Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-34745 is a critical path traversal vulnerability in ShaneIsrael fireshare versions prior to 1.5.3. The issue exists because a fix applied to the authenticated /api/uploadChunked endpoint was not applied to the unauthenticated /api/uploadChunked/public endpoint. This allows an unauthenticated attacker to exploit the checkSum parameter to write arbitrary files with attacker-controlled content to any writable path on the server filesystem. The vulnerability has been patched in version 1.5.3. Join the discussion | CVE Database V5 | 04/02/2026, 18:38:17 UTC Added: 04/02/2026, 19:28:26 UTC |
0 CVE-2026-33645 is a path traversal vulnerability in ShaneIsrael fireshare version 1.5.1. It allows an authenticated attacker to write arbitrary files outside the intended upload directory via the chunked upload endpoint by exploiting improper sanitization of the 'checkSum' multipart field. This can lead to integrity violations and potentially enable further attacks depending on the deployment environment. The issue is fixed in version 1.5.2. Join the discussion | CVE Database V5 | 03/26/2026, 20:58:21 UTC Added: 03/26/2026, 21:14:45 UTC |
0 Fireshare facilitates self-hosted media and link sharing. Versions 1.2.30 and below allow an authenticated user, or unauthenticated user if the Public Uploads setting is enabled, to craft a malicious filename when uploading a video file. The malicious filename is then concatenated directly into a shell command, which can be used for uploading files to arbitrary directories via path traversal, or executing system commands for Remote Code Execution (RCE). This issue is fixed in version 1.3.0. Join the discussion | CVE Database V5 | 12/12/2025, 07:10:55 UTC Added: 12/12/2025, 07:16:56 UTC |
Showing 1 to 3 of 3 results