026, 15:31:10 UTC |
Showing 1 to 5 of 5 results