Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-78654 is a medium severity vulnerability in the cleverbrush framework up to version 4.4.0. It affects the deepExtend function in the libs/deep/src/deepExtend.ts file, allowing improper modification of object prototype attributes. This flaw can be exploited remotely without authentication. The issue is fixed in version 4.4.1. Join the discussion | CVE Database V5 | 08/25/2026, 06:00:13 UTC Added: 08/25/2026, 06:09:16 UTC |
0 CVE-2026-73661 is a high-severity vulnerability in the FreePBX Framework module that allows an authenticated user with backup-restore or write access to crafted backup files to disable authentication during restoration. This occurs because the restore process permits restoring the hidden AUTHTYPE setting with the value 'none', bypassing the user interface's removal of this insecure setting. The issue affects FreePBX versions prior to 16.0.47 and 17.0.30 and is fixed in these versions. Join the discussion | CVE Database V5 | 08/13/2026, 21:25:26 UTC Added: 08/13/2026, 21:41:43 UTC |
0 CVE-2026-72578 is a high-severity cross-site request forgery (CSRF) vulnerability in FreePBX Framework version 17.0. It allows an unauthenticated remote attacker to perform administrative actions by exploiting the privileges of an authenticated administrator. The vulnerability has a CVSS score of 8.8, indicating a significant risk to confidentiality, integrity, and availability. No official patch or remediation guidance has been provided yet. Join the discussion | CVE Database V5 | 08/10/2026, 10:41:09 UTC Added: 08/10/2026, 10:56:48 UTC |
0 Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but the same restriction was never applied to other settings registered as LESS config variables (for example theme_primary_color and theme_secondary_color, as well as any key registered via Extend\Settings::registerLessConfigVar()). Those values are interpolated verbatim into the LESS source at compile time, allowing an authenticated administrator to craft a theme-color value that injects an arbitrary @import directive into the compiled forum.css. Because the underlying LESS parser honours @import (inline) '<path>', an attacker can read arbitrary files reachable by the PHP process (local file inclusion) or trigger outbound HTTP(S) requests (server-side request forgery). This issue has been patched in versions 1.8.16 and 2.0.0-rc.1. Join the discussion | CVE Database V5 | 05/08/2026, 15:50:38 UTC Added: 05/08/2026, 16:21:25 UTC |
FreePBX is an open-source web-based graphical user interface (GUI) that manages Asterisk. Prior to versions 16.0.45 and 17.0.24 of the FreePBX framework, an authenticated local privilege escalation exists in the deprecated FreePBX startup script `amportal`. In the deprecated `amportal` utility, the lookup for the `freepbx_engine` file occurs in `/etc/asterisk/` directories. Typically, these are configured by FreePBX as writable by the **asterisk** user and any members of the **asterisk** group. This means that a member of the **asterisk** group can add their own `freepbx_engine` file in `/etc/asterisk/` and upon `amportal` executing, it would exec that file with root permissions (even though the file was created and placed by a non-root user). Version 16.0.45 and 17.0.24 contain a fix for the issue. Other mitigation strategies are also available. Confirm only trusted local OS system users are members of the `asterisk` group. Look for suspicious files in the `/etc/asterisk/` directory (via Admin -> Config Edit in the GUI, or via CLI). Double-check that `live_dangerously = no` is set (or unconfigured, as the default is **no**) in `/etc/asterisk/asterisk.conf` file. Eliminate any unsafe custom use of Asterisk dial plan applications and functions that potentially can manipulate the file system, e.g., System(), FILE(), etc. Join the discussion | CVE Database V5 | 12/16/2025, 00:14:18 UTC Added: 12/16/2025, 00:45:38 UTC |
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions are vulnerable to authentication bypass when the authentication type is set to "webserver." When providing an Authorization header with an arbitrary value, a session is associated with the target user regardless of valid credentials. This issue is fixed in versions 16.0.44 and 17.0.23. Join the discussion | CVE Database V5 | 12/09/2025, 21:32:03 UTC Added: 12/09/2025, 21:42:56 UTC |
0 ThinkPHP 8.0.3 allows remote attackers to exploit XSS due to inadequate filtering of function argument values in think_exception.tpl. Join the discussion | CVE Database V5 | 05/04/2024, 00:00:00 UTC Added: 02/25/2026, 21:40:32 UTC |
Showing 1 to 7 of 7 results