Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
An authorization bypass vulnerability exists in the supplier API of Roskus Prospero Flow CRM versions 4.0.0 through 5.3.1. This flaw allows any authenticated user to read and modify supplier records belonging to other companies and to reassign those records to their own company by manipulating the company_id field in a PUT request to /api/supplier/{id}. Join the discussion | GCVE Database | 08/24/2026, 15:31:51 UTC Added: 08/24/2026, 16:40:44 UTC |
An authorization bypass vulnerability exists in Roskus Prospero Flow CRM versions 5.0.0 through 5.3.5. An authenticated user can access transactions belonging to other companies on the same instance by incrementing the transaction identifier in the API endpoint GET /api/transaction/{id}. This occurs because the transaction API does not enforce company scoping or perform permission checks on the requested transaction ID. Join the discussion | GCVE Database | 08/21/2026, 12:30:34 UTC Added: 08/21/2026, 14:22:11 UTC |
A vulnerability in Roskus Prospero Flow CRM before version 5.15.9 allows unauthenticated remote attackers to authenticate as any employee onboarded through the standard flow by exploiting hard-coded credentials. The employee save controller uses a literal password "changeme" due to the onboarding form lacking a password field, enabling attackers to bypass authentication knowing only the employee's email address. Join the discussion | GCVE Database | 08/14/2026, 14:00:55 UTC Added: 08/14/2026, 16:35:52 UTC |
0 An authorization bypass vulnerability exists in the payroll module of Roskus Prospero Flow CRM versions before 5.15.10. Authenticated users with read payroll permission can view salary and banking details of employees from other companies within the same instance. Additionally, users with create payroll permission can create payroll records for employees of other companies. This occurs because the query listing is not properly scoped to the caller's company, and employee identifiers are validated only for global existence rather than company membership. Join the discussion | GCVE Database | 08/14/2026, 12:08:30 UTC Added: 08/14/2026, 16:35:53 UTC |
CVE-2026-19734 is a vulnerability in Roskus Prospero Flow CRM before version 5.4.7 involving missing authorization checks in the product management component. Authenticated users from any company can read sensitive product data of other companies and hijack products by reassigning their company_id due to improper access control. This occurs because the ProductUpdateController lacks proper authentication enforcement and the product save operation does not restrict queries to the authenticated user's company. Join the discussion | GCVE Database | 08/13/2026, 15:34:42 UTC Added: 08/13/2026, 17:48:02 UTC |
Authorization Bypass Through User-Controlled Key in the ticket management component in Roskus Prospero Flow CRM before 5.4.9 allows authenticated users of any company to read the full content (title, description, and attachments) of tickets belonging to another company, to hijack another company's tickets by reassigning their company_id, and to delete another company's tickets without any authorization check, via the ticket's numeric identifier, because the read and save operations retrieve the record without constraining the query to the authenticated user's company, and the delete controller type-hints a generic Illuminate\Http\Request instead of the TicketDeleteRequest that would enforce the required permission. Join the discussion | GCVE Database | 08/11/2026, 13:54:05 UTC Added: 08/11/2026, 18:54:04 UTC |
Showing 1 to 6 of 6 results