Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 open-webui v0.6.33 is vulnerable to Incorrect Access Control. The API /api/tasks/stop/ directly accesses and cancels tasks without verifying user ownership, enabling attackers (a normal user) to stop arbitrary LLM response tasks. Join the discussion | CVE Database V5 | 12/04/2025, 00:00:00 UTC Added: 12/04/2025, 15:29:43 UTC |
CVE Database V5 | 03/20/2025, 10:11:02 UTC Added: 10/15/2025, 13:01:30 UTC | |
An improper access control vulnerability in open-webui/open-webui v0.3.8 allows attackers to view and delete any files. The application does not verify whether the attacker is an administrator, allowing the attacker to directly call the GET /api/v1/files/ interface to retrieve information on all files uploaded by users, which includes the ID values. The attacker can then use the GET /api/v1/files/{file_id} interface to obtain information on any file and the DELETE /api/v1/files/{file_id} interface to delete any file. Join the discussion | CVE Database V5 | 03/20/2025, 10:10:40 UTC Added: 10/15/2025, 13:01:31 UTC |
0 In version 0.3.8 of open-webui, an endpoint for converting markdown to HTML is exposed without authentication. A maliciously crafted markdown payload can cause the server to spend excessive time converting it, leading to a denial of service. The server becomes unresponsive to other requests until the conversion is complete. Join the discussion | CVE Database V5 | 03/20/2025, 10:10:35 UTC Added: 10/15/2025, 13:01:32 UTC |
CVE Database V5 | 03/20/2025, 10:09:45 UTC Added: 10/15/2025, 13:01:31 UTC | |
In version v0.3.8 of open-webui, an improper privilege management vulnerability exists in the API endpoints GET /api/v1/documents/ and POST /rag/api/v1/doc. This vulnerability allows a lower-privileged user to access and overwrite files managed by a higher-privileged admin. By exploiting this vulnerability, an attacker can view metadata of files uploaded by an admin and overwrite these files, compromising the integrity and availability of the RAG models. Join the discussion | CVE Database V5 | 10/10/2024, 01:22:16 UTC Added: 10/15/2025, 13:01:31 UTC |
0 An Insecure Direct Object Reference (IDOR) vulnerability exists in open-webui/open-webui version v0.3.8. The vulnerability occurs in the API endpoint `http://0.0.0.0:3000/api/v1/memories/{id}/update`, where the decentralization design is flawed, allowing attackers to edit other users' memories without proper authorization. Join the discussion | CVE Database V5 | 10/09/2024, 19:57:41 UTC Added: 10/15/2025, 13:01:31 UTC |
Showing 1 to 7 of 7 results