Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 osTicket versions from 1.10 up to 1.17.7 and from 1.18.0 up to 1.18.3 are vulnerable to a stored XSS due to a vulnerable Bootstrap Tooltip component and insufficient HTML sanitization, allowing remote attackers to execute arbitrary JavaScript in Agent or Admin sessions. Join the discussion | CVE Database V5 | 07/14/2026, 00:00:00 UTC Added: 07/14/2026, 16:48:07 UTC |
0 osTicket version 1.18.2 contains a session fixation vulnerability that allows an attacker to hijack a user's account by reusing the initial session identifier (OSTSESSID) after login. The application fails to invalidate or regenerate the session ID upon authentication, enabling unauthorized access if an attacker sets a known session ID in the victim's browser. Join the discussion | CVE Database V5 | 06/16/2026, 11:47:56 UTC Added: 06/16/2026, 13:15:51 UTC |
0 A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argument _method leads to cross-site request forgery. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The project was informed of the problem early through a pull request but has not reacted yet. Join the discussion | CVE Database V5 | 05/09/2026, 19:30:09 UTC Added: 05/09/2026, 19:36:29 UTC |
0 User enumeration vulnerability in /pwreset.php in osTicket v1.18.2 allows remote attackers to enumerate valid usernames registered in the platform. Join the discussion | CVE Database V5 | 04/02/2026, 00:00:00 UTC Added: 04/02/2026, 18:40:54 UTC |
Enhancesoft osTicket versions 1.18.x prior to 1.18.3 and 1.17.x prior to 1.17.7 contain an arbitrary file read vulnerability in the ticket PDF export functionality. A remote attacker can submit a ticket containing crafted rich-text HTML that includes PHP filter expressions which are insufficiently sanitized before being processed by the mPDF PDF generator during export. When the attacker exports the ticket to PDF, the generated PDF can embed the contents of attacker-selected files from the server filesystem as bitmap images, allowing disclosure of sensitive local files in the context of the osTicket application user. This issue is exploitable in default configurations where guests may create tickets and access ticket status, or where self-registration is enabled. Join the discussion | CVE Database V5 | 01/12/2026, 18:34:12 UTC Added: 01/12/2026, 18:53:46 UTC |
Showing 1 to 5 of 5 results