Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-42090 is a critical stored cross-site scripting (XSS) vulnerability in the Notesnook note-taking application affecting versions prior to 3.3.15 on Web/Desktop and prior to 3.3.20 on iOS/Android. The vulnerability arises because note fields such as title, headline, and content are inserted into an HTML template without proper HTML escaping during the note export flow. This allows malicious script injection that executes in a same-origin, unsandboxed iframe. In the desktop app, this escalates to remote code execution (RCE) due to Electron's insecure configuration (nodeIntegration: true, contextIsolation: false). The issue has been patched in the specified versions. Join the discussion | CVE Database V5 | 05/04/2026, 16:43:07 UTC Added: 05/04/2026, 17:06:33 UTC |
0 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to version 3.3.17, a stored XSS vulnerability exists in the mobile share / web clip flow because attacker-controlled clip metadata is concatenated into HTML without escaping and then rendered with innerHTML inside the mobile share editor WebView. An attacker can control the shared title metadata (for example through Android/iOS share metadata such as TITLE / SUBJECT, or through link-preview title data) and inject HTML such as </a><img src=x onerror=...>. When the victim opens the Notesnook share flow and selects Web clip, the payload is inserted into the generated HTML and executed in the mobile editor WebView. This issue has been patched in version 3.3.17. Join the discussion | CVE Database V5 | 04/01/2026, 16:11:56 UTC Added: 04/01/2026, 19:29:40 UTC |
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop, a cross-site scripting vulnerability stored in the note history comparison viewer can escalate to remote code execution in a desktop application. The issue is triggered when an attacker-controlled note header is displayed using `dangerouslySetInnerHTML` without secure handling. When combined with the full backup and restore feature in the desktop application, this becomes remote code execution because Electron is configured with `nodeIntegration: true` and `contextIsolation: false`. Version 3.3.11 patches the issue. Join the discussion | CVE Database V5 | 03/27/2026, 21:27:31 UTC Added: 03/27/2026, 21:44:47 UTC |
Notesnook is a note-taking app. Prior to version 3.3.11 on Web/Desktop and 3.3.17 on Android/iOS, a stored XSS in the Web Clipper rendering flow can be escalated to remote code execution in the desktop app. The root cause is that the clipper preserves attacker-controlled attributes from the source page’s root element and stores them inside web-clip HTML. When the clip is later opened, Notesnook renders that HTML into a same-origin, unsandboxed iframe using `contentDocument.write(...)`. Event-handler attributes such as `onload`, `onclick`, or `onmouseover` execute in the Notesnook origin. In the desktop app, this becomes RCE because Electron is configured with `nodeIntegration: true` and `contextIsolation: false`. Version 3.3.11 Web/Desktop and 3.3.17 on Android/iOS patch the issue. Join the discussion | CVE Database V5 | 03/27/2026, 21:26:10 UTC Added: 03/27/2026, 21:44:47 UTC |
0 Notesnook is a note-taking app focused on user privacy & ease of use. Prior to 3.3.9, a Stored Cross-Site Scripting (XSS) vulnerability existed in Notesnook's editor embed component when rendering Twitter/X embed URLs. The tweetToEmbed() function in component.tsx interpolated the user-supplied URL directly into an HTML string without escaping, which was then assigned to the srcdoc attribute of an <iframe>. This vulnerability is fixed in 3.3.9. Join the discussion | CVE Database V5 | 03/11/2026, 18:17:08 UTC Added: 03/11/2026, 18:46:34 UTC |
Showing 1 to 5 of 5 results