Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 OpenPanel js-runtime through commit bad75bdd contains a sandbox escape vulnerability in the JavaScript webhook template validator that fails to block computed member access to constructor chains. Attackers with project write access can create webhook templates using computed property notation to access Function constructor and execute arbitrary code in the worker process. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:37 UTC Added: 09/19/2026, 12:02:09 UTC |
OpenPanel tracking API through commit bad75bddc74d12d36cfb843f4531d3b830a8d994 fails to verify client secret cryptographic hash before authorizing revenue events and bot filtering. Attackers with only a public client ID can supply arbitrary dummy secrets to inject forged revenue metrics and bypass bot detection filters. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:36 UTC Added: 09/19/2026, 12:02:09 UTC |
0 OpenPanel through commit bad75bdd fails to escape property keys in ClickHouse SQL queries, allowing authenticated users to inject boolean SQL terms. Attackers can supply crafted filter names to bypass project isolation and access metrics from other projects. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:35 UTC Added: 09/19/2026, 12:02:09 UTC |
0 OpenPanel through commit bad75bdd writes Model Context Protocol authentication tokens from URL query parameters to plaintext application logs without redaction. Attackers with access to application stdout or centralized logging systems can capture base64-encoded credentials to replay MCP requests and access project analytics. Join the discussion | CVE Database V5 | 09/19/2026, 11:53:34 UTC Added: 09/19/2026, 12:02:09 UTC |
0 CVE-2026-77769 is an authorization bypass vulnerability in Openpanel-dev's openpanel product. The issue arises because the report.list procedure verifies project membership but does not confirm that the dashboardId belongs to the same project. This allows an authenticated user to access reports from dashboards outside their organization by pairing their projectId with another organization's dashboardId. The vulnerability results from improper scoping in the report retrieval function, which selects reports by dashboardId alone without project validation. Join the discussion | CVE Database V5 | 08/21/2026, 11:05:15 UTC Added: 08/21/2026, 11:23:00 UTC |
0 CVE-2026-77768 is an authorization bypass vulnerability in the Openpanel-dev openpanel product. The vulnerability exists in the report.get procedure, which accepts only a reportId and returns the report data without proper project or organization membership checks. This allows any authenticated user to access the full configuration of any saved report by supplying its identifier. Other related procedures such as update, delete, and duplicate correctly enforce project access checks, so the issue is isolated to the report.get procedure. Join the discussion | CVE Database V5 | 08/21/2026, 11:05:14 UTC Added: 08/21/2026, 11:23:00 UTC |
Showing 1 to 6 of 6 results