Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-33130 is a medium-severity vulnerability in Uptime Kuma versions 1.23.0 through 2.2.0 that allows attackers with limited privileges to read arbitrary files on the server. The issue arises from improper control of filename inclusion in the LiquidJS template engine, specifically in the require.resolve() fallback mechanism, which lacks containment checks for unquoted absolute paths. This flaw enables remote file inclusion (RFI) attacks, potentially exposing sensitive server files such as /etc/passwd. The vulnerability does not require user interaction but does require some level of privileges (PR:L). It was fixed in version 2. Join the discussion | CVE Database V5 | 03/20/2026, 09:50:55 UTC Added: 03/20/2026, 10:09:20 UTC |
CVE-2026-32230 is a medium severity vulnerability in Uptime Kuma versions 2.0.0 through 2.1.3 where the GET /api/badge/:id/ping/:duration? endpoint fails to verify authorization properly. This flaw allows unauthenticated users to access average ping/response time data for private monitors, bypassing the intended access control that restricts such data to public monitors only. The vulnerability arises from missing authorization checks on this specific endpoint, while other badge endpoints correctly enforce public group verification. Exploitation requires no authentication or user interaction and can lead to unauthorized disclosure of monitoring data. The issue is fixed in version 2. Join the discussion | CVE Database V5 | 03/12/2026, 18:13:58 UTC Added: 03/12/2026, 18:47:41 UTC |
0 Uptime Kuma >== 1.23.0 has a ReDoS vulnerability, specifically when an administrator creates a notification through the web service. If a string is provided it triggers catastrophic backtracking in the regular expression, leading to a ReDoS attack. Join the discussion | CVE Database V5 | 03/17/2025, 00:00:00 UTC Added: 01/26/2026, 16:06:00 UTC |
Showing 1 to 3 of 3 results