Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Attacker can use the IMAP SETACL command to inject the anyone permission to user's dovecot-acl file even if imap_acl_allow_anyone=no. This causes folders to be spammed to all users. The impact is limited to being able to spam folders to other users, no unexpected access is gained. Install to fixed version. No publicly available exploits are known. Join the discussion | CVE Database V5 | 05/12/2026, 13:28:46 UTC Added: 05/12/2026, 14:06:29 UTC |
CVE-2026-27860 is an LDAP injection vulnerability in Open-Xchange GmbH's OX Dovecot Pro. It occurs if the configuration parameter auth_username_chars is empty, allowing injection of arbitrary LDAP filters during LDAP authentication. This can potentially bypass restrictions and enable probing of the LDAP structure. No public exploits are known, and the vulnerability has a low severity rating with a CVSS score of 3.7. Join the discussion | CVE Database V5 | 03/27/2026, 08:10:22 UTC Added: 03/27/2026, 08:29:49 UTC |
0 Having a large number of address headers (From, To, Cc, Bcc, etc.) becomes excessively CPU intensive. With 100k header lines CPU usage is already 12 seconds, and in a production environment we observed 500k header lines taking 18 minutes to parse. Since this can be triggered by external actors sending emails to a victim, this is a security issue. An external attacker can send specially crafted messages that consume target system resources and cause outage. One can implement restrictions on address headers on MTA component preceding Dovecot. No publicly available exploits are known. Join the discussion | CVE Database V5 | 09/10/2024, 14:33:34 UTC Added: 11/04/2025, 16:46:31 UTC |
Showing 1 to 3 of 3 results