Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-92602 is a Server-Side Request Forgery (SSRF) vulnerability in TDuckCloud's tduck-survey-form up to version 5.3. The vulnerability arises because the application does not validate webhook URLs or verify form ownership in the WebhookConfigController. Authenticated attackers can exploit this to attach webhooks to other users' forms and exfiltrate form submissions to arbitrary external or internal addresses. Join the discussion | CVE Database V5 | 09/16/2026, 16:03:07 UTC Added: 09/16/2026, 16:17:30 UTC |
0 TDuckCloud tduck-survey-form versions up to 5.0 have an authorization bypass vulnerability in the POST /user/form/data/update endpoint. Authenticated users can overwrite other users' form submission data by exploiting predictable submission identifiers. This allows modification of arbitrary form responses containing personal data without proper ownership validation. Join the discussion | CVE Database V5 | 09/16/2026, 14:40:47 UTC Added: 09/16/2026, 14:47:25 UTC |
Showing 1 to 2 of 2 results