Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, when hideConfigSecrets is enabled, the catch-all socket dispatcher in js/node_helper.js passes every inbound object payload through replaceSecretPlaceholder in js/server_functions.js before invoking socketNotificationReceived. A client connected to a loaded module namespace can submit a SECRET_API_KEY placeholder, causing the server to replace it with the corresponding process environment value. The default weather helper accepts INIT_WEATHER, copies the attacker-controlled instanceId, and returns it in WEATHER_ERROR, providing an echo path for the expanded secret. This reverses the intended one-way redaction boundary and can disclose API tokens, credentials, or service keys stored in SECRET_ variables. This issue is fixed in version 2.37.0. Join the discussion | CVE Database V5 | 08/18/2026, 17:35:44 UTC Added: 08/18/2026, 17:50:23 UTC |
0 MagicMirror² versions prior to 2.37.0 contain a Server-Side Request Forgery (SSRF) vulnerability in the newsfeed module. The vulnerability arises because the checkArticleUrl function accepts URLs via an unauthenticated Socket.IO namespace and performs HTTP HEAD requests without validating the URL. This allows attackers to probe internal hosts and ports and potentially trigger side effects on services responding to HEAD requests. The issue is resolved in version 2.37.0. Join the discussion | CVE Database V5 | 08/18/2026, 17:22:02 UTC Added: 08/18/2026, 17:36:14 UTC |
0 MagicMirror² versions prior to 2.37.0 contain a server-side request forgery (SSRF) vulnerability in the ADD_CALENDAR handler of the calendar module. This handler accepts attacker-controlled URLs and authentication data via an unauthenticated Socket.IO namespace, allowing SSRF without proper validation. The vulnerability can lead to exfiltration of internal service response data if the response is a valid iCal calendar. The issue is fixed in version 2.37.0. Join the discussion | CVE Database V5 | 08/18/2026, 17:18:52 UTC Added: 08/18/2026, 17:36:14 UTC |
MagicMirror² is an open source modular smart mirror platform. Prior to 2.37.0, MagicMirror applies ipWhitelist only as Express middleware, while the Socket.IO server in js/server.js is attached directly to the HTTP server without equivalent IP allowlist, origin, or namespace authentication checks. In a documented non-loopback deployment that relies on ipWhitelist, an unauthenticated adjacent-network client can connect directly to module Socket.IO namespaces, and js/node_helper.js dispatches arbitrary events and payloads to socketNotificationReceived. The default newsfeed and calendar helpers can make server-side requests to attacker-selected URLs, while the default updatenotification helper can reach child_process.exec when a third-party module update is pending and the attacker supplies an update command through the socket CONFIG path. This can expose internal services, manipulate module-helper state, and conditionally execute commands. This issue is fixed in version 2.37.0. Join the discussion | CVE Database V5 | 08/18/2026, 17:13:03 UTC Added: 08/18/2026, 17:36:14 UTC |
0 MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to force the MagicMirror² server to perform arbitrary HTTP requests to internal networks, cloud metadata services, and localhost services. The endpoint also expands environment variable placeholders (**VAR_NAME**), enabling exfiltration of server-side secrets. This vulnerability is fixed in 2.36.0. Join the discussion | CVE Database V5 | 05/14/2026, 15:46:41 UTC Added: 05/14/2026, 16:06:42 UTC |
Showing 1 to 5 of 5 results