Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 ClipBucket V5 version 5.5.1 contains an OS command injection vulnerability in its web installer. The vulnerability arises because the php_cli_filepath parameter is not properly validated or escaped before being passed to shell execution. This allows unauthenticated attackers to execute arbitrary commands as the web server user by submitting a crafted POST request to the installer. The vulnerability has a critical severity with a CVSS score of 9.2. Join the discussion | CVE Database V5 | 08/25/2026, 22:12:23 UTC Added: 08/25/2026, 22:22:55 UTC |
0 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141. Join the discussion | CVE Database V5 | 06/11/2026, 22:55:17 UTC Added: 06/11/2026, 23:30:07 UTC |
0 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133. Join the discussion | CVE Database V5 | 06/11/2026, 22:53:17 UTC Added: 06/11/2026, 23:00:06 UTC |
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129. Join the discussion | CVE Database V5 | 06/11/2026, 22:51:47 UTC Added: 06/11/2026, 23:00:06 UTC |
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140. Join the discussion | CVE Database V5 | 06/11/2026, 22:49:58 UTC Added: 06/11/2026, 23:00:06 UTC |
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132. Join the discussion | CVE Database V5 | 06/11/2026, 22:48:32 UTC Added: 06/11/2026, 23:00:06 UTC |
ClipBucket v5 versions prior to 5.5.3 contain a critical SQL Injection vulnerability in the authenticated admin endpoint admin_area/action_logs.php. The vulnerability arises because the 'type' parameter from the GET request is directly concatenated into a SQL query without proper parameterization, allowing an attacker with admin privileges to perform UNION-based SQL injection and potentially exfiltrate database data. This issue is fixed in version 5.5.3. Join the discussion | CVE Database V5 | 05/14/2026, 20:45:54 UTC Added: 05/14/2026, 21:22:34 UTC |
CVE-2026-32321 is a high-severity SQL injection vulnerability affecting ClipBucket v5 versions prior to 5.5.3 #80. It exists in the actions/ajax.php endpoint due to improper sanitization of the userid parameter, allowing an authenticated attacker to perform time-based blind SQL injection. Exploitation can lead to full database disclosure and administrative account takeover without requiring user interaction. The vulnerability has a CVSS score of 8.8, reflecting its critical impact on confidentiality, integrity, and availability. Although no known exploits are currently reported in the wild, affected users should urgently update to version 5.5. Join the discussion | CVE Database V5 | 03/18/2026, 20:37:51 UTC Added: 03/18/2026, 20:58:26 UTC |
0 ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, collection item operations are vulnerable to authorization flaws, allowing a normal authenticated user to modify another user’s collection items. This affects both add item (/actions/add_to_collection.php) due to missing authorization checks and delete item (/manage_collections.php?mode=manage_items...) due to a broken ownership check in removeItemFromCollection(). As a result, attackers can insert and remove items from collections they do not own. Version 5.5.3 #59 fixes the issue. Join the discussion | CVE Database V5 | 02/27/2026, 19:18:25 UTC Added: 02/27/2026, 19:26:13 UTC |
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 #59, a normal authenticated user can store the XSS payload. The payload is triggered by administrator. Version 5.5.3 #59 fixes the issue. Join the discussion | CVE Database V5 | 02/27/2026, 19:15:11 UTC Added: 02/27/2026, 19:26:11 UTC |
Showing 1 to 10 of 18 results