Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/typecho/typecho

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

0

CVE-2026-7025 is a server-side request forgery (SSRF) vulnerability in Typecho versions up to 1.3.0. It affects the Service::sendPingHandle function in the Ping Back Service Endpoint component. The vulnerability arises from manipulation of the X-Pingback/link argument, allowing an attacker to cause the server to make unauthorized requests. The vulnerability can be exploited remotely. The vendor has not responded to disclosure requests, and no official patch or remediation is currently available. The CVSS 4.0 score rates this as a medium severity issue.

Join the discussion
CVE-2024-35540: n/aCVE-2024-35540
0

A stored cross-site scripting (XSS) vulnerability in Typecho v1.3.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

Join the discussion
CVE-2024-35539: n/aCVE-2024-35539
0

Typecho v1.3.0 was discovered to contain a race condition vulnerability in the post commenting function. This vulnerability allows attackers to post several comments before the spam protection checks if the comments are posted too frequently.

Join the discussion
CVE-2024-35538: n/aCVE-2024-35538
0

Typecho v1.3.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.

Join the discussion

Showing 1 to 4 of 4 results

Filters:Package: pkg:github/typecho/typecho
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses