Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-51953: n/aCVE-2026-51953 0 An issue in FeehiCMS v.2.1.1 allows an attacker to escalate privileges via the Session management module, authentication logic, logout handler components Join the discussion | GCVE Database | 07/31/2026, 00:00:00 UTC Added: 08/01/2026, 08:14:09 UTC |
CVE-2026-54244: CWE-863: Incorrect Authorization in statamic cmsCVE-2026-54244 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.74.0 and 6.20.3, the Live Preview endpoint for existing entries and terms in src/Http/Controllers/CP/PreviewController.php only checked view authorization, but it accepts and renders caller-supplied field values. A Control Panel user with view but not edit permission could therefore submit content they were not authorized to author and generate a shareable Live Preview URL rendering it. This issue is fixed in versions 5.74.0 and 6.20.3. Join the discussion | CVE Database V5 | 07/17/2026, 20:22:35 UTC Added: 07/18/2026, 11:08:26 UTC |
CVE-2026-54243: CWE-1236: Improper Neutralization of Formula Elements in a CSV File in statamic cmsCVE-2026-54243 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, form submission values in src/Forms/Exporters/CsvExporter.php were not neutralized for spreadsheet formula characters when exported to CSV. A submission containing a value beginning with a formula trigger character, such as =, +, -, or @, could be interpreted as a live formula when a Control Panel user opens the export in a spreadsheet application. Form submissions can come from unauthenticated front-end visitors, so the malicious value can be supplied by an anonymous user and is later triggered by an editor opening the export. This issue is fixed in versions 5.73.24 and 6.20.1. Join the discussion | CVE Database V5 | 07/17/2026, 20:24:53 UTC Added: 07/18/2026, 11:08:26 UTC |
CVE-2026-54242: CWE-367: Time-of-check Time-of-use (TOCTOU) Race Condition in statamic cmsCVE-2026-54242 0 Statamic is a Laravel and Git powered content management system (CMS). Prior to 5.73.24 and 6.20.1, the Glide image proxy's URL validation in src/Imaging/RemoteUrlValidator.php and src/Imaging/GuzzleAdapter.php could be bypassed using DNS rebinding. The remote hostname was validated as publicly routable, but resolved again when the image was actually fetched, so an attacker controlling the hostname's DNS could rebind it to an internal address after validation and cause the server to make HTTP requests to internal addresses, including loopback, private network, and cloud metadata endpoints. This affects sites that pass user-supplied URLs to Glide. This issue is fixed in versions 5.73.24 and 6.20.1. Join the discussion | CVE Database V5 | 07/17/2026, 20:23:42 UTC Added: 07/18/2026, 11:08:23 UTC |
CVE-2026-12257: CWE-94 Improper Control of Generation of Code ('Code Injection') in Mura Software CMSCVE-2026-12257 0 Versions of Mura CMS prior to 10.0.712 contain a critical remote code execution (RCE) vulnerability. The flaw is located in the endpoint “/index.cfm/_api/json/v1/default”, where the “method” parameter in POST requests is not properly validated or sanitised before being processed by the ColdFusion engine. As a result, a remote attacker could exploit this vulnerability to inject and execute arbitrary CFML (ColdFusion Markup Language) expressions and instantiate malicious Java objects, thereby compromising the system’s security. Join the discussion | CVE Database V5 | 07/13/2026, 11:29:59 UTC Added: 07/13/2026, 12:04:03 UTC |
Showing 1 to 5 of 5 results