Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
A vulnerability in stoatchat versions before 0.15.5 allows attackers to bypass multi-factor authentication (MFA) by using their own valid MFA ticket combined with another user's session token. This flaw enables unauthorized actions such as disabling TOTP, viewing recovery codes, or performing other sensitive operations without the victim's credentials. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:22 UTC |
January, the media proxy/embed service of stoatchat, before version 0.15.5, improperly resolves SVG <image href> values as local filesystem paths when serving image/svg+xml content. This allows an unauthenticated remote attacker to probe for local file existence via timing differences and disclose local image files after re-encoding. The vulnerability can also cause unbounded local filesystem I/O and memory pressure, leading to denial of service. The issue is fixed in version 0.15.5. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:22 UTC |
Stoatchat versions before 0.15.5 have a denial of service vulnerability in the acknowledgement worker that handles mass mention messages. Authenticated users can exploit this by sending five crafted role-mention messages, causing all acknowledgement workers to terminate. This disables push notifications and mention badges across the deployment until the API process is restarted. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:21 UTC |
stoatchat versions before 0.15.5 do not properly revalidate usernames after Unicode sanitization. This allows attackers to create usernames containing forbidden characters by submitting Unicode letters that transform into rejected characters. Attackers can bypass character allowlists and length limits, enabling creation of reserved-name lookalikes, embedding special characters, and exceeding the 32-character storage limit. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:21 UTC |
Stoatchat versions before 0.15.5 do not enforce account-level attempt limits on multi-factor authentication (MFA) login challenges. This allows attackers who have obtained a user's password to repeatedly guess Time-based One-Time Password (TOTP) codes. The vulnerability arises because only IP-based rate limiting is applied, which can be bypassed by reusing MFA challenge tickets across multiple failed attempts and distributing guesses across different IP addresses. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:21 UTC |
Stoatchat versions before 0.15.5 have an account enumeration vulnerability in the login endpoint. This flaw allows unauthenticated attackers to differentiate between registered and unregistered email addresses by analyzing error responses that expose source file locations. The vulnerability is identified as CVE-2026-100677 and has a medium severity rating with a CVSS score of 5.3. Join the discussion | GCVE Database | 09/26/2026, 15:31:20 UTC Added: 09/27/2026, 04:30:21 UTC |
stoatchat versions before 0.15.0 have a missing authorization vulnerability in the Subscribe message handler. This flaw allows authenticated attackers to subscribe to member-update topics of private servers without being members. As a result, attackers can enumerate members and monitor profile updates such as display names, avatars, and status changes that they should not have access to. Join the discussion | GCVE Database | 08/17/2026, 12:32:21 UTC Added: 08/17/2026, 16:14:19 UTC |
Showing 1 to 7 of 7 results