Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/newbee-ltd/newbee-mall

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-105573 is a medium severity vulnerability in newbee-ltd newbee-mall versions 2.7.0 through 2.7.5. It involves business logic errors triggered by manipulation of the goodsCount argument in the Shopping Cart Quantity Handler component. The vulnerability can be exploited remotely without user interaction. Although the issue was reported early, the vendor has not yet responded or issued a fix. Public exploit code exists, but no known active exploitation in the wild has been reported.

Join the discussion

newbee-mall stores and verifies user passwords using an unsalted MD5 hashing algorithm. The implementation does not incorporate per-user salts or computational cost controls, enabling attackers who obtain password hashes through database exposure, backup leakage, or other compromise vectors to rapidly recover plaintext credentials via offline attacks.

Join the discussion

newbee-mall includes pre-seeded administrator accounts in its database initialization script. These accounts are provisioned with a predictable default password. Deployments that initialize or reset the database using the provided schema and fail to change the default administrative credentials may allow unauthenticated attackers to log in as an administrator and gain full administrative control of the application.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/newbee-ltd/newbee-mall
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses