Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor. Join the discussion | CVE Database V5 | 09/10/2026, 13:05:42 UTC Added: 09/10/2026, 13:23:18 UTC |
0 CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks. Join the discussion | CVE Database V5 | 09/09/2026, 11:21:06 UTC Added: 09/09/2026, 11:37:47 UTC |
0 CyberPanel versions prior to 3.0.0 contain a path traversal vulnerability in the cloudAPI ReadReport endpoint. Authenticated administrators can exploit this flaw by supplying unsanitized file paths, allowing them to read arbitrary files on the server filesystem. This includes sensitive files such as credential files, SSL and SSH private keys, and JWT secret files. The vulnerability arises because the reportFile parameter is passed directly to the open() function without validation or allowlisting. The CVSS 4.0 base score is 6.9, indicating a medium severity issue. Join the discussion | CVE Database V5 | 08/13/2026, 17:09:05 UTC Added: 08/13/2026, 17:27:08 UTC |
CyberPanel versions prior to 3.0.0 contain a critical vulnerability due to a hard-coded JWT secret in the WebTerminal FastAPI SSH service. This flaw allows unauthenticated remote attackers to forge valid JWT authentication tokens, specifying ssh_user=root, to gain an interactive root shell via WebSocket on port 8888 without valid credentials. Join the discussion | CVE Database V5 | 08/13/2026, 17:08:40 UTC Added: 08/13/2026, 17:27:08 UTC |
0 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary OS commands by controlling a remote server's API response. Attackers can inject malicious commands through a crafted directory name in the remote server's API response, which bypasses security middleware validation and is passed unsanitized to the OS command execution function. Join the discussion | CVE Database V5 | 08/10/2026, 18:53:12 UTC Added: 08/10/2026, 19:27:01 UTC |
0 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system. Join the discussion | CVE Database V5 | 08/10/2026, 18:52:40 UTC Added: 08/10/2026, 19:27:01 UTC |
0 CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user's home directory to persist on disk and be accessed through the web interface. Join the discussion | CVE Database V5 | 08/10/2026, 18:51:43 UTC Added: 08/10/2026, 18:56:59 UTC |
0 CyberPanel through 1.9.1, fixed in commit b198460, contains an insecure direct object reference (IDOR) vulnerability in the IncBackups application's incremental-backup handlers (deleteBackup, fetchRestorePoints, and restorePoint) that allows authenticated panel users to access or manipulate other tenants' backup resources by supplying an attacker-controlled globally sequential IncJob integer ID that is never re-scoped to the authorized domain. Attackers can enumerate sequential backup IDs to read another tenant's backup metadata, irrecoverably delete another tenant's backup snapshots, or trigger unauthorized restoration of another tenant's backup job with root privileges. Join the discussion | CVE Database V5 | 07/23/2026, 15:59:48 UTC Added: 07/23/2026, 16:23:01 UTC |
CyberPanel through 1.9.1, fixed in commit b198460, contains a missing authorization vulnerability in the cancelBackupCreation handler that allows authenticated users to kill, delete, and corrupt other tenants' backups. Attackers can send crafted POST requests with arbitrary backupCancellationDomain and fileName parameters to terminate backup processes, delete backup archives, corrupt backup status files, and remove database records belonging to other tenants. Join the discussion | CVE Database V5 | 07/23/2026, 15:53:05 UTC Added: 07/23/2026, 16:23:01 UTC |
0 CyberPanel versions prior to 2.4.5 contain an authentication bypass vulnerability in the AI Scanner worker API endpoints that allows unauthenticated remote attackers to write arbitrary data to the database by sending requests to the /api/ai-scanner/status-webhook and /api/ai-scanner/callback endpoints. Attackers can exploit the lack of authentication checks to cause denial of service through storage exhaustion, corrupt scan history records, and pollute database fields with malicious data. Join the discussion | CVE Database V5 | 04/24/2026, 20:40:36 UTC Added: 04/24/2026, 21:06:03 UTC |
Showing 1 to 10 of 15 results