Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-75773 is a vulnerability in karakeep-app karakeep up to version 0.32.0 affecting the authorize function in the Login Endpoint. It allows improper restriction of excessive authentication attempts, potentially enabling attackers to perform repeated login attempts remotely. The vulnerability has a medium severity with a CVSS score of 6.3. Exploitation is difficult and requires high complexity. The issue is fixed in version 0.33.0. Join the discussion | CVE Database V5 | 08/18/2026, 11:00:12 UTC Added: 08/18/2026, 11:33:14 UTC |
Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. Although the application implements protections intended to prevent requests toward internal/private network destinations, these protections could be bypassed through crafted HTTP redirect chains. By leveraging attacker-controlled redirects, an authenticated user could cause vulnerable application components to initiate requests toward internally reachable Docker network services accessible from the application environment. The issue affected multiple processing paths, including crawler-related functionality and video download processing flows. Version 0.32.0 contains a patch. Join the discussion | CVE Database V5 | 05/26/2026, 13:45:07 UTC Added: 05/26/2026, 14:33:03 UTC |
0 Karakeep is a elf-hostable bookmark-everything app. In version 0.30.0, when the Reddit metascraper plugin returns `readableContentHtml`, the HTML parsing subprocess uses it directly without running it through DOMPurify. Every other content source in the crawler goes through Readability + DOMPurify, but the Reddit path skips both. Since this content ends up in `dangerouslySetInnerHTML` in the reader view, any malicious HTML in the Reddit response gets executed in the user's browser. Version 0.31.0 contains a patch for this issue. Join the discussion | CVE Database V5 | 02/25/2026, 03:48:07 UTC Added: 02/25/2026, 04:11:31 UTC |
Showing 1 to 3 of 3 results