Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-53959 is a vulnerability in RARgames 4gaBoards prior to version 3.3.9 that allows any authenticated user to enumerate and retrieve sensitive account information of all users. The exposed data includes email addresses, phone numbers, organization details, admin status, and SSO-linked emails. This flaw arises because the API endpoints /api/users and /api/users/:id lack proper authorization checks and response sanitization. The vulnerability enables privacy breaches and facilitates targeted phishing attacks. It is fixed in version 3.3.9. Join the discussion | CVE Database V5 | 08/18/2026, 21:35:55 UTC Added: 08/18/2026, 21:50:01 UTC |
CVE-2026-53958 is an improper authentication vulnerability in 4gaBoards prior to version 3.3.9. It allows an authenticated user to modify backend-managed single sign-on (SSO) identity attributes via a PATCH request to the user API. This flaw enables an attacker to associate a victim's SSO provider identifier with the attacker's account, causing the victim to be logged into the attacker-controlled account upon their first SSO login. The vulnerability is fixed in version 3.3.9. Join the discussion | CVE Database V5 | 08/18/2026, 21:34:59 UTC Added: 08/18/2026, 21:50:04 UTC |
0 CVE-2026-50186 is a path traversal vulnerability in 4gaBoards prior to version 3.3.8. An authenticated project manager can exploit this flaw by supplying traversal sequences in the filename parameter of a GET request, allowing access to arbitrary files on the server. Additionally, the vulnerability can cause deletion of arbitrary files due to improper handling of the file path after download. This issue is fixed in version 3.3.8. Join the discussion | CVE Database V5 | 08/18/2026, 21:34:05 UTC Added: 08/18/2026, 21:50:01 UTC |
4gaBoards versions prior to 3.3.8 have an improper authentication vulnerability that allows attackers to create unverified local accounts using a victim's email when multiple registration methods and SSO providers are enabled. This flaw enables attackers to link their local account to the victim's verified SSO identity without ownership verification, retaining password access and gaining unauthorized access to the victim's projects and data. The issue is resolved in version 3.3.8. Join the discussion | CVE Database V5 | 08/18/2026, 21:33:16 UTC Added: 08/18/2026, 21:50:01 UTC |
0 4ga Boards is a boards system for realtime project management. Prior to 3.3.5, a path traversal vulnerability allows an authenticated user with board import privileges to make the server ingest arbitrary host files as board attachments during BOARDS archive import. Once imported, the file can be downloaded through the normal application interface, resulting in unauthorized local file disclosure. This vulnerability is fixed in 3.3.5. Join the discussion | CVE Database V5 | 04/24/2026, 18:50:44 UTC Added: 04/24/2026, 19:22:45 UTC |
CVE-2026-41418 is a timing side-channel vulnerability in 4ga Boards versions prior to 3.3.5 that allows user enumeration via the login endpoint. The server responds significantly faster when an invalid username/email is provided compared to a valid username/email with an incorrect password, due to the bcrypt.compareSync() operation. This timing difference is easily detectable over a network with a single request. The vulnerability has a medium severity with a CVSS score of 5.3 and is fixed in version 3.3.5. Join the discussion | CVE Database V5 | 04/24/2026, 18:49:38 UTC Added: 04/24/2026, 19:22:45 UTC |
Showing 1 to 6 of 6 results