Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Kiteworks Core has a business logic vulnerability in its file-request feature that allows an authenticated user to impersonate another user when sending requests. This flaw arises because the server does not verify that the requester is authorized to act as the specified account. Exploitation requires the feature to be enabled for the attacker and the targeted recipient to respond to the request. The vulnerability affects versions prior to 9.5.1 and has a medium severity rating with a CVSS score of 4.6. Join the discussion | CVE Database V5 | 09/30/2026, 20:24:29 UTC Added: 09/30/2026, 20:48:43 UTC |
0 CVE-2026-102110 is a medium severity vulnerability in Kiteworks Core where an endpoint used during initial appliance setup lacks authentication and does not enforce its intended state precondition. This allows an unauthenticated network attacker to repeatedly trigger the privileged activation process during the initial activation window, potentially disrupting setup and leaving the appliance incompletely configured. The issue is only exploitable during the first-time activation phase and not after full configuration. Join the discussion | CVE Database V5 | 09/30/2026, 20:21:42 UTC Added: 09/30/2026, 20:34:19 UTC |
0 CVE-2026-102111 is a vulnerability in Kiteworks Core where an authenticated administrator can configure a security-policy setting beyond its intended maximum value. This flaw causes the associated security control to never activate, despite appearing enabled in the administrative interface and audit logs, effectively rendering the control ineffective without detection. Join the discussion | CVE Database V5 | 09/30/2026, 20:21:15 UTC Added: 09/30/2026, 20:34:19 UTC |
0 CVE-2026-102112 is a privilege escalation vulnerability in Kiteworks Core that allows an attacker with existing local code execution as an unprivileged backend service account to escalate privileges to root and execute arbitrary commands with highest privileges. Exploitation requires prior local access to the service account on the appliance. The vulnerability is related to improper neutralization of special elements in OS commands (CWE-78). Join the discussion | CVE Database V5 | 09/30/2026, 20:20:59 UTC Added: 09/30/2026, 20:34:19 UTC |
0 CVE-2026-102113 is a privilege escalation vulnerability in Kiteworks Core that allows an attacker with existing local code execution as a low-privileged backend service account to escalate privileges to root. The issue arises from improper handling of filesystem paths by a privileged routine, enabling arbitrary command execution with root privileges. Exploitation requires prior local access to the service account. The vulnerability affects Kiteworks Core versions prior to 9.5.0. Join the discussion | CVE Database V5 | 09/30/2026, 20:20:35 UTC Added: 09/30/2026, 20:34:19 UTC |
0 CVE-2026-102114 is a command injection vulnerability in Kiteworks Core that allows a high-privileged authenticated administrator to execute arbitrary OS commands as root on the affected appliance node. Exploitation requires administrative credentials with elevated privileges. The vulnerability affects Kiteworks Core versions from 0 up to but not including 9.5.0. The CVSS v3.1 base score is 7.2, indicating a high severity level. Join the discussion | CVE Database V5 | 09/30/2026, 20:20:18 UTC Added: 09/30/2026, 20:34:21 UTC |
0 Kiteworks Core contains a critical vulnerability in its password recovery mechanism. The system does not properly validate parameters in the password reset workflow, allowing an unauthenticated attacker who knows a user's email address to reset that user's password without needing the emailed reset link. This flaw enables the attacker to authenticate as the targeted user, including accounts with administrative privileges. Join the discussion | CVE Database V5 | 09/30/2026, 20:19:55 UTC Added: 09/30/2026, 20:34:21 UTC |
0 CVE-2026-102117 is a high-severity vulnerability in Kiteworks Core affecting versions prior to 9.5.1. It allows an authenticated System Administrator with access to the key protecting submitted data to redirect the system's outbound support connection to an attacker-controlled destination. This redirection can lead to remote code execution with the privileges of a local service account. Join the discussion | CVE Database V5 | 09/30/2026, 20:19:02 UTC Added: 09/30/2026, 20:34:21 UTC |
0 CVE-2026-102118 is a local privilege escalation vulnerability in Kiteworks Core that allows an attacker with a low-privileged shell to escalate to root privileges on the appliance. The issue is due to improper link resolution before file access, categorized under CWE-59. The vulnerability affects Kiteworks Core versions from 0 up to but not including 9.5.0. It has a high severity with a CVSS score of 7.8. No known exploits are reported in the wild, and no patch information is provided. Join the discussion | CVE Database V5 | 09/30/2026, 20:18:21 UTC Added: 09/30/2026, 20:34:21 UTC |
0 CVE-2026-102120 is a high-severity OS command injection vulnerability in Kiteworks Core affecting versions prior to 9.5.1. It allows an attacker with existing code execution on one node of a clustered deployment to escalate privileges and execute OS commands on other nodes in the cluster. The vulnerability arises from insufficient input validation in an internal cluster management function, which is not accessible externally and requires prior node access. Join the discussion | CVE Database V5 | 09/30/2026, 20:17:48 UTC Added: 09/30/2026, 20:34:21 UTC |
Showing 1 to 10 of 93 results