Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, the GET /forms endpoint read table and column metadata without applying the document's access rules and did not check that the requested section was actually a form. A user with only partial read access, including public access on a publicly viewable document, could request the metadata of any widget and reveal table and column structure that access rules would otherwise hide, even in documents that contain no forms. This issue is fixed in version 1.7.15. Join the discussion | CVE Database V5 | 07/10/2026, 20:59:12 UTC Added: 07/10/2026, 21:03:31 UTC |
0 Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, Grist contained two cross-site scripting vulnerabilities where an attacker-controlled value reached a link's href without scheme validation, so a javascript URL could run in a victim's Grist origin on a single click. On the account-selection page, /welcome/select-account used its next query parameter as the account buttons' link target. In document tours, the GristDocTour table's Link_URL column became a clickable button, allowing an editor of a shared document to store a javascript URL there that ran when another user opened the document and clicked the tour link. Because the script runs in the victim's authenticated session, it can call Grist APIs as the victim, reading or modifying data and changing sharing settings and access rules. A document editor could therefore escalate to owner-level access. This issue is fixed in version 1.7.15. Join the discussion | CVE Database V5 | 07/10/2026, 20:58:24 UTC Added: 07/10/2026, 21:03:31 UTC |
0 Grist is spreadsheet software using Python as its formula language. Prior to 1.7.15, several server-rendered Grist pages embedded user-controlled values into the page and into inline scripts without fully escaping them, allowing cross-site scripting. On the main application page, a document's name or description, set by a document editor, is rendered into the page that other users load when opening the document. On the OAuth2 end-of-flow page, the openerOrigin request parameter was reflected back into the served page. Injected script runs in the victim's Grist origin and can act through the authenticated session, reading or modifying data and changing sharing settings and access rules. A document editor could therefore escalate to owner-level access. This issue is fixed in version 1.7.15. Join the discussion | CVE Database V5 | 07/10/2026, 20:57:39 UTC Added: 07/10/2026, 21:03:31 UTC |
CVE-2026-24002 is a critical vulnerability in grist-core spreadsheet software versions prior to 1.7.9. It arises from improper sandboxing of Python formulas executed via pyodide on Node.js, allowing malicious spreadsheet documents to execute arbitrary processes on the server. The vulnerability is due to CWE-74, improper neutralization of special elements in output used by downstream components, leading to injection attacks. Exploitation requires no authentication or user interaction beyond opening a malicious document with the vulnerable sandbox setting. The issue is mitigated in grist-core 1.7.9 and later by running pyodide under the Deno runtime, which provides stronger sandboxing. Join the discussion | CVE Database V5 | 01/22/2026, 02:26:28 UTC Added: 01/22/2026, 02:50:57 UTC |
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with only partial read access to a document could still access endpoints listing hashes for versions of that document and receive a full list of changes between versions, even if those changes contained cells, columns, or tables to which the user was not supposed to have read access. This was fixed in version 1.7.7 by restricting the `/compare` endpoint to users with full read access. As a workaround, remove sensitive document history using the `/states/remove` endpoint. Another possibility is to block the `/compare` endpoint. Join the discussion | CVE Database V5 | 11/13/2025, 21:46:00 UTC Added: 11/13/2025, 21:50:12 UTC |
grist-core is a spreadsheet hosting server. Prior to version 1.7.7, a user with access to any document on a Grist installation can use a feature for fetching from a URL that is executed on the server. The privileged network access of server-side requests could offer opportunities for attack escalation. This issue is fixed in version 1.7.7. The mitigation was to use the proxy for untrusted fetches intended for such purposes. As a workaround, avoid making http/https endpoints available to an instance running Grist that expose credentials or operate without credentials. Join the discussion | CVE Database V5 | 11/13/2025, 21:43:57 UTC Added: 11/13/2025, 21:50:12 UTC |
Showing 1 to 6 of 6 results