Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Horilla is an HR and CRM software. Prior to 2.0.0, approve_validate_attendance_request at /attendance/approve-validate-attendance-request/ changes attendance_validated, is_validate_request_approved, approved_by, and related pending-request state through an HTTP GET before calling attendance.save(), so Django does not require CSRF validation for the action. An unauthenticated attacker can cause a logged-in manager with attendance.change_attendance to make a top-level request that carries the manager's SameSite=Lax session cookie, silently approving attendance with the victim's privileges and attributing the approval to the victim in the audit trail. This issue is fixed in version 2.0.0. Join the discussion | CVE Database V5 | 09/25/2026, 22:18:13 UTC Added: 09/25/2026, 22:33:16 UTC |
0 Horilla is an HR and CRM software. Prior to 2.0.0, HorillaListView.export_data in horilla_views/generic/cbv/views.py accepts an authenticated user's columns POST parameter, takes field_tuple[1], interpolates it into dynamic_fn_str as Python source, and passes the generated function definition to exec(). A crafted string that remains valid under ast.literal_eval can inject Python syntax into a default argument evaluated during function definition, allowing arbitrary operating-system commands to execute with the application process privileges, including root privileges in the shipped Docker image. This issue is fixed in version 2.0.0. Join the discussion | CVE Database V5 | 09/25/2026, 22:17:04 UTC Added: 09/25/2026, 22:33:16 UTC |
0 Horilla is an HR and CRM software. Prior to 1.6.0, the search parameter at /employee/employee-filter-view is reflected by jQuery .html() in employee/templates/employee_nav.html without HTML neutralization. An external attacker can craft and deliver a link that causes JavaScript to execute when an authenticated employee or administrator reaches the employee filter, allowing access to browser-visible session data and actions with the victim's application privileges. This issue is fixed in version 1.6.0. Join the discussion | CVE Database V5 | 09/25/2026, 21:59:50 UTC Added: 09/25/2026, 22:33:16 UTC |
0 Horilla is an HR and CRM software. From 1.0.0 until 1.6.0 and 2.0.0, the get_mail_preview handlers in recruitment/views/actions.py and employee/not_in_out_dashboard.py render a user-controlled body at /recruitment/get-mail-preview/ and /employee/get-employee-mail-preview with the full request object in the Django template context. An authenticated user with a valid CSRF token can use template attribute traversal to read request.user.password, request.META, and related-user attributes, exposing password hashes, personal data, and server request metadata. Django template restrictions prevent arbitrary code execution through this primitive, so the demonstrated impact is information disclosure and possible offline password cracking or account compromise. This issue is fixed in versions 1.6.0 and 2.0.0. Join the discussion | CVE Database V5 | 09/25/2026, 21:58:21 UTC Added: 09/25/2026, 22:33:16 UTC |
Horilla is an HR and CRM software. In 1.5.0-85 and earlier, payroll/views/component_views.py does not consistently authorize access in allowances_deductions_tab, view_single_allowance, and view_single_deduction before loading records selected by emp_id, allowance_id, or deduction_id. An authenticated employee can substitute those identifiers to read another employee's salary structure, allowance and deduction amounts, personal loan disbursements, and repayment schedules without owning the record or holding payroll-view permissions. No complete fixed version is available as of this review. Join the discussion | CVE Database V5 | 09/25/2026, 21:56:00 UTC Added: 09/25/2026, 22:04:39 UTC |
0 CVE-2026-41513 is a medium severity vulnerability in horilla-hr version 1.5.0 and earlier. It involves an open redirect issue where the notification endpoints improperly trust an unvalidated 'next' parameter, allowing redirection to arbitrary external URLs. This can be exploited by attackers to craft trusted application links that redirect users to phishing or social engineering sites. No official patch or remediation has been confirmed yet. The vulnerability does not appear to have known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/12/2026, 16:43:50 UTC Added: 05/12/2026, 17:37:34 UTC |
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, a broken access control vulnerability in the helpdesk attachment viewer allows any authenticated user to view attachments from other tickets by changing the attachment ID. This can expose sensitive support files and internal documents across unrelated users or teams. Join the discussion | CVE Database V5 | 04/21/2026, 18:16:29 UTC Added: 04/21/2026, 18:46:06 UTC |
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document upload endpoint allows any authenticated user to overwrite or replace or corrupt another employee’s document by changing the document ID in the upload request. This enables unauthorized modification of HR records. Join the discussion | CVE Database V5 | 04/21/2026, 18:15:30 UTC Added: 04/21/2026, 18:46:06 UTC |
Horilla is a free and open source Human Resource Management System (HRMS). In 1.5.0, an insecure direct object reference in the employee document viewer allows any authenticated user to access other employees’ uploaded documents by changing the document ID in the request. This exposes sensitive HR files such as identity documents, contracts, certificates, and other private employee records. Join the discussion | CVE Database V5 | 04/21/2026, 18:14:19 UTC Added: 04/21/2026, 18:46:06 UTC |
Showing 1 to 9 of 9 results