Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.php of the component fileThumb Plugin. The manipulation of the argument ffmpegBin leads to command injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/17/2026, 12:00:14 UTC Added: 05/17/2026, 12:36:37 UTC |
CVE-2026-5618 is a server-side request forgery (SSRF) vulnerability in kalcaddle kodbox versions up to 1.64. It arises from manipulation of the siteFrom/siteTo arguments in the shareMake/shareCheck component. The vulnerability can be exploited remotely but requires high attack complexity and is considered difficult to exploit. The vendor has not responded to disclosure requests, and no official patch or remediation guidance is currently available. The CVSS 4.0 base score is 6.3, indicating medium severity. Join the discussion | CVE Database V5 | 04/06/2026, 03:30:19 UTC Added: 04/06/2026, 03:45:30 UTC |
A security flaw has been discovered in kalcaddle kodbox 1.64. Impacted is the function can of the file /workspace/source-code/app/controller/explorer/auth.class.php of the component Password-protected Share Handler. Performing a manipulation results in improper authentication. The attack is possible to be carried out remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/26/2026, 01:02:35 UTC Added: 03/26/2026, 18:27:09 UTC |
0 CVE-2026-4830 is a medium severity vulnerability in kalcaddle kodbox version 1.64. It involves an unrestricted file upload issue in the Public Share Handler component, specifically in the Add function of app/controller/explorer/userShare.class.php. The vulnerability allows remote attackers to upload files without proper restrictions. Exploitation complexity is high, and no privileges or user interaction are required. Although an exploit is publicly available, the vendor has not responded or provided a fix. Join the discussion | CVE Database V5 | 03/26/2026, 00:18:14 UTC Added: 03/26/2026, 01:01:02 UTC |
A security vulnerability has been detected in kalcaddle kodbox 1.64. This impacts the function loginAfter/tfaVerify of the file /workspace/source-code/plugins/client/controller/tfa/index.class.php of the component Password Login. The manipulation leads to improper authentication. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/23/2026, 15:56:44 UTC Added: 03/23/2026, 18:00:57 UTC |
0 A weakness has been identified in kalcaddle kodbox 1.64. This affects the function checkBin of the file /workspace/source-code/plugins/fileThumb/app.php of the component fileThumb Endpoint. Executing a manipulation can lead to os command injection. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/23/2026, 15:15:14 UTC Added: 03/23/2026, 15:45:54 UTC |
A security flaw has been discovered in kalcaddle kodbox 1.64. The impacted element is an unknown function of the file /workspace/source-code/plugins/oauth/controller/bind/index.class.php of the component loginSubmit API. Performing a manipulation of the argument third results in cross-site request forgery. Remote exploitation of the attack is possible. A high degree of complexity is needed for the attack. The exploitability is regarded as difficult. The exploit has been released to the public and may be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/23/2026, 14:24:35 UTC Added: 03/23/2026, 14:46:06 UTC |
A vulnerability was identified in kalcaddle kodbox 1.64. The affected element is the function PathDriverUrl of the file /workspace/source-code/app/controller/explorer/editor.class.php of the component fileGet Endpoint. Such manipulation of the argument path leads to server-side request forgery. The attack may be launched remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/23/2026, 13:32:42 UTC Added: 03/23/2026, 14:00:55 UTC |
A vulnerability was determined in kalcaddle kodbox 1.64. Impacted is the function shareSafeGroup of the file /workspace/source-code/app/controller/explorer/shareOut.class.php of the component Site-level API key Handler. This manipulation of the argument sk causes use of hard-coded cryptographic key . The attack may be initiated remotely. The complexity of an attack is rather high. The exploitability is considered difficult. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/23/2026, 12:46:51 UTC Added: 03/23/2026, 13:00:59 UTC |
0 A vulnerability was detected in kalcaddle kodbox up to 1.61.10. This issue affects some unknown processing of the file /?explorer/index/zip of the component Compression Handler. The manipulation results in command injection. The attack may be launched remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 01/17/2026, 21:02:06 UTC Added: 01/17/2026, 21:11:45 UTC |
Showing 1 to 10 of 11 results