Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenEMR versions prior to 8.3.0 contain a path traversal vulnerability in the EDI archive restore function. This flaw allows an authenticated user with EOB Data Entry permissions to probe arbitrary filesystem paths on the server by exploiting unsanitized input in the archrestore_sel POST parameter. The vulnerability leaks information about file existence based on differing response messages. Join the discussion | GCVE Database | 08/19/2026, 15:32:39 UTC Added: 08/19/2026, 17:55:30 UTC |
0 OpenEMR versions prior to 8.3.0 contain a cross-site request forgery (CSRF) vulnerability in the DICOM viewer component. This vulnerability arises because the web_path GET parameter is embedded directly as a URL without proper validation or sanitization. An attacker can exploit this by crafting a malicious URL that causes an authenticated user with Patients - Documents permissions to perform unintended authenticated requests, such as forced logout or other state-changing actions. Join the discussion | GCVE Database | 08/19/2026, 15:32:38 UTC Added: 08/19/2026, 17:55:32 UTC |
OpenEMR versions before 8.3.0 contain a reflected cross-site scripting (XSS) vulnerability in the patient portal template import handler. The vulnerability arises because the templateHtml GET parameter is reflected in the page response without proper sanitization. An attacker can craft a malicious URL that executes arbitrary JavaScript in the browser of any authenticated user with Forms Administration permissions who clicks the link, potentially enabling session hijacking. Join the discussion | GCVE Database | 08/19/2026, 15:32:38 UTC Added: 08/19/2026, 17:55:32 UTC |
OpenEMR versions before 8.3.0 contain a stored cross-site scripting (XSS) vulnerability in the patient portal template import handler. Authenticated users with Forms Administration permissions can upload template files containing arbitrary HTML or JavaScript. These malicious scripts are stored without proper sanitization and execute in the browsers of other Forms Administration users who view the template in the HTML editor. This vulnerability has a medium severity rating with a CVSS score of 5.4. Join the discussion | GCVE Database | 08/19/2026, 15:32:38 UTC Added: 08/19/2026, 17:55:32 UTC |
OpenEMR versions through 8.2.0 have an improper authentication vulnerability in the OAuth2 dynamic client registration endpoint. This flaw allows unauthenticated attackers to register malicious clients with system-level FHIR scopes by submitting a self-generated RSA keypair. After an administrator approves the client, attackers can use the client_credentials grant with a self-signed JWT assertion to obtain access tokens. These tokens grant read access to all FHIR resources for all patients in the system, potentially exposing sensitive health data. Join the discussion | GCVE Database | 08/03/2026, 18:30:48 UTC Added: 08/03/2026, 21:21:27 UTC |
OpenEMR versions through 8.2.0 have an authentication bypass vulnerability that allows attackers with valid credentials to circumvent multi-factor authentication. This is achieved by exploiting an exposed OAuth2 password grant flow via an unauthenticated client registration endpoint. Attackers can register an OAuth2 client without authentication and use the password grant to obtain an API access token, bypassing normal web interface authentication and MFA controls. Join the discussion | GCVE Database | 08/03/2026, 18:30:48 UTC Added: 08/03/2026, 21:21:27 UTC |
OpenEMR versions through 8.2.0 contain a critical remote code execution vulnerability in the document category tree component. Authenticated administrators can inject PHP payloads into the categories database table by exploiting a flaw that allows altering the id column type to VARCHAR and inserting malicious code. This payload is executed via an unsanitized eval() call whenever the CategoryTree class is instantiated, including on pages accessible to unauthenticated or low-privilege users, resulting in command execution as the web server user. Join the discussion | GCVE Database | 08/03/2026, 18:30:48 UTC Added: 08/03/2026, 21:21:27 UTC |
OpenEMR versions through 8.2.0 contain an authenticated SQL injection vulnerability in the backup configuration import feature. This flaw allows administrators with admin or super ACL privileges to execute arbitrary SQL statements by uploading a crafted SQL file. Exploitation can lead to unauthorized database modifications, extraction of credential hashes, creation of backdoor accounts, and arbitrary file writes if MySQL FILE privileges and permissive secure_file_priv settings are present. Join the discussion | GCVE Database | 08/03/2026, 18:30:48 UTC Added: 08/03/2026, 21:21:25 UTC |
Exploit-DB RSS Feed | 06/08/2026, 00:00:00 UTC Added: 06/08/2026, 22:13:28 UTC | |
0 An issue in OpenEMR 7.0.2 allows a remote attacker to escalate privileges viaa crafted POST request using the noteid parameter. Join the discussion | CVE Database V5 | 06/26/2024, 00:00:00 UTC Added: 02/25/2026, 21:41:01 UTC |
Showing 1 to 10 of 11 results