Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 SiYuan versions before 3.8.3 contain an SQL injection vulnerability in the graph.go query2Stmt function where tag values are concatenated raw into SQL string literals without escaping single quotes. A publish-mode reader or anonymous visitor can inject SQL via inline HTML span tags in the getGraph endpoint to execute arbitrary queries on the read-write database and exfiltrate private data across notebooks. Join the discussion | CVE Database V5 | 09/18/2026, 13:20:04 UTC Added: 09/18/2026, 13:32:11 UTC |
0 SiYuan before 3.8.4 renders document titles as HTML in the backlink dock tree without escaping markup characters. Attackers can set malicious titles through the rename API or crafted notebooks to execute scripts in the Electron renderer with access to child_process for command execution. Join the discussion | CVE Database V5 | 09/17/2026, 14:22:10 UTC Added: 09/17/2026, 14:32:51 UTC |
0 SiYuan versions before 3.8.4 fail to escape bookmark labels imported from notebook files when rendering them in the dock tree. Attackers can craft malicious .sy notebook files with unescaped HTML in bookmark attributes that execute scripts in the Electron renderer with access to child_process for command execution. Join the discussion | CVE Database V5 | 09/17/2026, 14:22:09 UTC Added: 09/17/2026, 14:32:51 UTC |
SiYuan versions before v3.8.2 contain a path traversal vulnerability in the /api/riff/removeRiffDeck endpoint that fails to validate the deckID parameter. An authenticated administrator can supply path traversal sequences to delete arbitrary .deck and .cards files outside the workspace directory. Join the discussion | CVE Database V5 | 09/09/2026, 11:21:02 UTC Added: 09/09/2026, 11:37:47 UTC |
0 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the search asset preview feature that fails to escape indexed asset content before inserting it into the DOM using innerHTML. Attackers who can place crafted text assets in a workspace can execute JavaScript in the SiYuan origin when victims preview the assets, enabling authenticated API requests and workspace manipulation. Join the discussion | CVE Database V5 | 09/09/2026, 11:21:01 UTC Added: 09/09/2026, 11:37:47 UTC |
0 SiYuan before v3.8.2 contains a stored cross-site scripting vulnerability in the Search Assets result list where asset filenames are interpolated into HTML without escaping. Authenticated attackers can craft asset filenames containing malicious markup that executes JavaScript in the victim's browser when searching assets, enabling same-origin API requests and application state manipulation. Join the discussion | CVE Database V5 | 09/09/2026, 11:21:01 UTC Added: 09/09/2026, 11:37:47 UTC |
0 SiYuan note-taking software versions prior to 3.8.2 contain a stored cross-site scripting (XSS) vulnerability. This flaw occurs because the iconURL metadata in Bazaar package cards is inserted directly into HTML img src attributes without proper escaping. An attacker can exploit this by injecting malicious URLs with event handlers that execute JavaScript when authenticated users view Bazaar listings. This enables unauthorized API requests and manipulation of application state within the authenticated session. Join the discussion | CVE Database V5 | 09/09/2026, 11:21:00 UTC Added: 09/09/2026, 11:37:43 UTC |
0 SiYuan before v3.8.2 inserts persisted notebook template paths into HTML input value attributes without proper attribute encoding. Attackers can craft malicious template paths that break out of the attribute context and execute JavaScript when a victim opens notebook configuration, enabling same-origin API requests and application state manipulation. Join the discussion | CVE Database V5 | 09/09/2026, 11:20:59 UTC Added: 09/09/2026, 11:37:43 UTC |
0 Siyuan before v3.8.2 contains an information disclosure vulnerability in the POST /api/search/fullTextSearchBlock endpoint that filters private blocks from results but returns unfiltered match counts. Unauthenticated publish-mode readers can submit arbitrary search terms to learn whether matching content exists in hidden or unpublished documents and determine the number of matching blocks and pages. Join the discussion | CVE Database V5 | 09/09/2026, 11:20:58 UTC Added: 09/09/2026, 11:37:43 UTC |
0 Siyuan before v3.8.2 fails to apply publish-access filtering to embedded blocks before rendering in the /api/export/preview and /api/lute/copyStdMarkdown endpoints. Attackers with reader access can retrieve the full rendered content of private, hidden, or publish-disabled blocks by accessing public documents containing embed queries that select those blocks. Join the discussion | CVE Database V5 | 09/09/2026, 11:20:58 UTC Added: 09/09/2026, 11:37:43 UTC |
Showing 1 to 10 of 117 results