Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-9575 is a medium severity SQL injection vulnerability in itsourcecode Student Transcript Processing System version 1.0. The issue arises from improper handling of the 'ID' parameter in the /admin/modules/class/index.php? view=view endpoint, allowing remote attackers to inject SQL commands. The vulnerability has been publicly disclosed, but no official patch or remediation guidance is currently available. Join the discussion | CVE Database V5 | 05/26/2026, 19:30:12 UTC Added: 05/26/2026, 19:42:52 UTC |
CVE-2026-9574 is a medium-severity SQL injection vulnerability in itsourcecode Student Transcript Processing System version 1.0. The flaw exists in the /admin/modules/student/trans.php file, where manipulation of the studentId or cid parameters can lead to SQL injection. The vulnerability can be exploited remotely without authentication. Although an exploit has been published, there is no confirmed patch or official remediation available at this time. Join the discussion | CVE Database V5 | 05/26/2026, 19:15:11 UTC Added: 05/26/2026, 19:42:52 UTC |
A vulnerability has been found in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/admin/login.php. The manipulation of the argument Username leads to sql injection. Remote exploitation of the attack is possible. The exploit has been disclosed to the public and may be used. Join the discussion | CVE Database V5 | 05/24/2026, 13:15:10 UTC Added: 05/24/2026, 14:01:37 UTC |
A vulnerability was identified in itsourcecode Electronic Judging System 1.0. This affects an unknown part of the file /intrams/login.php. Such manipulation of the argument Username leads to sql injection. The attack can be launched remotely. The exploit is publicly available and might be used. Join the discussion | CVE Database V5 | 05/01/2026, 05:45:10 UTC Added: 05/01/2026, 05:51:23 UTC |
CVE-2026-5256 is a medium severity SQL injection vulnerability in version 1.0 of code-projects Simple Laundry System. The flaw exists in the /modify.php file within the Parameter Handler component, where manipulation of the firstName argument can lead to SQL injection. This vulnerability can be exploited remotely without authentication or user interaction. Although an exploit has been published, there are no known exploits observed in the wild. No official patch or remediation guidance is currently available from the vendor. Join the discussion | CVE Database V5 | 04/01/2026, 06:00:17 UTC Added: 04/01/2026, 06:23:17 UTC |
A vulnerability was detected in code-projects Simple Laundry System 1.0. This affects an unknown part of the file /delstaffinfo.php of the component Parameter Handler. The manipulation of the argument userid results in cross site scripting. The attack may be launched remotely. The exploit is now public and may be used. Join the discussion | CVE Database V5 | 04/01/2026, 05:15:14 UTC Added: 04/01/2026, 05:38:17 UTC |
0 ZenTaoPMS v18.11 through v21.6.beta is vulnerable to Directory Traversal in /module/ai/control.php. This allows attackers to execute arbitrary code via a crafted file upload Join the discussion | CVE Database V5 | 02/26/2026, 00:00:00 UTC Added: 02/26/2026, 19:41:03 UTC |
A vulnerability was found in itsourcecode Directory Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/forget-password.php. The manipulation of the argument email results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used. Join the discussion | CVE Database V5 | 02/08/2026, 16:02:07 UTC Added: 02/08/2026, 16:16:15 UTC |
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be launched remotely. The exploit has been made public and could be used. Join the discussion | CVE Database V5 | 12/14/2025, 09:02:06 UTC Added: 12/14/2025, 09:13:33 UTC |
Showing 1 to 9 of 9 results