Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, which are used to manage sketches and analyses. Sketches have controllable graphs, which are comprised of nodes and relationships. The sketches contain information on an OSINT target (usernames, websites, etc) within these nodes and relationships. A remote attacker can create a node with a malicious description that contains arbitrary HTML. When the node is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3. Join the discussion | CVE Database V5 | 05/14/2026, 15:39:21 UTC Added: 05/14/2026, 16:06:42 UTC |
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, an adversary with knowledge of an investigation ID, could update the metadata of an investigation of another user. This vulnerability is fixed in 1.2.3. Join the discussion | CVE Database V5 | 05/12/2026, 23:01:23 UTC Added: 05/13/2026, 01:50:03 UTC |
0 Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a node with a malicious type that can escape an existing Cypher query and an adversary can execute an arbitrary Cypher query. This vulnerability is fixed in 1.2.3. Join the discussion | CVE Database V5 | 05/12/2026, 23:00:03 UTC Added: 05/13/2026, 01:50:03 UTC |
0 Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, a remote attacker can create a map node with a malicious label that contains arbitrary HTML. When the map tab is selected and a map node marker is selected, it will render the arbitrary HTML, potentially triggering stored XSS. This vulnerability is fixed in 1.2.3. Join the discussion | CVE Database V5 | 05/12/2026, 22:58:26 UTC Added: 05/13/2026, 01:50:03 UTC |
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs from any user. This vulnerability is fixed in 1.2.3. Join the discussion | CVE Database V5 | 05/12/2026, 22:55:12 UTC Added: 05/13/2026, 01:50:03 UTC |
CVE-2026-32311 is a critical OS command injection vulnerability in the open-source OSINT tool Flowsint by reconurge. The flaw allows a remote attacker to create a sketch and trigger the 'org_to_asn' transformer on an organization node, leading to arbitrary OS command execution as root via shell metacharacters and a Docker container escape. This vulnerability affects versions of Flowsint prior to commit b52cbbb904c8013b74308d58af88bc7dbb1b055c. The problematic code appears to have been removed in that commit. No official patch or advisory is explicitly provided, and no known exploits are reported in the wild. The CVSS 4.0 score is 9.3, indicating critical severity. Join the discussion | CVE Database V5 | 04/20/2026, 19:56:32 UTC Added: 04/20/2026, 20:01:07 UTC |
Showing 1 to 6 of 6 results