Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/humhub/calendar

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Nextcloud versions 5.5.13 to before 5.5.17 and 6.2.0 to before 6.2.3 contain a vulnerability where an authenticated user can enumerate other users on the same instance via the Calendar app's attendee suggestion endpoint. This endpoint did not enforce sharing restrictions that were applied elsewhere, leading to exposure of user information.

Join the discussion

The Calendar module for HumHub enables users to create one-time or recurring events, manage attendee invitations, and efficiently track all scheduled activities. Prior to version 1.8.11, a Stored Cross-Site Scripting (XSS) vulnerability in the Event Types of the HumHub Calendar module impacts users viewing events created by an administrative account. This issue has been patched in version 1.8.11.

Join the discussion

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.17 and 5.2.4, when a malicious user creates a calendar event with a crafted attachment that links to a download link of a file on the same Nextcloud server, the file would be downloaded without the user confirming the action. This vulnerability is fixed in 4.7.17 and 5.2.4.

Join the discussion

Nextcloud Calendar is a calendar app for Nextcloud. Prior to 4.7.19, 5.5.6, and 6.0.1, the calendar app allowed blindly booking appointments with a squential ID without known the appointment token. This vulnerability is fixed in 4.7.19, 5.5.6, and 6.0.1.

Join the discussion

CVE-2025-66511 is a medium severity vulnerability in Nextcloud Calendar versions prior to 6.0.3 where participant tokens for meeting proposals are generated using insufficiently random values. This weakness allows attackers to compute valid participant tokens, enabling unauthorized access to meeting proposal details and the ability to submit dates. The vulnerability arises from the use of a hash function rather than a cryptographically secure random number generator. Exploitation requires no authentication or user interaction but has a higher attack complexity. The issue is fixed in version 6.0.3. No known exploits are currently reported in the wild.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/humhub/calendar
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses