Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/sap_se/SAPUI5

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-76977 is a medium severity vulnerability in SAP UI5's Frame Options Allowlist. The issue arises from insufficient validation of the parent frame's origin against the configured allowlist, allowing an unauthenticated attacker to host a malicious page that can bypass framing restrictions. If an authenticated user visits the attacker's page and interacts with it, the attacker could trick the user into performing unintended actions. The impact is limited to integrity with no confidentiality or availability impact.

Join the discussion

SAPUI5 allows a key user with content adaptation privileges to inject malicious script content into persisted application changes. When another user subsequently opens the adapted application, the injected script executes in the victim's browser session. Successful exploitation could allow the attacker to access sensitive session data and perform unauthorized actions on behalf of the victim, resulting in a high impact on confidentiality and integrity. There is no impact on availability.

Join the discussion

CVE-2026-34258 is a vulnerability in SAPUI5 (Search UI) that allows an unauthenticated attacker to manipulate URL parameters to inject malicious content. This can mislead users into clicking links that lead to attacker-controlled pages rendered by the application. The vulnerability impacts confidentiality to a low degree but does not affect integrity or availability. It has a medium severity with a CVSS score of 4.7. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time.

Join the discussion

Showing 1 to 3 of 3 results

Filters:Package: pkg:github/sap_se/SAPUI5
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses