Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/requarks/wiki

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without any ownership check or restriction on which groups can be assigned. A user with manage:users — a permission typically delegated to wiki moderators for account management — can set groups:[1] on their own account to self-assign to the Administrators group. After re-authentication, the fresh JWT carries manage:system, granting full site administrator access in a single mutation call. This vulnerability is fixed in 2.5.313.

Join the discussion

CVE-2026-34735 is a high-severity vulnerability in HytaleModding wiki versions 1.2.0 and earlier. The quickUpload() endpoint improperly validates uploaded files by checking MIME type independently from the client-supplied file extension. This allows an attacker to upload files with dangerous extensions like . php that pass MIME type checks but can be executed on the server, leading to server-side code execution. No patches or official fixes are currently available for this issue.

Join the discussion

CVE-2026-32736 is an Insecure Direct Object Reference (IDOR) vulnerability affecting versions of the Hytale Modding Wiki prior to 1.0.0. This vulnerability allows any authenticated user to access personal information of mod authors, including full names and email addresses, by simply visiting a mod page. Exploitation requires only account creation and no additional user interaction. The flaw stems from missing authorization checks when accessing mod author data. The vulnerability has a CVSS score of 4.3, indicating medium severity, with confidentiality impacted but no effect on integrity or availability. Version 1.0.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/requarks/wiki
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses