Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 crawl4ai versions before 0.9.3 have a DOM-based cross-site scripting (XSS) vulnerability in the Playground UI. The vulnerability arises because the forceHighlightElement() function improperly assigns textContent back to innerHTML, causing JSON responses to be re-parsed as HTML. This allows attackers to inject malicious scripts via crawled page content such as the page title. Exploitation can lead to theft of the operator's API token from sessionStorage and potentially full server control. Join the discussion | CVE Database V5 | 09/15/2026, 15:18:03 UTC Added: 09/15/2026, 15:32:42 UTC |
0 crawl4ai before 0.9.3 contains a DOM-based cross-site scripting vulnerability in the Docker Playground UI that assigns untrusted crawl results to element.innerHTML. Attackers can craft malicious PDFs with event-handler markup to execute JavaScript in the Playground origin and steal API tokens from sessionStorage for authenticated API abuse. Join the discussion | CVE Database V5 | 09/15/2026, 15:18:02 UTC Added: 09/15/2026, 15:32:42 UTC |
CVE-2026-91941 is a high-severity vulnerability in unclecode's crawl4ai before version 0.9.3. It involves uncontrolled resource consumption in the PDFContentScrapingStrategy, allowing attackers to cause denial of service by downloading large remote PDFs without size or page limits. This can exhaust disk space, CPU, and bandwidth on shared workers. Join the discussion | CVE Database V5 | 09/15/2026, 15:18:01 UTC Added: 09/15/2026, 15:32:42 UTC |
0 crawl4ai before 0.9.3 contains an arbitrary file write vulnerability in PDFContentScrapingStrategy where the _filter_untrusted_fields function fails to validate untrusted configuration fields. Attackers can submit crafted config bodies with malicious image_save_dir paths to write attacker-controlled bytes into any directory accessible to the service account. Join the discussion | CVE Database V5 | 09/15/2026, 15:18:01 UTC Added: 09/15/2026, 15:32:42 UTC |
0 Crawl4AI versions before 0.8.8 have credential exfiltration vulnerabilities in their Docker API server. Attackers can exploit unauthenticated endpoints (/md, /llm, /llm/job) by manipulating the base_url parameter and setting api_token to environment variable references, allowing them to read arbitrary environment variables. This can lead to exfiltration of sensitive data such as provider API keys and JWT SECRET_KEY, enabling authentication bypass. Join the discussion | GCVE Database | 07/12/2026, 12:31:47 UTC Added: 07/13/2026, 09:21:28 UTC |
Crawl4AI versions before 0.8.7 have an arbitrary file write vulnerability in the Docker API server's /screenshot and /pdf endpoints. The vulnerability arises because the output_path parameter does not validate input, allowing attackers to write files to arbitrary locations accessible by the application user. This can lead to overwriting server files and cause denial of service. Join the discussion | GCVE Database | 07/12/2026, 12:31:47 UTC Added: 07/13/2026, 09:21:28 UTC |
Crawl4AI before 0.8.7 contains a server-side request forgery (SSRF) vulnerability in the Docker API server's /crawl/job and /llm/job endpoints, which accept webhook URLs without destination validation. An attacker can supply webhook URLs pointing to private or internal IP ranges, Docker networks, or cloud metadata endpoints (e.g. 169.254.169.254), causing the server to make requests to internal services and potentially expose cloud metadata. Join the discussion | GCVE Database | 07/10/2026, 15:31:39 UTC Added: 07/11/2026, 09:37:50 UTC |
0 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server accepted request-supplied browser_config.extra_args, which flowed into Chromium's launch arguments. An attacker could inject Chromium switches that replace a child-process launch command together with --no-zygote, causing Chromium to fork or exec an attacker-controlled command as the container's runtime user. The Docker API is unauthenticated by default, so a single request yields arbitrary command execution. This issue is fixed in version 0.9.0. Join the discussion | CVE Database V5 | 07/06/2026, 20:16:21 UTC Added: 07/06/2026, 20:37:16 UTC |
Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, the Docker API server applied its SSRF destination check on the non-streaming /crawl path but not on the streaming path. handle_stream_crawl_request passed seed URLs straight to the crawler with no destination validation, allowing a remote unauthenticated client to call POST /crawl/stream or POST /crawl with crawler_config.stream=true with a URL pointing at an internal, private, or link-local address; the server fetched it and streamed the response body back. This issue is fixed in version 0.9.0. Join the discussion | CVE Database V5 | 07/06/2026, 20:11:15 UTC Added: 07/06/2026, 20:37:16 UTC |
0 Crawl4AI is an open-source LLM-friendly web crawler and scraper. Prior to 0.9.0, when the crawler saves a downloaded file, the destination filename was taken from attacker-influenced input and joined to the downloads directory with no confinement. A filename containing an absolute path or traversal escaped the downloads directory, giving an arbitrary file write with attacker-controlled contents; the HTTP crawler path uses the response Content-Disposition filename and the browser crawler path uses the download's suggested filename. Because the written bytes are attacker-controlled, this can escalate to remote code execution. This issue is fixed in version 0.9.0. Join the discussion | CVE Database V5 | 07/06/2026, 20:09:52 UTC Added: 07/06/2026, 20:37:16 UTC |
Showing 1 to 10 of 15 results