Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/openpanel-dev/openpanel

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process.

Join the discussion

OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters.

Join the discussion

OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects.

Join the discussion

OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics.

Join the discussion

CVE-2026-77769 is an authorization bypass vulnerability in Openpanel-dev's openpanel product. The issue arises because the report.list procedure verifies project membership but does not confirm that the dashboardId belongs to the same project. This allows an authenticated user to access reports from dashboards outside their organization by pairing their projectId with another organization's dashboardId. The vulnerability results from improper scoping in the report retrieval function, which selects reports by dashboardId alone without project validation.

Join the discussion

CVE-2026-77768 is an authorization bypass vulnerability in the Openpanel-dev openpanel product. The vulnerability exists in the report.get procedure, which accepts only a reportId and returns the report data without proper project or organization membership checks. This allows any authenticated user to access the full configuration of any saved report by supplying its identifier. Other related procedures such as update, delete, and duplicate correctly enforce project access checks, so the issue is isolated to the report.get procedure.

Join the discussion

Showing 1 to 6 of 6 results

Filters:Package: pkg:github/openpanel-dev/openpanel
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses