Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
JimuReport contains an authentication bypass vulnerability in the report folder template listing endpoint that allows unauthenticated attackers to enumerate all reports and retrieve share tokens. Attackers can use disclosed share tokens to access protected report endpoints and retrieve full report definitions including embedded SQL statements and live query data. Join the discussion | CVE Database V5 | 08/17/2026, 20:36:05 UTC Added: 08/17/2026, 20:42:01 UTC |
JimuReport through 2.5.0 exposes the POST /jmreport/auto/export endpoint without authentication: the handler is annotated @JimuNoLoginRequired, so JimuReportTokenInterceptor skips all authentication and authorization, and the export service streams the rendered report for any supplied report id without verifying the auto-export configuration flag. An unauthenticated remote attacker can enumerate Snowflake report identifiers and export the full contents of any report, including the data returned by the report configured SQL queries and any credentials embedded in its data sources. Join the discussion | CVE Database V5 | 06/30/2026, 15:58:47 UTC Added: 06/30/2026, 16:52:01 UTC |
0 JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code. Join the discussion | CVE Database V5 | 06/17/2026, 00:00:00 UTC Added: 06/17/2026, 16:28:13 UTC |
0 CVE-2026-5848 is a medium severity code injection vulnerability in jeecgboot JimuReport versions up to 2.3.0. It affects the DriverManager.getConnection function in the Data Source Handler component, where manipulation of the dbUrl argument can lead to code injection. The vulnerability can be exploited remotely without user interaction and requires high privileges. The vendor has confirmed the issue and plans to release a fix in an upcoming version, but no patch is currently available. Exploit details have been made public, increasing the risk of exploitation. Join the discussion | CVE Database V5 | 04/09/2026, 05:15:11 UTC Added: 04/09/2026, 05:50:47 UTC |
0 An issue in the component /jeecg-boot/jmreport/dict/list of JimuReport v1.7.8 allows attacker to escalate privileges via a crafted GET request. Join the discussion | CVE Database V5 | 09/10/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:02 UTC |
Showing 1 to 5 of 5 results