Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:github/usmannasir/cyberpanel

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CyberPanel before 2.4.4 has no logging for actions that could potentially manipulate the child domains list.

Join the discussion

CyberPanel before 2.4.4 omits a "return 0" that is required by the business logic.

Join the discussion
CVE-2026-29811: n/aCVE-2026-29811
0

CyberPanel versions prior to 2.4.4 contain a flaw in how they detect alias domains. Instead of using a proper Python conditional statement, the detection relies on an ORM query filter, which may lead to incorrect identification of alias domains.

Join the discussion

CyberPanel before 3.0.5 fails to enforce two-factor authentication on API endpoints, allowing attackers to bypass TOTP requirements using password-derived tokens. Attackers who obtain an administrator's password can derive API tokens and perform administrative operations or create authenticated sessions without the second factor.

Join the discussion

CyberPanel versions 2.4.3 through 2.4.5 expose unauthenticated AI Scanner debugging endpoints that disclose administrator usernames, API-key prefixes, scan identifiers, target domains, and account metadata. Unauthenticated attackers can enumerate panel administrators and recent scanner activity to inventory multi-tenant installations and facilitate follow-on attacks.

Join the discussion

CyberPanel versions prior to 3.0.0 contain a path traversal vulnerability in the cloudAPI ReadReport endpoint. Authenticated administrators can exploit this flaw by supplying unsanitized file paths, allowing them to read arbitrary files on the server filesystem. This includes sensitive files such as credential files, SSL and SSH private keys, and JWT secret files. The vulnerability arises because the reportFile parameter is passed directly to the open() function without validation or allowlisting. The CVSS 4.0 base score is 6.9, indicating a medium severity issue.

Join the discussion

CyberPanel versions prior to 3.0.0 contain a critical vulnerability due to a hard-coded JWT secret in the WebTerminal FastAPI SSH service. This flaw allows unauthenticated remote attackers to forge valid JWT authentication tokens, specifying ssh_user=root, to gain an interactive root shell via WebSocket on port 8888 without valid credentials.

Join the discussion

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated command injection vulnerability in the remote backup transfer feature that allows authenticated attackers to execute arbitrary OS commands by controlling a remote server's API response. Attackers can inject malicious commands through a crafted directory name in the remote server's API response, which bypasses security middleware validation and is passed unsanitized to the OS command execution function.

Join the discussion

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an authenticated remote code execution vulnerability in the remote backup feature that allows authenticated attackers to gain root-level SSH access by supplying a malicious remote server address. Attackers can exploit the unverified SSH public key retrieval process to write an attacker-controlled public key directly to /root/.ssh/authorized_keys, granting persistent root access to the host system.

Join the discussion

CyberPanel 2.4.3, fixed in commit eca0c3c, contains an arbitrary file read vulnerability in the file manager component that allows authenticated attackers to read sensitive system files by uploading a crafted ZIP archive containing symbolic links. Attackers can exploit the application's failure to validate symlinks before extraction, causing symbolic links targeting arbitrary filesystem paths outside the user's home directory to persist on disk and be accessed through the web interface.

Join the discussion

Showing 1 to 10 of 18 results

Filters:Package: pkg:github/usmannasir/cyberpanel
Page 1 of 2
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses