Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-32638 is an authorization bypass vulnerability in StudioCMS versions prior to 0.4.4. The REST API's getUsers endpoint improperly uses an attacker-controlled 'rank' query parameter to filter user accounts, allowing admin users to retrieve owner account details such as IDs, usernames, display names, and email addresses. This occurs despite the adjacent getUser endpoint correctly restricting access to owner user data, indicating an authorization inconsistency within the same user management interface. The vulnerability has a low CVSS score of 2.7, reflecting limited impact and the requirement for admin privileges to exploit. No known exploits are currently reported in the wild. The issue is resolved in StudioCMS version 0.4. Join the discussion | CVE Database V5 | 03/18/2026, 20:41:14 UTC Added: 03/18/2026, 20:58:26 UTC |
0 CVE-2026-32104 is an authorization bypass vulnerability in withstudiocms's StudioCMS versions prior to 0.4.3. The updateUserNotifications endpoint allows any authenticated user to modify notification preferences for any other user by supplying an arbitrary user ID, without verifying ownership. This flaw enables attackers to disable admin notifications, potentially suppressing alerts of malicious activity. The vulnerability requires authentication but no user interaction beyond sending crafted requests. It impacts confidentiality indirectly by enabling stealthy attacks and affects integrity and availability of notification settings. The issue is fixed in version 0.4.3. Join the discussion | CVE Database V5 | 03/11/2026, 20:09:44 UTC Added: 03/11/2026, 20:29:54 UTC |
CVE-2026-32106 is a medium severity privilege management vulnerability in StudioCMS versions prior to 0.4.3. The issue arises from inconsistent rank checks between the REST API and Dashboard API when creating user accounts. Specifically, the REST API uses string-based rank checks that only block creation of owner accounts, while the Dashboard API uses indexOf-based rank comparisons to prevent creating users at or above the caller's rank. This inconsistency allows an authenticated admin to create additional admin accounts via the REST API, leading to privilege escalation and persistence. No user interaction is required beyond authentication, and the vulnerability is fixed in version 0.4.3. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 03/11/2026, 20:09:12 UTC Added: 03/11/2026, 20:29:54 UTC |
0 CVE-2026-32103 is an authorization bypass vulnerability in StudioCMS versions prior to 0.4.3. It affects the POST /studiocms_api/dashboard/create-reset-link endpoint, allowing any authenticated admin user to generate password reset tokens for any other user, including the highest-privileged owner account. The vulnerability arises because the system verifies admin status but does not enforce role hierarchy or validate that the target userId matches the caller's identity. By combining this with the password reset endpoint, an attacker with admin privileges can fully take over the owner account. This flaw has a CVSS score of 6.8 (medium severity) and does not require user interaction. The vulnerability is fixed in version 0.4. Join the discussion | CVE Database V5 | 03/11/2026, 20:06:58 UTC Added: 03/11/2026, 20:29:54 UTC |
0 CVE-2026-30945 is a high-severity authorization bypass vulnerability in StudioCMS versions prior to 0.4.0. It allows any authenticated user with editor privileges or higher to revoke API tokens belonging to other users, including administrators and owners, without proper ownership or role verification. This occurs because the DELETE /studiocms_api/dashboard/api-tokens endpoint accepts tokenID and userID directly from the request payload without validating the caller's identity or role hierarchy. Exploiting this flaw can lead to denial of service against critical integrations and automations relying on those API tokens. The vulnerability does not require user interaction and can be exploited remotely over the network. It is fixed in StudioCMS version 0.4.0. Join the discussion | CVE Database V5 | 03/10/2026, 16:52:14 UTC Added: 03/10/2026, 17:34:45 UTC |
0 StudioCMS is a server-side-rendered, Astro native, headless content management system. Prior to 0.4.0, the /studiocms_api/dashboard/api-tokens endpoint allows any authenticated user (at least Editor) to generate API tokens for any other user, including owner and admin accounts. The endpoint fails to validate whether the requesting user is authorized to create tokens on behalf of the target user ID, resulting in a full privilege escalation. This vulnerability is fixed in 0.4.0. Join the discussion | CVE Database V5 | 03/10/2026, 16:48:55 UTC Added: 03/10/2026, 17:34:45 UTC |
0 CVE-2026-24134 is a Broken Object Level Authorization (BOLA) vulnerability in StudioCMS versions prior to 0.2.0. It allows users with the 'Visitor' role to access draft content created by higher-privileged users such as Editors, Admins, or Owners. The vulnerability arises from improper authorization checks on user-controlled keys in the content management feature. Exploitation requires no user interaction but does require low-level privileges (Visitor role). The vulnerability impacts confidentiality by exposing sensitive unpublished content but does not affect integrity or availability. The issue is patched in version 0.2.0. Join the discussion | CVE Database V5 | 01/27/2026, 23:34:55 UTC Added: 01/27/2026, 23:50:56 UTC |
Showing 1 to 7 of 7 results