Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue exists in requests for resources where the session token is submitted as a URL parameter. This exposes information about the authenticated session, which can be leveraged for session hijacking. Join the discussion | CVE Database V5 | 01/04/2025, 00:00:00 UTC Added: 02/25/2026, 21:35:23 UTC |
0 An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity session issue exists in the Commerce B2B application, affecting the longevity of active sessions in the storefront. This allows session tokens tied to logged-out sessions to still be active and usable. Join the discussion | CVE Database V5 | 01/04/2025, 00:00:00 UTC Added: 02/25/2026, 21:35:23 UTC |
0 An issue was discovered in Optimizely Configured Commerce before 5.2.2408. For newly created accounts, the Commerce B2B application does not require email confirmation. This medium-severity issue allows the mass creation of accounts. This could affect database storage; also, non-requested storefront accounts can be created on behalf of visitors. Join the discussion | CVE Database V5 | 01/04/2025, 00:00:00 UTC Added: 02/25/2026, 21:35:23 UTC |
An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity issue concerning business logic exists in the Commerce B2B application, which allows storefront visitors to purchase discontinued products in specific scenarios where requests are altered before reaching the server. Join the discussion | CVE Database V5 | 01/04/2025, 00:00:00 UTC Added: 02/25/2026, 21:35:23 UTC |
0 An issue was discovered in Optimizely Configured Commerce before 5.2.2408. A medium-severity input validation issue exists in the Commerce B2B application, affecting the Contact Us functionality. This allows visitors to send e-mail messages that could contain unfiltered HTML markup in specific scenarios. Join the discussion | CVE Database V5 | 01/04/2025, 00:00:00 UTC Added: 02/25/2026, 21:35:23 UTC |
0 In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in list item names. Join the discussion | CVE Database V5 | 12/18/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:28 UTC |
0 In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from client-side template injection in search history. Join the discussion | CVE Database V5 | 12/18/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:28 UTC |
0 In Optimizely Configured Commerce before 5.2.2408, malicious payloads can be stored and subsequently executed in users' browsers under specific conditions: XSS from JavaScript in an SVG document. Join the discussion | CVE Database V5 | 12/18/2024, 00:00:00 UTC Added: 02/25/2026, 21:38:28 UTC |
Showing 1 to 8 of 8 results