Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

A vulnerability was determined in OpenBoxes up to 0.9.7. (CVE-2026-19928)CVE-2026-19928
0

A vulnerability in OpenBoxes up to version 0.9.7 affects the needManager function in the RoleInterceptor component, allowing improper privilege management. The issue can be exploited remotely without user interaction. Public exploit code is available. Upgrading to versions 0.9.8 or 0.9.8-hotfix1 mitigates the vulnerability.

Join the discussion
A vulnerability was identified in OpenBoxes up to 0.9.6. (CVE-2026-19929)CVE-2026-19929
0

A vulnerability in OpenBoxes up to version 0.9.6 affects the Template Processing component, specifically the buildZebraTemplate function in DocumentController.groovy. This flaw allows improper neutralization of special elements in the template engine, enabling remote exploitation. Public exploit code exists. Upgrading to versions 0.9.8 or 0.9.8-hotfix1 resolves the issue.

Join the discussion
A vulnerability was found in OpenBoxes up to 0.9.7. (CVE-2026-19927)CVE-2026-19927
0

A server-side request forgery (SSRF) vulnerability exists in OpenBoxes up to version 0.9.7 in the Product Upload Endpoint. This vulnerability is due to improper validation of the params.url argument in the Upload function of ProductController.groovy. Remote attackers can exploit this flaw to cause the server to make unintended requests. The issue is resolved by upgrading to versions 0.9.8-hotfix1 or 0.9.8.

Join the discussion
CVE-2026-19929: Improper Neutralization of Special Elements Used in a Template Engine in OpenBoxesCVE-2026-19929
0

A vulnerability was identified in OpenBoxes up to 0.9.6. This impacts the function buildZebraTemplate of the file grails-app/controllers/org/pih/warehouse/core/DocumentController.groovy of the component Template Processing. The manipulation leads to improper neutralization of special elements used in a template engine. It is possible to initiate the attack remotely. The exploit is publicly available and might be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 will fix this issue. The identifier of the patch is deeac6a4a7aba86ce99c4bda37142e41d209293e. It is recommended to upgrade the affected component.

Join the discussion
CVE-2026-19928: Improper Privilege Management in OpenBoxesCVE-2026-19928
0

A vulnerability was determined in OpenBoxes up to 0.9.7. This affects the function needManager of the file grails-app/controllers/org/pih/warehouse/RoleInterceptor.groovy of the component Role Interceptor. Executing a manipulation can lead to improper privilege management. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. Upgrading to version 0.9.8-hotfix1 and 0.9.8 mitigates this issue. This patch is called 788cace0af816aa972a713a4631c57f16f895e6b. Upgrading the affected component is recommended.

Join the discussion
CVE-2026-19927: Server-Side Request Forgery in OpenBoxesCVE-2026-19927
0

A vulnerability was found in OpenBoxes up to 0.9.7. The impacted element is the function Upload of the file grails-app/controllers/org/pih/warehouse/product/ProductController.groovy of the component Product Upload Endpoint. Performing a manipulation of the argument params.url results in server-side request forgery. The attack is possible to be carried out remotely. The exploit has been made public and could be used. Upgrading to version 0.9.8-hotfix1 and 0.9.8 is sufficient to resolve this issue. The patch is named a599007325efe780a21b3537ecce3ca25635c926. It is suggested to upgrade the affected component.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/openboxes/OpenBoxes
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses