Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
OpenCart version 4.2.0.0 contains a directory traversal vulnerability in its extension installer. The installer extracts uploaded .zip extension files without validating that extracted paths remain within the intended directory. This allows an attacker who can upload a malicious extension to write files outside the intended directory, such as placing a PHP web shell in the webroot. Exploitation requires valid administrator credentials to install the malicious extension. No patch is currently available, and users are advised to avoid installing untrusted extensions and to run OpenCart with minimal privileges. Join the discussion | CERT/CC | 08/10/2026, 15:33:52 UTC Added: 08/10/2026, 14:52:36 UTC |
0 CVE-2026-5331 is a medium severity path traversal vulnerability in OpenCart version 4.1.0.3, specifically in the Extension Installer Page's installer.php file. This vulnerability allows an attacker with high privileges to remotely manipulate file paths, potentially accessing unauthorized files. The vulnerability has been publicly disclosed, but no vendor response or patch is currently available. Exploitation requires high privileges, and the impact is limited by low confidentiality, integrity, and availability requirements. No known exploits are reported in the wild at this time. Join the discussion | CVE Database V5 | 04/02/2026, 13:00:13 UTC Added: 04/02/2026, 13:08:20 UTC |
0 OpenCart Core 4.0.2.3 contains a SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the 'search' parameter. Attackers can send GET requests to the product search endpoint with malicious 'search' values to extract sensitive database information using boolean-based blind or time-based blind SQL injection techniques. Join the discussion | CVE Database V5 | 03/25/2026, 16:04:35 UTC Added: 03/25/2026, 16:16:36 UTC |
0 OpenCart version 4.1.0.4 is vulnerable to a Stored Cross-Site Scripting (XSS) attack via the blog editor. The vulnerability arises because input in the blog's editor is not properly sanitized or escaped before being rendered. This allows attackers to inject malicious JavaScript code Join the discussion | CVE Database V5 | 07/25/2025, 00:00:00 UTC Added: 07/25/2025, 17:02:55 UTC |
Showing 1 to 4 of 4 results