Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation of the group IDs supplied. The resolver passes the caller's arguments straight to the model without any ownership check or restriction on which groups can be assigned. A user with manage:users — a permission typically delegated to wiki moderators for account management — can set groups:[1] on their own account to self-assign to the Administrators group. After re-authentication, the fresh JWT carries manage:system, granting full site administrator access in a single mutation call. This vulnerability is fixed in 2.5.313. Join the discussion | CVE Database V5 | 05/12/2026, 20:33:53 UTC Added: 05/12/2026, 20:51:27 UTC |
0 CVE-2026-34735 is a high-severity vulnerability in HytaleModding wiki versions 1.2.0 and earlier. The quickUpload() endpoint improperly validates uploaded files by checking MIME type independently from the client-supplied file extension. This allows an attacker to upload files with dangerous extensions like . php that pass MIME type checks but can be executed on the server, leading to server-side code execution. No patches or official fixes are currently available for this issue. Join the discussion | CVE Database V5 | 04/02/2026, 18:23:26 UTC Added: 04/02/2026, 18:40:27 UTC |
CVE-2026-32736 is an Insecure Direct Object Reference (IDOR) vulnerability affecting versions of the Hytale Modding Wiki prior to 1.0.0. This vulnerability allows any authenticated user to access personal information of mod authors, including full names and email addresses, by simply visiting a mod page. Exploitation requires only account creation and no additional user interaction. The flaw stems from missing authorization checks when accessing mod author data. The vulnerability has a CVSS score of 4.3, indicating medium severity, with confidentiality impacted but no effect on integrity or availability. Version 1.0. Join the discussion | CVE Database V5 | 03/18/2026, 22:06:10 UTC Added: 03/18/2026, 22:28:22 UTC |
Showing 1 to 3 of 3 results