Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use them to enumerate all users and create a new administrator account. This happens because the route definitions do not enforce admin-only middleware, and the controller-level authorization check uses a broken boolean condition. As a result, any user with a valid web session cookie can reach functionality that should be restricted to administrators. Version 0.71.1 patches the issue. Join the discussion | CVE Database V5 | 04/18/2026, 00:07:33 UTC Added: 04/18/2026, 01:08:07 UTC |
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=true` to `PUT /settings/users/{userId}` for their own user ID. The endpoint is intended to let a user edit their own profile, but it updates the sensitive `isAdmin` field without any admin-only authorization check. Version 0.71.1 patches the issue. Join the discussion | CVE Database V5 | 04/18/2026, 00:05:46 UTC Added: 04/18/2026, 13:41:10 UTC |
Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets through `POST /settings/jellyfin/server-url-verify`. The endpoint accepts a user-controlled URL, appends `/system/info/public`, and sends a server-side HTTP request with Guzzle. Because there is no restriction on internal hosts, loopback addresses, or private network ranges, this can be abused for SSRF and internal network probing. Any ordinary authenticated user can use this endpoint to make the server connect to arbitrary internal targets and distinguish between different network states. This enables SSRF-based internal reconnaissance, including host discovery, port-state probing, and service fingerprinting. In certain deployments, it may also be usable to reach internal administrative services or cloud metadata endpoints that are not directly accessible from the outside. Version 0.71.1 fixes the issue. Join the discussion | CVE Database V5 | 04/18/2026, 00:01:09 UTC Added: 04/18/2026, 13:41:10 UTC |
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryCreated=`. Version 0.70.0 fixes the issue. Join the discussion | CVE Database V5 | 01/19/2026, 18:35:21 UTC Added: 01/19/2026, 18:56:54 UTC |
CVE-2026-23840 is a critical cross-site scripting (XSS) vulnerability in the leepeuker movary web application, affecting versions prior to 0.70.0. The issue arises from improper input validation of the `? categoryDeleted=` parameter, allowing attackers to inject malicious scripts. Exploitation requires user interaction but no authentication, and can lead to full compromise of user confidentiality and integrity. The vulnerability has a CVSS score of 9.3, indicating a severe risk. Although no known exploits are currently in the wild, unpatched instances remain at high risk. European organizations using movary for movie tracking and rating should prioritize upgrading to version 0. Join the discussion | CVE Database V5 | 01/19/2026, 18:32:50 UTC Added: 01/19/2026, 18:56:54 UTC |
Movary is a web application to track, rate and explore your movie watch history. Due to insufficient input validation, attackers can trigger cross-site scripting payloads in versions prior to 0.70.0. The vulnerable parameter is `?categoryUpdated=`. Version 0.70.0 fixes the issue. Join the discussion | CVE Database V5 | 01/19/2026, 18:27:25 UTC Added: 01/19/2026, 18:41:45 UTC |
0 Movary is a web application to track, rate and explore your movie watch history. Versions up to and including 0.68.0 use the HTTP Referer header value directly for redirects in multiple settings endpoints, allowing a crafted link to cause an open redirect to an attacker-controlled site and facilitate phishing. This vulnerability is fixed in 0.69.0. Join the discussion | CVE Database V5 | 10/30/2025, 17:39:19 UTC Added: 10/30/2025, 17:55:48 UTC |
0 Movary is a web application to track, rate and explore your movie watch history. Prior to 0.69.0, the login page accepts a redirect parameter without validation, allowing attackers to redirect authenticated users to arbitrary external sites. This vulnerability is fixed in 0.69.0. Join the discussion | CVE Database V5 | 10/30/2025, 17:32:41 UTC Added: 10/30/2025, 17:55:48 UTC |
Showing 1 to 8 of 8 results