Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A server-side request forgery (SSRF) vulnerability exists in JeecgBoot up to version 3.9.2 in an unknown function within the /airag/chat/send file of the Anonymous Chat Attachment Parser component. This vulnerability can be exploited remotely without authentication. Public exploit code is available. A fix is planned for a future release but is not yet available. Join the discussion | GCVE Database | 08/06/2026, 05:15:08 UTC Added: 08/06/2026, 18:17:13 UTC |
0 CVE-2026-19000 is a server-side request forgery (SSRF) vulnerability in JeecgBoot versions 3.9.0, 3.9.1, and 3.9.2. It affects an unknown function in the /airag/chat/send file of the Anonymous Chat Attachment Parser component. The vulnerability can be exploited remotely without authentication. A fix is planned but not yet available. The CVSS 4.0 base score is 6.9, indicating medium severity. Join the discussion | CVE Database V5 | 08/06/2026, 05:15:08 UTC Added: 08/06/2026, 05:41:47 UTC |
0 A vulnerability was identified in JeecgBoot up to 3.9.2. The impacted element is an unknown function of the file /airag/airagModel/test. The manipulation of the argument baseUrl leads to server-side request forgery. The attack is possible to be carried out remotely. The exploit is publicly available and might be used. A fix is planned for the upcoming release. Join the discussion | CVE Database V5 | 06/01/2026, 08:15:08 UTC Added: 06/01/2026, 09:18:38 UTC |
0 A vulnerability was determined in JeecgBoot up to 3.9.2. The affected element is the function WordUtil.addImage of the file /airag/word/edit. Executing a manipulation can lead to server-side request forgery. The attack can be executed remotely. The exploit has been publicly disclosed and may be utilized. A fix is planned for the upcoming release. Join the discussion | CVE Database V5 | 06/01/2026, 08:00:16 UTC Added: 06/01/2026, 09:18:38 UTC |
0 A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improper access controls. The attack can be executed remotely. The exploit is now public and may be used. Upgrading to version 3.9.2 is able to resolve this issue. The affected component should be upgraded. Join the discussion | CVE Database V5 | 05/26/2026, 22:15:15 UTC Added: 05/26/2026, 22:48:35 UTC |
0 CVE-2026-9581 is a medium severity vulnerability in JeecgBoot versions up to 3.9.1 involving improper access controls in the /sys/comment/add endpoint. This flaw allows remote attackers to manipulate the affected function, potentially bypassing intended access restrictions. Exploits for this vulnerability are publicly available. Upgrading to JeecgBoot version 3.9.2 resolves the issue. Join the discussion | CVE Database V5 | 05/26/2026, 20:30:13 UTC Added: 05/27/2026, 19:52:44 UTC |
0 CVE-2026-9580 is a medium severity vulnerability in JeecgBoot versions up to 3.9.1 involving improper access controls in the LoginController.selectDepart function. This flaw allows remote attackers to bypass access restrictions. The issue is fixed by upgrading to version 3.9.2. No known exploits are currently reported in the wild. Join the discussion | CVE Database V5 | 05/26/2026, 20:15:14 UTC Added: 05/26/2026, 20:35:44 UTC |
0 CVE-2026-9579 is a medium severity vulnerability in JeecgBoot versions up to 3.9.1. It involves improper access controls in the user.getUsername function within the SysUser component, specifically in the /sys/user/login/setting/userEdit file. The vulnerability arises from manipulation of the userIdentity argument, allowing remote attackers to potentially bypass access restrictions. An exploit has been publicly disclosed. Upgrading to JeecgBoot version 3.9.2 is recommended to address this issue. Join the discussion | CVE Database V5 | 05/26/2026, 19:45:09 UTC Added: 05/26/2026, 20:35:44 UTC |
0 CVE-2026-8114 is a medium severity SQL injection vulnerability affecting JeecgBoot versions up to 3.9.1. The issue exists in the JSON Object Handler component, specifically in the /sys/dict/loadTreeData endpoint, where manipulation of the 'condition' argument can lead to SQL injection. The vulnerability can be exploited remotely without user interaction and requires low privileges. The vendor has indicated that this issue should have been fixed recently, but no explicit patch or advisory link is provided. Exploit code is publicly available, though no known widespread exploitation has been reported. Join the discussion | CVE Database V5 | 05/07/2026, 22:00:11 UTC Added: 05/07/2026, 22:06:23 UTC |
0 A vulnerability was found in JeecgBoot up to 3.9.1. Affected by this vulnerability is an unknown functionality of the file /sys/fillRule/edit of the component FillRuleUtil Component. The manipulation of the argument ruleClass results in improper authorization. The attack may be performed from remote. The exploit has been made public and could be used. You should upgrade the affected component. The vendor confirmed the issue and will provide a fix in the upcoming release. Join the discussion | CVE Database V5 | 05/02/2026, 03:15:12 UTC Added: 05/02/2026, 04:06:24 UTC |
Showing 1 to 10 of 13 results