Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-4355 is a medium severity cross-site scripting (XSS) vulnerability found in Portabilis i-Educar version 2.11, specifically in the /intranet/educar_servidor_curso_lst.php file. The vulnerability arises from improper sanitization of the 'Name' argument, allowing remote attackers to inject malicious scripts. Exploitation requires no authentication but does require user interaction, such as a victim clicking a crafted link. The vendor has not responded to disclosure attempts, and no patches are currently available. Although no known exploits are in the wild, the exploit code is publicly available, increasing the risk of attacks. This vulnerability can lead to session hijacking, credential theft, or unauthorized actions within the affected web application. Organizations using i-Educar 2.11 should prioritize mitigation to prevent exploitation. Join the discussion | CVE Database V5 | 03/17/2026, 23:32:14 UTC Added: 03/17/2026, 23:43:22 UTC |
A vulnerability was identified in Portabilis i-Educar up to 2.10. Affected by this vulnerability is an unknown functionality of the file /intranet/meusdadod.php of the component User Data Page. Such manipulation of the argument File leads to cross site scripting. It is possible to launch the attack remotely. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 02/06/2026, 19:32:07 UTC Added: 02/06/2026, 19:45:10 UTC |
A weakness has been identified in Portabilis i-Educar up to 2.10. Affected is an unknown function of the file FinalStatusImportService.php of the component Final Status Import. Executing a manipulation of the argument school_id can lead to improper authorization. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 02/06/2026, 10:32:07 UTC Added: 02/06/2026, 10:45:26 UTC |
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Portabilis i-Educar allows Stored Cross-Site Scripting (XSS) via the matricula_interna parameter in the educar_usuario_cad.php endpoint. This issue affects i-Educar: 2.10.0. Join the discussion | CVE Database V5 | 12/09/2025, 15:59:13 UTC Added: 12/09/2025, 16:11:42 UTC |
0 CVE-2025-65022 is a high-severity SQL injection vulnerability affecting portabilis i-educar versions 2.10.0 and earlier. It allows an authenticated attacker to execute arbitrary SQL commands via the cod_agenda parameter in the ieducar/intranet/agenda.php script due to improper input sanitization. Exploitation requires an authenticated session but no user interaction beyond that. The vulnerability impacts confidentiality, integrity, and availability of the application’s database. Although no known exploits are currently in the wild, the vulnerability has been patched in a recent commit. European educational institutions using i-educar are at risk, especially in countries with higher adoption of this software. Mitigation involves applying the patch, restricting authenticated user privileges, and implementing strict input validation. Join the discussion | CVE Database V5 | 11/19/2025, 16:02:13 UTC Added: 11/19/2025, 16:12:51 UTC |
0 i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/funcionario_vinculo_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_funcionario_vinculo GET parameter, which is directly concatenated into an SQL query without proper sanitization. This issue has been patched in commit a00dfa3. Join the discussion | CVE Database V5 | 11/19/2025, 16:02:10 UTC Added: 11/19/2025, 16:12:51 UTC |
0 i-Educar is free, fully online school management software. In versions 2.10.0 and prior, an authenticated time-based SQL injection vulnerability exists in the ieducar/intranet/agenda_admin_cad.php script. An attacker with access to an authenticated session can execute arbitrary SQL commands against the application's database. This vulnerability is caused by the improper handling of the cod_agenda GET parameter, which is directly concatenated into an SQL query without proper sanitization. This issue has been patched in commit 3e9763a. Join the discussion | CVE Database V5 | 11/19/2025, 16:02:06 UTC Added: 11/19/2025, 16:12:51 UTC |
A vulnerability, which was classified as problematic, has been found in Portabilis i-Educar 2.9.0. Affected by this issue is some unknown functionality of the file intranet/educar_turma_tipo_det.php?cod_turma_tipo=ID of the component Turma Module. The manipulation of the argument nm_tipo leads to cross site scripting. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/20/2025, 05:02:05 UTC Added: 07/20/2025, 05:16:08 UTC |
A vulnerability was found in Portabilis i-Educar up to 2.10. This issue affects some unknown processing of the file /intranet/educar_calendario_dia_motivo_cad.php of the component Calendar Module. The manipulation of the argument Motivo/descricao results in cross site scripting. It is possible to launch the attack remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/20/2025, 04:32:05 UTC Added: 07/20/2025, 04:46:08 UTC |
A vulnerability has been found in Portabilis i-Educar 2.9.0/2.10.0. This vulnerability affects unknown code of the file /intranet/agenda.php of the component Agenda Module. The manipulation of the argument novo_titulo/novo_descricao leads to cross site scripting. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 07/20/2025, 04:02:05 UTC Added: 07/20/2025, 04:31:17 UTC |
Showing 1 to 10 of 11 results