Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/nagios/fusion

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A maliciously crafted add-in, when installed and executed in Autodesk Fusion Desktop, can modify persistent network proxy settings without user notification or consent. A successful exploit may allow an attacker to redirect authenticated Fusion network traffic through an attacker-controlled proxy, potentially exposing sensitive information with the current user.

Join the discussion

A maliciously crafted HTML payload in a component name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Join the discussion

A maliciously crafted HTML payload in an assembly variant name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Join the discussion

A maliciously crafted HTML payload, stored in a component’s description and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Join the discussion

A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Join the discussion

A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current process.

Join the discussion

CVE-2023-53689 is a reflected cross-site scripting (XSS) vulnerability in Nagios Fusion versions prior to 4.2.0, specifically in the license key configuration flow. An attacker can craft a malicious URL that, when visited by an authenticated user with administrative privileges, executes attacker-controlled scripts in the user's browser. This can lead to session or credential theft and unauthorized administrative actions, although the server itself is not directly compromised. The vulnerability requires user interaction and high privileges but no authentication bypass. It has a CVSS score of 6.0 (medium severity). European organizations using Nagios Fusion for IT infrastructure monitoring should prioritize patching or mitigating this issue to prevent browser-based attacks targeting administrators.

Join the discussion

CVE-2023-53690 is a stored cross-site scripting (XSS) vulnerability affecting Nagios Fusion versions prior to 4.2.0. The flaw exists in the LDAP/AD authentication-server configuration, where unsanitized user input can be stored and later rendered in the administrative UI. This allows an attacker with privileges to add authentication servers to inject malicious JavaScript that executes in the browsers of other users viewing the affected page. Exploitation requires high privileges to add LDAP/AD servers and user interaction to trigger the payload. The vulnerability has a CVSS 4.0 score of 6.2, indicating medium severity. No known exploits are currently reported in the wild.

Join the discussion

CVE-2023-7312 is a stored cross-site scripting (XSS) vulnerability in Nagios Fusion versions prior to 4.2.0. It arises from improper input sanitization when configuring Email Settings, allowing attackers with high privileges to inject malicious JavaScript payloads. These payloads execute in the browsers of users who access the affected administrative UI pages. Exploitation requires authenticated access with privileges to modify SMTP/email settings, and user interaction is needed to trigger the payload. The vulnerability has a CVSS score of 6.2, indicating medium severity. No known public exploits exist currently. European organizations using Nagios Fusion for IT infrastructure monitoring should prioritize patching to prevent potential compromise of administrative sessions and data.

Join the discussion
CVE-2025-60424: n/aCVE-2025-60424
0

CVE-2025-60424 is a high-severity vulnerability in Nagios Fusion versions v2024R1.2 and v2024R2 where the OTP verification component lacks rate limiting, enabling attackers with low privileges to perform brute-force attacks to bypass authentication. This flaw impacts confidentiality and integrity by allowing unauthorized access without user interaction. The vulnerability requires network access and low privileges but no user interaction, making exploitation relatively feasible in targeted environments. European organizations using affected Nagios Fusion versions for IT infrastructure monitoring could face unauthorized access risks, potentially leading to data breaches or manipulation of monitoring data. No known exploits are currently reported in the wild, but the absence of patches increases urgency for mitigation. Organizations should implement strict network segmentation, monitor authentication attempts, and apply compensating controls until official patches are released. Countries with significant Nagios Fusion deployments, such as Germany, the UK, France, and the Netherlands, are more likely to be impacted due to their large IT infrastructure sectors and reliance on monitoring tools. Given the vulnerability's characteristics and CVSS score of 7.6, it is classified as high severity.

Join the discussion

Showing 1 to 10 of 10 results

Filters:Package: pkg:github/nagios/fusion
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses