Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-54767 is a critical vulnerability in LabRedesCefetRJ's WeGIA web manager for charitable institutions. Versions prior to 3.8.5 contain an unauthenticated GET endpoint that allows remote attackers to perform destructive database truncation operations without authorization. The vulnerability arises because the endpoint's access is controlled only by a hardcoded key embedded in the public source code. Exploitation can permanently delete member and contributor records. This issue is fixed in version 3.8.5. Join the discussion | CVE Database V5 | 09/17/2026, 21:56:28 UTC Added: 09/17/2026, 22:12:12 UTC |
0 CVE-2026-54671 is an authorization bypass vulnerability in LabRedesCefetRJ's WeGIA web manager for charitable institutions. Versions prior to 3.8.5 improperly map an internal control resource to an empty array, which the system treats as granting unconditional access to authenticated users. This flaw allows low-privileged users to read, modify, or delete other users' sensitive personal and medical records without verifying ownership. The issue is fixed in version 3.8.5. Join the discussion | CVE Database V5 | 09/17/2026, 21:55:39 UTC Added: 09/17/2026, 22:12:12 UTC |
0 WeGIA is a web manager for charitable institutions. Prior to 3.8.5, the contribution request dispatcher in web/html/contribuicao/controller/control.php accepts attacker-controlled nomeClasse and metodo values without a complete controller and method allowlist, exempts sensitive ContribuicaoLogController operations from authentication, and constructs a controller include path without canonical directory containment. An unauthenticated remote attacker can invoke getContribuicoesLogJSON, sincronizarStatus, registrarFaturas, and other sensitive methods to disclose contribution and donation records or trigger financial workflow operations. A traversal-shaped nomeClasse value can also cause require_once to include an accessible PHP or configuration file outside the intended controller directory, exposing source code, credentials, or other sensitive local data. This issue is fixed in version 3.8.5. Join the discussion | CVE Database V5 | 09/17/2026, 21:54:43 UTC Added: 09/17/2026, 22:12:12 UTC |
0 WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags. Join the discussion | CVE Database V5 | 08/20/2026, 13:48:20 UTC Added: 08/20/2026, 14:09:22 UTC |
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routing through verificarSenhaConfig() instead of verificarSenha() to bypass current password verification and convert temporary session access into permanent account takeover. Join the discussion | CVE Database V5 | 08/20/2026, 13:46:24 UTC Added: 08/20/2026, 13:53:21 UTC |
0 CVE-2026-45335 is an Open Redirect vulnerability in the WeGIA web manager for charitable institutions. The flaw exists in versions prior to 3.7.3 within the /WeGIA/controle/control.php endpoint, specifically involving the nextPage parameter when used with certain query parameters. The application does not properly validate or restrict this parameter, allowing attackers to redirect users to arbitrary external sites. This can facilitate phishing, credential theft, malware distribution, and social engineering attacks leveraging the trusted WeGIA domain. The vulnerability has a medium severity rating and a CVSS score of 5.4. It is fixed in version 3. Join the discussion | CVE Database V5 | 05/27/2026, 15:25:57 UTC Added: 05/27/2026, 16:33:44 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/FuncionarioControle.php follows the same pattern. SHA-256 is a general-purpose cryptographic hash built for speed, not password storage. Without a salt, identical passwords produce identical digests, making the entire hash database vulnerable to a single precomputed rainbow table lookup. This vulnerability is fixed in 3.7.3. Join the discussion | CVE Database V5 | 05/27/2026, 15:24:21 UTC Added: 05/27/2026, 16:33:44 UTC |
0 CVE-2026-45026 is a stored Cross-Site Scripting (XSS) vulnerability in WeGIA, a web manager for charitable institutions. The flaw exists in versions prior to 3.7.3 and allows an authenticated user to inject malicious JavaScript into the Processo de Aceitação page. This script executes when users access the page, potentially enabling session hijacking and account takeover. The vulnerability has a medium severity with a CVSS score of 6.8. A fix is available in version 3.7.3. Join the discussion | CVE Database V5 | 05/11/2026, 18:36:45 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the "Etapas de um Processo" (html/atendido/etapa_processo.php) page, which is executed when user access the the page, enabling session hijacking and account takeover. This vulnerability is fixed in 3.7.3. Join the discussion | CVE Database V5 | 05/11/2026, 18:35:28 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of user-supplied input. The id_processo parameter is directly embedded into the HTML without sanitization, allowing attackers to inject arbitrary JavaScript. This can lead to session hijacking, credential theft, or execution of malicious actions in the context of the victim's browser. This vulnerability is fixed in 3.7.0. Join the discussion | CVE Database V5 | 05/11/2026, 18:32:45 UTC Added: 05/11/2026, 19:21:28 UTC |
Showing 1 to 10 of 93 results