Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Vtiger CRM before 8.4.0 contains an authenticated file upload vulnerability that allows low-privileged users to achieve remote code execution by uploading a .phar file containing arbitrary PHP code through the Documents module, bypassing the extension denylist in config.inc.php which omits the .phar extension. The uploaded file is stored with its original .phar extension under the web-accessible storage directory, and a misconfigured .htaccess using Apache 2.2 syntax is silently ignored on Apache 2.4 deployments, allowing unauthenticated HTTP requests to directly execute the uploaded PHP payload. Join the discussion | CVE Database V5 | 07/07/2026, 16:17:02 UTC Added: 07/07/2026, 16:44:05 UTC |
0 A HTML Injection vulnerability exists in the Dashboard module of Vtiger CRM 8.4.0. The application fails to properly neutralize user-supplied input in the tabid parameter of the DashBoardTab view (getTabContents action), allowing an attacker to inject arbitrary HTML content into the dashboard interface. The injected content is rendered in the victim's browser Join the discussion | CVE Database V5 | 04/13/2026, 00:00:00 UTC Added: 04/13/2026, 21:01:53 UTC |
0 CVE-2025-70936 is a reflected cross-site scripting (XSS) vulnerability in Vtiger CRM version 8.4.0, specifically within the MailManager module. The issue arises from improper handling of user input in the _folder parameter, allowing a double URL-encoded payload to be reflected and executed in the context of an authenticated user's session. This vulnerability has a medium severity rating with a CVSS score of 5.4. No official patch or remediation guidance is currently available, and there are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 04/13/2026, 00:00:00 UTC Added: 04/13/2026, 21:01:53 UTC |
0 Vtiger CRM v.6.1 and before is vulnerable to Cross Site Scripting (XSS) via the Documents module and function uploadAndSaveFile in CRMEntity.php. Join the discussion | CVE Database V5 | 01/10/2025, 00:00:00 UTC Added: 02/25/2026, 21:38:14 UTC |
0 Vtiger CRM v8.2.0 has a HTML Injection vulnerability in the module parameter. Authenticated users can inject arbitrary HTML. Join the discussion | CVE Database V5 | 10/14/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:39 UTC |
0 A reflected cross-site scripting (XSS) vulnerability in the viewname parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. Join the discussion | CVE Database V5 | 08/29/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:00 UTC |
0 A reflected cross-site scripting (XSS) vulnerability in the parent parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. Join the discussion | CVE Database V5 | 08/29/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:00 UTC |
0 A reflected cross-site scripting (XSS) vulnerability in the tag parameter in the index page of vTiger CRM 7.4.0 allows attackers to execute arbitrary code in the context of a user's browser via injecting a crafted payload. Join the discussion | CVE Database V5 | 08/29/2024, 00:00:00 UTC Added: 02/25/2026, 21:43:00 UTC |
0 VTiger CRM <= 8.1.0 does not properly sanitize user input before using it in a SQL statement, leading to a SQL Injection in the "CompanyDetails" operation of the "MailManager" module. Join the discussion | CVE Database V5 | 08/16/2024, 00:00:00 UTC Added: 02/25/2026, 21:42:44 UTC |
Showing 1 to 9 of 9 results