Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-55583: CWE-639: Authorization Bypass Through User-Controlled Key in twentyhq twentyCVE-2026-55583 0 Twenty is an open-source CRM (customer relationship management) platform. Prior to 2.9.0, Twenty was vulnerable to a cross-workspace insecure direct object reference (IDOR) in the AI agent monitor's AgentTurnResolver, in packages/twenty-server/src/engine/metadata-modules/ai/ai-agent-monitor/reso lvers/agent-turn.resolver.ts. The agentTurns(agentId) query and the evaluateAgentTurn(turnId) mutation looked up rows by agentId or id only; although AgentTurnEntity has a workspaceId column, it was not included in the WHERE clause, and the class-level guards only checked that the caller was authenticated in some workspace rather than that the requested object belonged to it, with the same flaw present in agent-turn-grader.service.ts. As a result, any authenticated user with the AI settings flag, a workspace owner by default, could target any other workspace on the same instance given the victim's agentId or turnId: agentTurns returned the victim's full chat history including message parts such as raw chat text, tool calls, and tool outputs, while evaluateAgentTurn inserted an agentTurnEvaluation row with the victim's workspaceId and fed the victim's turn into the default LLM. The agentId and turnId are non-guessable UUIDs but are exposed in the URL of the settings page. This issue is fixed in version 2.9.0. Join the discussion | CVE Database V5 | 06/24/2026, 19:21:35 UTC Added: 06/24/2026, 19:56:53 UTC |
CVE-2026-44729: CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in twentyhq twentyCVE-2026-44729 0 CVE-2026-44729 is a high-severity cross-site scripting (XSS) vulnerability in the open source CRM Twenty (version 1.18.0 and earlier). The issue arises because the file serving endpoints do not set Content-Type, Content-Disposition, or X-Content-Type-Options headers when serving uploaded files. This allows an authenticated attacker to upload a malicious HTML file containing JavaScript, which executes in the context of the victim's browser when accessed. Exploitation can lead to session hijacking, account takeover, and data theft. Join the discussion | CVE Database V5 | 05/26/2026, 16:56:06 UTC Added: 05/26/2026, 17:02:38 UTC |
Showing 1 to 2 of 2 results