Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
UTMStack versions prior to 11.2.16 have an account enumeration vulnerability. This flaw allows unauthenticated attackers to determine if an email address is registered by submitting it to the password reset initiation endpoint. Registered emails return a 200 OK response, while unregistered ones cause a 500 Internal Server Error with backend details. This behavior enables attackers to distinguish valid accounts, potentially facilitating targeted phishing or credential attacks. Join the discussion | GCVE Database | 10/02/2026, 21:32:07 UTC Added: 10/03/2026, 17:22:02 UTC |
UTMStack versions prior to 11.2.16 have a JPQL injection vulnerability in the UtmNetworkScanService.searchPropertyValues() method. Authenticated attackers can exploit this flaw by injecting malicious JPQL through the value parameter in the GET /api/utm-network-scans/searchPropertyValues endpoint. This allows unauthorized reading of arbitrary entity data, including sensitive credential tables such as jhi_user. Join the discussion | GCVE Database | 10/02/2026, 21:32:07 UTC Added: 10/03/2026, 17:22:01 UTC |
UTMStack versions prior to 11.2.16 contain a server-side request forgery (SSRF) vulnerability. Authenticated attackers can exploit this flaw by supplying an unvalidated URL parameter to the PdfService.downloadPdf() method via the GET /api/generate-pdf-report endpoint. This allows the attacker to make the server request arbitrary internal resources, potentially exposing sensitive internal data rendered into the generated PDF report. Join the discussion | GCVE Database | 10/02/2026, 21:32:07 UTC Added: 10/03/2026, 17:22:01 UTC |
UTMStack versions before 11.2.16 have an authentication bypass vulnerability (CVE-2026-82042) that allows remote attackers to gain full administrative API access by using a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable. This bypass does not require a user account or JWT and lacks path restrictions, constant-time comparison, rate limiting, or audit logging. Exploitation enables attackers to create accounts, manage users, exfiltrate data, and modify security rules. Join the discussion | GCVE Database | 10/02/2026, 21:32:07 UTC Added: 10/03/2026, 17:22:01 UTC |
UTMStack versions before 11.2.16 have a missing authorization vulnerability in the UTMIncidentCommandWebsocket.processCommand() handler. This handler, mapped to the /command/{hostname} STOMP destination, does not enforce role checks or command allowlists before forwarding commands. As a result, any authenticated user can execute arbitrary operating-system commands on monitored endpoints where agents typically run with high privileges. Join the discussion | GCVE Database | 10/02/2026, 21:32:07 UTC Added: 10/03/2026, 17:22:01 UTC |
UTMStack versions before 11.2.16 have a SQL injection vulnerability in the UtmAssetGroupService.searchQueryBuilder() method. Authenticated attackers can exploit this flaw by sending crafted requests to the GET /api/utm-asset-groups/searchGroupsByFilter endpoint, injecting arbitrary SQL commands. This vulnerability allows execution of SQL with DBA privileges, potentially leading to full database read, data modification, and filesystem access. Join the discussion | GCVE Database | 10/02/2026, 21:32:06 UTC Added: 10/03/2026, 17:22:02 UTC |
UTMStack versions prior to 11.2.16 have a server-side request forgery (SSRF) vulnerability in the IdentityProviderService.validateMetadataUrl() function. This flaw allows authenticated attackers to supply a malicious metadata URL to the identity-providers endpoint, causing the server to send requests to arbitrary internal or cloud metadata hosts. The vulnerability affects the POST/PUT /api/identity-providers endpoint, which does not validate the target host, IP address, or URL scheme. Exploitation can enable internal network port scanning and access to cloud instance-metadata services. Join the discussion | GCVE Database | 10/02/2026, 21:32:06 UTC Added: 10/03/2026, 17:22:02 UTC |
Showing 1 to 7 of 7 results