Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Serendipity before 2.6.0 contains a server-side request forgery vulnerability in the serendipity_url_allowed() filter that fails to block hex-encoded IPv4 addresses, IPv6 literals, and link-local ranges. Authenticated users with adminImagesAdd permission can bypass the filter using alternate address formats to request internal services and retrieve response bodies through the public uploads directory. Join the discussion | CVE Database V5 | 08/13/2026, 11:28:27 UTC Added: 08/13/2026, 12:52:13 UTC |
0 Serendipity versions >= 2.3.5 and <= 2.6.0 contain a reflected cross-site scripting vulnerability in the search clean-URL route (/search/<term>). In include/functions_routing.inc.php serveSearch(), the sanitisation pipeline runs urldecode() after HTML-encoding, so a single URL-encoded HTML payload survives strip_tags() and htmlspecialchars() and is then decoded back into live HTML in the page. A crafted search link can execute arbitrary JavaScript in the victim's browser. Fixed in 2.6.1. Join the discussion | CVE Database V5 | 08/13/2026, 11:28:26 UTC Added: 08/13/2026, 12:52:13 UTC |
0 Serendipity before 2.6.1 contains an open redirect vulnerability in exit.php that allows unauthenticated attackers to redirect users to arbitrary external sites by supplying a malicious Base64-encoded url parameter when the Track Exits plugin is configured with commentredirection set to s9y. Attackers can craft trusted-looking URLs leveraging the legitimate blog domain to conduct phishing, deliver malware, or bypass URL reputation filters. Join the discussion | CVE Database V5 | 07/31/2026, 14:19:01 UTC Added: 07/31/2026, 14:53:03 UTC |
Serendipity versions prior to 2.6.0 contain a vulnerability where the HTTP Host header is improperly sanitized before being inserted into the Message-ID SMTP header during email sending. This allows an attacker controlling the Host header to inject arbitrary SMTP headers into outgoing emails, potentially enabling identity spoofing, reply hijacking, and email reputation abuse. The issue is fixed in version 2.6.0. Join the discussion | CVE Database V5 | 04/14/2026, 23:35:49 UTC Added: 04/15/2026, 00:01:58 UTC |
0 Serendipity versions prior to 2.6.0 contain a vulnerability where the function serendipity_setCookie() uses the HTTP Host header without validation when setting cookies. This allows an attacker who can manipulate the Host header during login to cause authentication cookies to be scoped to an attacker-controlled domain. The vulnerability enables session fixation, token leakage, and potential privilege escalation if an administrator logs in under a manipulated Host header. The issue is fixed in version 2.6.0. Join the discussion | CVE Database V5 | 04/14/2026, 23:31:13 UTC Added: 04/15/2026, 00:01:58 UTC |
Serendipity 2.4.0 contains a remote code execution vulnerability that allows authenticated attackers to upload malicious PHP files with .phar extension. Attackers can upload files with system command payloads to the media upload endpoint and execute arbitrary commands on the server. Join the discussion | CVE Database V5 | 12/17/2025, 22:44:59 UTC Added: 12/17/2025, 23:00:19 UTC |
0 Serendipity 2.4.0 contains a stored cross-site scripting vulnerability that allows authenticated users to inject malicious scripts through blog entry creation. Attackers can craft entries with JavaScript payloads that will execute when other users view the compromised blog post. Join the discussion | CVE Database V5 | 12/17/2025, 22:44:59 UTC Added: 12/17/2025, 23:00:19 UTC |
Showing 1 to 7 of 7 results