Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-41921 is a stored cross-site scripting (XSS) vulnerability in Koha Community's Koha software affecting versions 25.05.0 through before 25.05.13, 25.11.0 through before 25.11.07, and 26.05.0 through before 26.05.02. Authenticated staff users can inject malicious scripts via unsanitized input fields in the purchase suggestion handler. These scripts execute in the browsers of staff users viewing the suggestion list, potentially leading to unauthorized actions or data exposure. Join the discussion | CVE Database V5 | 08/18/2026, 21:09:48 UTC Added: 08/18/2026, 21:20:44 UTC |
0 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the borrowers => edit_borrowers permission to cause a time-based denial of service by storing a SQL payload in a patron lang field. The value is concatenated raw into a subquery in Koha::AdditionalContents->search_for_display when an issue slip is printed for the affected patron. The 25-character column length limits exploitation to timing attacks; data extraction is not practical. The stored payload executes on each subsequent issue-slip print, scaling linearly with the SLEEP value and the number of slip-news rows. Join the discussion | CVE Database V5 | 08/11/2026, 11:22:47 UTC Added: 08/11/2026, 11:41:58 UTC |
0 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => label_creator permission to execute arbitrary SQL via the image_name field of a patron card layout. The image_name value is stored verbatim in the layout XML and later concatenated raw into a SQL query in patroncards/create-pdf.pl when a patron card batch is printed. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes via error-based or time-based blind injection. Join the discussion | CVE Database V5 | 08/11/2026, 11:22:14 UTC Added: 08/11/2026, 11:41:58 UTC |
0 A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item modification rule. The agefield value is stored verbatim to the system preference and later interpolated without parameterization into a SQL query in C4::Items::ToggleNewStatus (line 1228) when the scheduled cron job executes. The injection is SELECT-only under standard MariaDB/MySQL DBI single-statement execution; a time-based SLEEP payload is also achievable via the cron trigger. An attacker can read the entire Koha database including patron PII and staff bcrypt password hashes. Join the discussion | CVE Database V5 | 08/11/2026, 11:22:12 UTC Added: 08/11/2026, 11:41:58 UTC |
0 Koha's reports/issues_stats.pl (the circulation statistics report) builds its calculation query in sub calculate by concatenating several user-controlled request parameters directly into the SQL string. The PeriodTypeSel, PeriodDaySel, and PeriodMonthSel parameters are interpolated raw into single-quoted equality and function-comparison fragments, and the Filter slots plus the Line and Column identifiers are likewise interpolated with no whitelist and no placeholder binding. Join the discussion | CVE Database V5 | 08/04/2026, 13:00:15 UTC Added: 08/04/2026, 13:42:26 UTC |
0 Koha's reports/issues_avg_stats.pl builds dynamic SQL in sub calculate by concatenating several user-controlled request parameters directly into the query string. The Line and Column parameters are not validated against any whitelist and land verbatim in identifier positions (SELECT DISTINCTROW, GROUP BY, ORDER BY), and each Filter slot is concatenated raw into single-quoted LIKE, BETWEEN, and comparison fragments with no bound parameters. Join the discussion | CVE Database V5 | 08/04/2026, 13:00:10 UTC Added: 08/04/2026, 13:42:26 UTC |
0 Koha's reports/catalogue_stats.pl builds dynamic SQL in sub calculate by interpolating the user-controlled Line and Column request parameters directly into identifier positions of the query (SELECT DISTINCTROW, GROUP BY, ORDER BY) with no whitelist validation. Join the discussion | CVE Database V5 | 08/04/2026, 13:00:07 UTC Added: 08/04/2026, 13:42:26 UTC |
0 A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to inject arbitrary web scripts via the item type check-in message field (checkinmsg). Join the discussion | CVE Database V5 | 06/26/2026, 00:00:00 UTC Added: 06/26/2026, 21:51:30 UTC |
0 A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitrary web scripts via the item public notes field (items.itemnotes). Join the discussion | CVE Database V5 | 06/26/2026, 00:00:00 UTC Added: 06/26/2026, 21:51:30 UTC |
SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x before 26.11.00 allows an authenticated staff user with the Reports module flag to read arbitrary data from the Koha application database via the Filter URL parameter when the Criteria parameter matches /branchcode/. Join the discussion | CVE Database V5 | 06/13/2026, 16:34:10 UTC Added: 06/13/2026, 17:09:26 UTC |
Showing 1 to 10 of 18 results