Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A Cross-Site Request Forgery (CSRF) vulnerability exists in MobSF Mobile-Security-Framework-MobSF versions prior to 4.5.1. The issue arises because the CSRF middleware is only configured in a deprecated setting and omitted from the active middleware configuration, allowing remote attackers to trick logged-in users into submitting unauthorized POST requests. This can lead to unauthorized actions such as deleting scans, uploading or downloading applications, changing passwords, or managing users with the victim's permissions. The vulnerability is fixed in version 4.5.1. Join the discussion | CVE Database V5 | 08/18/2026, 17:49:23 UTC Added: 08/18/2026, 17:50:23 UTC |
0 MobSF is a mobile application security testing tool used. Prior to 4.5.1, get_browsable_activities in mobsf/StaticAnalyzer/views/android/manifest_analysis.py validates only an Android manifest android:host value with valid_host before appending a separately supplied android:port to the URL fetched by _check_url, allowing an authenticated user to upload a crafted APK that makes requests to an attacker-selected nonstandard port at /.well-known/assetlinks.json. With an attacker-controlled hostname and DNS rebinding between validation and the requests.get connection, the request can reach an internal service, although redirects remain disabled and the path is fixed. This issue is fixed in version 4.5.1. Join the discussion | CVE Database V5 | 08/18/2026, 17:48:42 UTC Added: 08/18/2026, 17:50:23 UTC |
CVE-2026-68922 is a path traversal vulnerability in MobSF Mobile-Security-Framework-MobSF prior to version 4.5.1. The flaw exists in the find_icon_path_zip function, which uses the Android manifest's android:icon value to build file paths without proper validation. This allows an authenticated user to upload a crafted ZIP or APK file that can read server files with allowed extensions, copy them to a predictable location, and retrieve them via the /download/ endpoint. The vulnerability also enables a file-existence oracle through the icon_path report field. The issue is fixed in version 4.5.1. Join the discussion | CVE Database V5 | 08/18/2026, 17:47:56 UTC Added: 08/18/2026, 17:50:23 UTC |
0 MobSF is a mobile application security testing tool used. Prior to 4.5.1, the unzip function in mobsf/StaticAnalyzer/views/common/shared_func.py logs that an archive member exceeding ZIP_MAX_UNCOMPRESSED_FILE_SIZE is being skipped but does not continue to the next member, so an authenticated user can upload a crafted ZIP or APK whose oversized member is extracted to disk when the aggregate ZIP_MAX_UNCOMPRESSED_TOTAL_SIZE limit has not yet been reached, potentially exhausting disk space and preventing further scans. This issue is fixed in version 4.5.1. Join the discussion | CVE Database V5 | 08/18/2026, 17:46:32 UTC Added: 08/18/2026, 17:50:23 UTC |
CVE-2026-24490 is a high-severity Stored Cross-site Scripting (XSS) vulnerability in MobSF Mobile-Security-Framework versions prior to 4.4.5. It arises from improper sanitization of the android:host attribute in Android manifest analysis reports, allowing attackers to inject malicious JavaScript by uploading crafted APK files. Exploitation can lead to session hijacking and account takeover within the victim's browser session. The vulnerability requires authenticated access and user interaction to upload the malicious APK, but it affects the confidentiality and integrity of user sessions with no impact on availability. MobSF 4.4.5 addresses this issue by properly neutralizing input. European organizations using vulnerable MobSF versions for mobile app security testing are at risk, especially those in sectors with high mobile app security demands. Join the discussion | CVE Database V5 | 01/27/2026, 00:40:36 UTC Added: 01/27/2026, 00:50:56 UTC |
Showing 1 to 5 of 5 results