Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenMetadata versions prior to 2.0.0 contain an open redirect vulnerability where the application accepts a user-supplied post-authentication redirect URL without validation. This allows an attacker to craft a URL that redirects users to an untrusted site while appending a valid authentication token, potentially handing over user account control to the attacker. Version 2.0.0 removes this vulnerable callback parameter. Join the discussion | CVE Database V5 | 08/26/2026, 15:44:57 UTC Added: 08/26/2026, 15:52:59 UTC |
0 OpenMetadata is a unified metadata platform. Prior to version 1.12.4, a non-admin SSO user can trigger a TEST_CONNECTION workflow for a Database Service and receive, in the HTTP 201 response of POST /api/v1/automations/workflows, both the cleartext database password in request.connection.config.password and the ingestion bot JWT in openMetadataServerConnection.securityConfig.jwtToken. The leaked ingestion-bot token can then be reused as Authorization: Bearer <jwt> to access sensitive service APIs with bot-level privileges. This issue has been patched in version 1.12.4. Join the discussion | CVE Database V5 | 06/08/2026, 16:51:06 UTC Added: 06/08/2026, 17:06:22 UTC |
0 OpenMetadata is a unified metadata platform. Versions 1.5.0 through 1.11.3 are vulnerable to remote code execution via Server-Side Template Injection (SSTI) in FreeMarker email templates. An attacker must have administrative privileges to exploit the vulnerability. Version 1.11.4 contains a patch. Join the discussion | CVE Database V5 | 01/08/2026, 15:12:51 UTC Added: 01/08/2026, 15:35:18 UTC |
Showing 1 to 3 of 3 results