Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 HireFlow versions prior to 1.3 contain a hard-coded Flask secret_key used for signing session cookies. This vulnerability allows unauthenticated attackers who know the hard-coded key to forge cookies with elevated privileges, such as role=admin, bypassing authentication controls. Version 1.3 addresses this issue. Join the discussion | CVE Database V5 | 07/16/2026, 17:03:00 UTC Added: 07/16/2026, 17:33:03 UTC |
0 HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add. Join the discussion | CVE Database V5 | 05/11/2026, 00:00:00 UTC Added: 05/11/2026, 17:22:10 UTC |
0 HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve records by the user-supplied ID without verifying that the requesting user is the owner or has an authorized role. Any authenticated user can access any other user's candidate profiles and interview notes by iterating the integer ID in the URL path, constituting a horizontal privilege escalation and full data breach of all records in the system. Join the discussion | CVE Database V5 | 05/11/2026, 00:00:00 UTC Added: 05/11/2026, 17:22:10 UTC |
0 HireFlow version 1.2 contains critical SQL injection vulnerabilities in its /login and /search endpoints. These vulnerabilities arise because user input is directly concatenated into SQL queries without proper parameterization. An unauthenticated attacker can exploit this to bypass authentication or extract the entire database contents, including user credentials, using UNION-based SQL injection techniques. The vulnerability has a CVSS score of 9.8, indicating a critical severity level. No official patch or remediation guidance is currently available from the vendor. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 05/11/2026, 00:00:00 UTC Added: 05/11/2026, 17:22:10 UTC |
0 HireFlow version 1.2 lacks CSRF token validation on all state-changing POST endpoints, including password changes, candidate deletions, feedback submissions, and interview scheduling. Additionally, the SESSION_COOKIE_SAMESITE attribute is not configured, removing a browser-level defense against CSRF attacks. An attacker who tricks an authenticated user into visiting a malicious page could perform unauthorized actions on the victim's behalf. This vulnerability has a high severity score of 8.1 but currently has no known exploits in the wild and no official patch or remediation guidance published. Join the discussion | CVE Database V5 | 05/11/2026, 00:00:00 UTC Added: 05/11/2026, 17:22:10 UTC |
Showing 1 to 5 of 5 results