Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 ruoyi-ai versions 3.0.0 through 3.1.0 have a missing authorization vulnerability that allows authenticated users to delete workflows owned by other users. This occurs because the softDelete() function bypasses ownership checks, enabling deletion via a specific POST request with a workflow UUID obtained from a search endpoint. Join the discussion | CVE Database V5 | 10/09/2026, 15:04:59 UTC Added: 10/09/2026, 15:34:06 UTC |
0 ruoyi-ai 3.0.0 through 3.1.0 contains a missing authorization vulnerability in the GET /workflow/search endpoint that exposes other users' private workflows. Authenticated non-admin users can query this endpoint, which lacks owner or is_public filtering, to list enabled private workflows in the same tenant, including UUIDs and full node and edge configurations. Join the discussion | CVE Database V5 | 10/09/2026, 15:04:58 UTC Added: 10/09/2026, 15:34:06 UTC |
0 A vulnerability was found in ageerle ruoyi-ai 2.0.0 and classified as critical. Affected by this issue is the function speechToTextTranscriptionsV2/upload of the file ruoyi-modules/ruoyi-system/src/main/java/org/ruoyi/system/service/impl/SseServiceImpl.java. The manipulation of the argument File leads to unrestricted upload. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. Upgrading to version 2.0.1 is able to address this issue. The patch is identified as 4e93ac86d4891c59ecfcd27c051de9b3c5379315. It is recommended to upgrade the affected component. Join the discussion | CVE Database V5 | 06/22/2025, 05:00:14 UTC Added: 06/22/2025, 05:04:30 UTC |
Showing 1 to 3 of 3 results