Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Kiteworks Secure Data Forms versions prior to 9.3.0 contain a stored cross-site scripting (XSS) vulnerability. This flaw allows an authenticated attacker to inject and execute arbitrary JavaScript code in other users' sessions. The vulnerability is fixed in version 9.3.0 and later. Join the discussion | CVE Database V5 | 06/01/2026, 21:46:56 UTC Added: 06/01/2026, 22:33:44 UTC |
Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP to still authenticate towards user OIDC after they where deleted. This issue has been patched in version 8.4.0. Join the discussion | CVE Database V5 | 06/01/2026, 16:57:56 UTC Added: 06/01/2026, 19:52:38 UTC |
Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder or file with a Nextcloud Team that includes an external member (a person added via email address who does not have a Nextcloud account), the system automatically creates a public link for that external member. This public link is not displayed in the share section of the folder, so the folder owner has no knowledge of its existence. It is sent via email to the external member. It grants the same permissions (read, write, delete, reshare, download) as the Team’s access. An attacker who receives or intercepts this link can access, modify, delete, reshare, and download all data in the shared folder without any further authentication. The folder owner cannot see or revoke the link through the normal sharing interface. This issue has been patched in versions 32.0.9 and 33.0.3. Join the discussion | CVE Database V5 | 06/01/2026, 16:57:50 UTC Added: 06/01/2026, 19:52:38 UTC |
0 Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses the attackers link to log in via user OIDC. This issue has been patched in version 8.2.2. Join the discussion | CVE Database V5 | 06/01/2026, 16:51:55 UTC Added: 06/01/2026, 19:52:38 UTC |
0 CVE-2026-45277 is a low-severity vulnerability in Nextcloud security-advisories prior to version 2.7.2. Authenticated users could determine whether arbitrary files were linked to specific approval workflows, potentially exposing sensitive information. This issue does not allow modification or denial of service and has been addressed in Nextcloud version 2.7.2. Join the discussion | CVE Database V5 | 06/01/2026, 16:51:34 UTC Added: 06/01/2026, 19:52:38 UTC |
0 Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been patched in version 5.2.6. Join the discussion | CVE Database V5 | 06/01/2026, 16:40:18 UTC Added: 06/01/2026, 17:04:39 UTC |
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-performance Backend is installed. This issue has been patched in versions 21.1.10, 22.0.11, and 23.0.3. Join the discussion | CVE Database V5 | 06/01/2026, 16:39:56 UTC Added: 06/01/2026, 17:04:39 UTC |
0 Nextcloud versions from 1.15.0 up to but not including 1.15.4, 1.16.0 up to 1.16.3, 1.17. Join the discussion | CVE Database V5 | 06/01/2026, 16:39:38 UTC Added: 06/01/2026, 17:04:39 UTC |
Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks Email Protection Gateway allows authenticated administrators to inject malicious scripts through a configuration interface. The stored script executes when users interact with the affected user interface. Version 9.2.0 contains a patch for the issue. Join the discussion | CVE Database V5 | 02/27/2026, 20:22:59 UTC Added: 02/27/2026, 20:41:10 UTC |
0 Kiteworks is a private data network (PDN). Prior to version 9.2.0, a vulnerability in Kiteworks configuration functionality allows bypassing of SSRF protections through DNS rebinding attacks. Malicious administrators could exploit this to access internal services that should be restricted. Version 9.2.0 contains a patch for the issue. Join the discussion | CVE Database V5 | 02/27/2026, 20:21:12 UTC Added: 02/27/2026, 20:41:10 UTC |
Showing 1 to 10 of 17 results