Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenPanel js-runtime versions up to 2.3.0 have a critical code injection vulnerability due to improper sandboxing in the JavaScript webhook template validator. This flaw allows attackers with project write access to execute arbitrary code by exploiting computed property access to constructor chains. The vulnerability enables escape from the sandbox environment, potentially compromising the worker process. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:37 UTC Added: 09/19/2026, 12:02:09 UTC |
CVE-2026-93984 is an authentication vulnerability in Openpanel-dev's openpanel tracking API up to version 2.3.0. The API fails to verify the client secret cryptographic hash before authorizing revenue events and bot filtering. This allows attackers possessing only a public client ID to supply arbitrary dummy secrets, enabling them to inject forged revenue metrics and bypass bot detection filters. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:36 UTC Added: 09/19/2026, 12:02:09 UTC |
0 CVE-2026-93983 is a medium severity SQL injection vulnerability in Openpanel-dev's openpanel product. Versions 0 through 2.3.0 fail to properly escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. This flaw enables attackers to bypass project isolation and access metrics from other projects by supplying crafted filter names. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:35 UTC Added: 09/19/2026, 12:02:09 UTC |
0 OpenPanel versions up to 2.3.0 log Model Context Protocol authentication tokens from URL query parameters in plaintext without redaction. This allows attackers with access to application logs or stdout to capture base64-encoded credentials and potentially replay MCP requests to access project analytics. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:34 UTC Added: 09/19/2026, 12:02:09 UTC |
0 CVE-2026-77769 is an authorization bypass vulnerability in Openpanel-dev's openpanel product. The issue arises because the report.list procedure verifies project membership but does not confirm that the dashboardId belongs to the same project. This allows an authenticated user to access reports from dashboards outside their organization by pairing their projectId with another organization's dashboardId. The vulnerability results from improper scoping in the report retrieval function, which selects reports by dashboardId alone without project validation. Join the discussion | CVE Database V5 | 08/21/2026, 11:05:15 UTC Added: 08/21/2026, 11:23:00 UTC |
0 CVE-2026-77768 is an authorization bypass vulnerability in the Openpanel-dev openpanel product. The vulnerability exists in the report.get procedure, which accepts only a reportId and returns the report data without proper project or organization membership checks. This allows any authenticated user to access the full configuration of any saved report by supplying its identifier. Other related procedures such as update, delete, and duplicate correctly enforce project access checks, so the issue is isolated to the report.get procedure. Join the discussion | CVE Database V5 | 08/21/2026, 11:05:14 UTC Added: 08/21/2026, 11:23:00 UTC |
Showing 1 to 6 of 6 results