Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Lychee is a free, open-source photo-management tool. Prior to 7.5.4, a SQL operator-precedence bug in SharingController::listAll() causes the orWhereNotNull('user_group_id') clause to escape the ownership filter applied by the when() block. Any authenticated non-admin user with upload permission who owns at least one album can retrieve all user-group-based sharing permissions across the entire instance, including private albums owned by other users. This vulnerability is fixed in 7.5.4. Join the discussion | CVE Database V5 | 04/09/2026, 16:14:56 UTC Added: 04/09/2026, 16:35:50 UTC |
0 Lychee versions prior to 7.5.3 contain a cross-site scripting (XSS) vulnerability in the photo description field. This field is stored without HTML sanitization and rendered unescaped in RSS, Atom, and JSON feed templates. The publicly accessible /feed endpoint allows any RSS reader to execute attacker-controlled JavaScript. The issue is fixed in version 7.5.3. Join the discussion | CVE Database V5 | 03/26/2026, 20:25:44 UTC Added: 03/26/2026, 20:29:50 UTC |
Lychee is a free, open-source photo-management tool. Prior to version 7.5.2, the SSRF protection in `PhotoUrlRule.php` can be bypassed using DNS rebinding. The IP validation check (line 86-89) only activates when the hostname is an IP address. When a domain name is used, `filter_var($host, FILTER_VALIDATE_IP)` returns `false`, skipping the entire check. Version 7.5.2 patches the issue. Join the discussion | CVE Database V5 | 03/26/2026, 20:04:18 UTC Added: 03/27/2026, 18:04:03 UTC |
Lychee is a free, open-source photo-management tool. The patch introduced for GHSA-cpgw-wgf3-xc6v (SSRF via `Photo::fromUrl`) contains an incomplete IP validation check that fails to block loopback addresses and link-local addresses. Prior to version 7.5.1, an authenticated user can still reach internal services using direct IP addresses, bypassing all four protection configuration settings even when they are set to their secure defaults. Version 7.5.1 contains a fix for the issue. Join the discussion | CVE Database V5 | 03/26/2026, 20:01:19 UTC Added: 03/27/2026, 18:04:03 UTC |
Lychee is a free, open-source photo-management tool. Prior to 7.1.0, an authorization vulnerability exists in Lychee's album password unlock functionality that allows users to gain possibly unauthorized access to other users' password-protected albums. When a user unlocks a password-protected public album, the system automatically unlocks ALL other public albums that share the same password, resulting in a complete authorization bypass. This vulnerability is fixed in 7.1.0. Join the discussion | CVE Database V5 | 01/12/2026, 18:37:55 UTC Added: 01/12/2026, 18:53:46 UTC |
0 Cross-site Request Forgery (CSRF) vulnerability in Lychee version 3.1.6, allows remote attackers to execute arbitrary code via the create new album function. Join the discussion | CVE Database V5 | 03/22/2024, 00:00:00 UTC Added: 02/25/2026, 21:45:19 UTC |
0 Cross Site Scripting (XSS) vulnerability in Lychee 3.1.6, allows remote attackers to execute arbitrary code and obtain sensitive information via the title parameter when creating an album. Join the discussion | CVE Database V5 | 03/22/2024, 00:00:00 UTC Added: 02/25/2026, 21:45:19 UTC |
Showing 1 to 7 of 7 results