Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/suitecrm/SuiteCRM-Core

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-32697 is an authorization bypass vulnerability in SuiteCRM-Core versions prior to 8.9.3. The vulnerability arises because the getRecord() method does not verify user permissions before retrieving records, allowing users with limited privileges to access sensitive data they should not view. Although the saveRecord() method correctly enforces access control, the missing ACL check in getRecord() leads to a confidentiality breach. This flaw has a CVSS score of 6.5, indicating medium severity, and does not require user interaction but does require some level of privileges. The issue was patched in version 8.9.3.

Join the discussion

CVE-2026-29109 is a high-severity deserialization vulnerability in SuiteCRM versions prior to 8.9.3. It affects the SavedSearch filter processing component, where the application unserializes user-controlled data without restricting allowed classes. This flaw allows an authenticated administrator to execute arbitrary system commands on the server, potentially leading to full system compromise. The vulnerability arises from unsafe use of PHP's unserialize() function on data from the saved_search.contents database column. No user interaction beyond authentication is required, and the vulnerability does not require network-level access beyond normal admin privileges. Although no exploits are currently known in the wild, the risk is significant due to the potential impact and ease of exploitation by privileged users. Organizations using SuiteCRM versions before 8.

Join the discussion

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 8.9.3, an authenticated API endpoint allows any user to retrieve detailed information about any other user, including their password hash, username, and MFA configuration. As any authenticated user can query this endpoint, it's possible to retrieve and potentially crack the passwords of administrative users. Version 8.9.3 patches the issue.

Join the discussion

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. In versions 8.6.0 through 8.9.0, there is an authenticated, blind (time-based) SQL-injection inside the appMetadata-operation of the GraphQL-API. This allows extraction of arbitrary data from the database, and does not require administrative access. This issue is fixed in version 8.9.1.

Join the discussion

SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Versions 8.9.0 and below contain a time-based blind SQL Injection vulnerability. This vulnerability allows an authenticated attacker to infer data from the database by measuring response times, potentially leading to the extraction of sensitive information. It is possible for an attacker to enumerate database, table, and column names, extract sensitive data, or escalate privileges. This is fixed in version 8.9.1.

Join the discussion

Showing 1 to 5 of 5 results

Filters:Package: pkg:github/suitecrm/SuiteCRM-Core
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses