Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2025-55046 is a high-severity CSRF vulnerability in MuraCMS versions through 10.1.10 that allows attackers to permanently delete all trashed content. The vulnerability exists because the cTrash.empty function does not validate CSRF tokens, enabling malicious websites to forge requests that empty the trash system when an authenticated administrator visits a crafted webpage. Exploitation requires the administrator to interact with a malicious page, which then automatically submits a hidden form to irreversibly delete trashed content without confirmation. This results in significant data loss impacting the integrity and availability of content within MuraCMS. No known exploits are currently in the wild, and no patches have been linked yet. Organizations using MuraCMS should be aware of this risk and take immediate mitigation steps to prevent data destruction. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 16:13:27 UTC |
0 CVE-2025-55045 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability in MuraCMS up to version 10.1.10 affecting the updateAddress function. The vulnerability arises because this function does not validate CSRF tokens, allowing attackers to craft malicious web pages that, when visited by an authenticated administrator, automatically submit requests to add, modify, or delete user address information. Exploitation can lead to unauthorized changes in user contact details, including injection of attacker-controlled email addresses and phone numbers, potentially redirecting sensitive communications and disrupting business operations. This manipulation compromises data integrity and user privacy and may facilitate social engineering attacks. The vulnerability requires the administrator to visit a malicious webpage but does not require additional privileges or complex conditions. Although no known exploits are currently reported in the wild, the vulnerability's ease of exploitation and impact on integrity warrant urgent attention. Organizations using MuraCMS should prioritize patching or implementing mitigations to prevent unauthorized address manipulation. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 16:13:27 UTC |
0 CVE-2025-55044 is a high-severity Cross-Site Request Forgery (CSRF) vulnerability in MuraCMS up to version 10.1.10. It allows attackers to restore deleted content from the trash to arbitrary locations without proper authorization by exploiting the lack of CSRF token validation in the cTrash.restore function. When an authenticated administrator visits a malicious webpage, their browser can be tricked into submitting a hidden form that restores content to attacker-specified parent locations. This can lead to unauthorized restoration of malicious or sensitive content, manipulation of site structure, or exposure of sensitive documents. The vulnerability requires user interaction (administrator visiting a crafted page) but no additional privileges beyond administrator authentication. No known exploits are currently reported in the wild. The CVSS v3. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 16:13:27 UTC |
0 CVE-2025-55043 is a Cross-Site Request Forgery (CSRF) vulnerability in MuraCMS versions through 10.1.10 affecting the bundle creation functionality. It allows unauthenticated attackers to trick administrators into creating site bundles containing sensitive data, which are saved to publicly accessible directories. This enables attackers to exfiltrate critical information such as user accounts, password hashes, form submissions, email lists, plugins, and site content without the administrator's knowledge. The attack requires user interaction (administrator visiting a malicious link) but no authentication by the attacker. The vulnerability has a CVSS score of 6.5 (medium severity) and does not impact integrity or availability but results in high confidentiality loss. No known exploits are currently reported in the wild. Organizations using vulnerable MuraCMS versions should implement strict CSRF protections, restrict access to bundle files, and monitor for suspicious bundle creation activity. Join the discussion | CVE Database V5 | 03/18/2026, 00:00:00 UTC Added: 03/18/2026, 16:13:27 UTC |
Showing 1 to 4 of 4 results