Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 WeGIA before 3.9.2 contains an insecure direct object reference vulnerability in the employee profile page that allows authenticated attackers to access arbitrary employee records by injecting an id_pessoa parameter through a request extraction function that overwrites the session-derived identifier. Attackers can enumerate all user identifiers to retrieve full profile data for any employee account, including name, CPF, address, contact details, and administrative flags. Join the discussion | CVE Database V5 | 08/20/2026, 13:48:20 UTC Added: 08/20/2026, 14:09:22 UTC |
WeGIA before 3.9.2 contains an authorization bypass vulnerability in the password change flow that allows any authenticated user to change their account password without providing existing credentials by exploiting the unconditional exclusion of the alterarSenha method from permission checks in controle/control.php. Attackers can manipulate the redir parameter to point to alterar_senha.php, routing through verificarSenhaConfig() instead of verificarSenha() to bypass current password verification and convert temporary session access into permanent account takeover. Join the discussion | CVE Database V5 | 08/20/2026, 13:46:24 UTC Added: 08/20/2026, 13:53:21 UTC |
0 CVE-2026-45335 is an Open Redirect vulnerability in the WeGIA web manager for charitable institutions. The flaw exists in versions prior to 3.7.3 within the /WeGIA/controle/control.php endpoint, specifically involving the nextPage parameter when used with certain query parameters. The application does not properly validate or restrict this parameter, allowing attackers to redirect users to arbitrary external sites. This can facilitate phishing, credential theft, malware distribution, and social engineering attacks leveraging the trusted WeGIA domain. The vulnerability has a medium severity rating and a CVSS score of 5.4. It is fixed in version 3. Join the discussion | CVE Database V5 | 05/27/2026, 15:25:57 UTC Added: 05/27/2026, 16:33:44 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, when a user logs in, html/login.php hashes the submitted password using PHP's hash() function with the SHA-256 algorithm and no salt before comparing it to the stored value. The password change flow in controle/FuncionarioControle.php follows the same pattern. SHA-256 is a general-purpose cryptographic hash built for speed, not password storage. Without a salt, identical passwords produce identical digests, making the entire hash database vulnerable to a single precomputed rainbow table lookup. This vulnerability is fixed in 3.7.3. Join the discussion | CVE Database V5 | 05/27/2026, 15:24:21 UTC Added: 05/27/2026, 16:33:44 UTC |
0 CVE-2026-45026 is a stored Cross-Site Scripting (XSS) vulnerability in WeGIA, a web manager for charitable institutions. The flaw exists in versions prior to 3.7.3 and allows an authenticated user to inject malicious JavaScript into the Processo de Aceitação page. This script executes when users access the page, potentially enabling session hijacking and account takeover. The vulnerability has a medium severity with a CVSS score of 6.8. A fix is available in version 3.7.3. Join the discussion | CVE Database V5 | 05/11/2026, 18:36:45 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the "Etapas de um Processo" (html/atendido/etapa_processo.php) page, which is executed when user access the the page, enabling session hijacking and account takeover. This vulnerability is fixed in 3.7.3. Join the discussion | CVE Database V5 | 05/11/2026, 18:35:28 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a reflected Cross-Site Scripting (XSS) vulnerability exists in lista_arquivos_etapa.php due to improper handling of user-supplied input. The id_processo parameter is directly embedded into the HTML without sanitization, allowing attackers to inject arbitrary JavaScript. This can lead to session hijacking, credential theft, or execution of malicious actions in the context of the victim's browser. This vulnerability is fixed in 3.7.0. Join the discussion | CVE Database V5 | 05/11/2026, 18:32:45 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, a Stored Cross-Site Scripting (XSS) flaw was identified at the following endpoint: funcionario/profile_funcionario.php?id_funcionario=2. By injecting a malicious payload into the 'Description' (Descrição) field and saving the profile, the script becomes persistently stored. The payload is subsequently executed whenever the profile page is accessed. This vulnerability is fixed in 3.7.0. Join the discussion | CVE Database V5 | 05/11/2026, 18:32:03 UTC Added: 05/11/2026, 19:21:28 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive error message, including database-related details. This verbosity leads to information disclosure, which could assist a potential attacker in mapping the backend infrastructure and expanding the attack surface. This vulnerability is fixed in 3.7.0. Join the discussion | CVE Database V5 | 05/11/2026, 18:31:37 UTC Added: 05/12/2026, 01:50:53 UTC |
0 WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, a Stored Cross-Site Scripting (XSS) vulnerability was identified in the 'Member Registration' (Cadastrar Sócio) function. By injecting a payload into the 'Member Name' (Nome Sócio) field, the script is persistently stored in the database. Consequently, the payload is executed whenever a user navigates to certain URL. Version 3.6.10 fixes the issue. Join the discussion | CVE Database V5 | 04/17/2026, 20:27:59 UTC Added: 04/17/2026, 20:53:12 UTC |
Showing 1 to 10 of 55 results