Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 yudao-cloud before 2026.06 contains a broken access control vulnerability in the BPM module that allows any authenticated user to access arbitrary process instance records by supplying a caller-controlled process-instance identifier to an unprotected endpoint lacking the @PreAuthorize annotation. Attackers can query any process-instance identifier through the unguarded GET endpoint to read sensitive workflow data including submitted form variables, approver identities, approval and rejection comments, and process BPMN XML without ownership or tenant party verification. Join the discussion | CVE Database V5 | 06/30/2026, 21:06:21 UTC Added: 06/30/2026, 21:36:47 UTC |
A vulnerability has been found in YunaiV yudao-cloud 2026.03. This affects the function IotDataSinkHttpConfig of the file /admin-api/iot/data-sink/create of the component Admin API Endpoint. Such manipulation leads to server-side request forgery. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/25/2026, 14:00:16 UTC Added: 05/25/2026, 18:58:30 UTC |
0 A weakness has been identified in YunaiV yudao-cloud up to 2026.01. This vulnerability affects unknown code of the file /admin-api/system/mail-log/page. This manipulation of the argument toMail causes sql injection. The attack can be initiated remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 03/30/2026, 19:45:10 UTC Added: 03/30/2026, 20:08:16 UTC |
0 CVE-2026-5147 is a medium severity SQL injection vulnerability in YunaiV yudao-cloud version 2026.01. The flaw exists in the /admin-api/system/tenant/get-by-website endpoint, where manipulation of the Website argument allows remote attackers to perform SQL injection. The vulnerability has a CVSS 4.0 base score of 6.9. The vendor has not responded to disclosure attempts, and no patch or official remediation is currently available. Public exploit code has been released, but no known exploitation in the wild has been reported. Join the discussion | CVE Database V5 | 03/30/2026, 18:45:13 UTC Added: 03/30/2026, 19:08:17 UTC |
A vulnerability was determined in YunaiV yudao-cloud up to 2025.11. This affects the function BpmHttpCallbackTrigger/BpmSyncHttpRequestTrigger of the component Business Process Management. Executing manipulation of the argument url/header/body can lead to server-side request forgery. The attack may be performed from remote. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 12/26/2025, 03:02:06 UTC Added: 12/26/2025, 03:15:33 UTC |
Showing 1 to 5 of 5 results