Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Trilium Notes, version v0.103.0 and earlier, contains a stored cross-site scripting (XSS) vulnerability in the share renderer for webView notes due to improper HTML escaping of user-controlled #webViewSrc values. This vulnerability allows attackers with note-authoring privileges to inject arbitrary JavaScript that executes for any user who opens the shared note, including administrators. Join the discussion | CVE Database V5 | 09/14/2026, 18:31:28 UTC Added: 09/14/2026, 17:33:55 UTC |
0 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. Prior to 0.103.0, the #iconClass label value is returned raw by getNoteIcon() and inserted without HTML attribute encoding into class attributes in apps/client/src/widgets/quick_search.ts and apps/client/src/services/note_autocomplete.ts, allowing a stored payload to execute automatically when a victim opens a new tab or uses Ctrl+J and, because Electron enables nodeIntegration and disables contextIsolation, run operating-system commands as the victim. This issue is fixed in version 0.103.0. Join the discussion | CVE Database V5 | 08/18/2026, 15:13:16 UTC Added: 08/18/2026, 15:19:59 UTC |
0 CVE-2026-45668 is a critical path traversal and cross-site scripting (XSS) vulnerability in Trilium Notes versions prior to 0.102.2. A malicious ZIP archive imported with safe import enabled can exploit this flaw by using a crafted #docName label with .. / path traversal to access a payload note containing raw HTML/JS. Because the Electron renderer in the desktop client runs with nodeIntegration enabled, this leads to remote code execution (RCE) when the payload executes. The vulnerability is fixed in version 0.102.2. Join the discussion | CVE Database V5 | 05/29/2026, 17:18:28 UTC Added: 05/29/2026, 17:33:42 UTC |
0 Trilium Notes versions 0.102.1 and earlier contain a critical vulnerability due to lack of SVG sanitization combined with a disabled Content Security Policy and a publicly accessible backend API. This flaw allows an attacker to execute arbitrary Node.js code on the server by tricking an authenticated user into viewing a malicious SVG attachment. The vulnerability arises from serving SVGs without sanitization and disabling Helmet's CSP middleware, enabling script execution under the Same-Origin Policy. The issue is fixed in version 0.102.2. Join the discussion | CVE Database V5 | 05/20/2026, 19:13:00 UTC Added: 05/20/2026, 19:34:39 UTC |
Trilium Notes versions 0.102.1 and earlier contain an improper access control vulnerability in the Clipper API when running in an Electron environment. Authentication middleware is disabled, exposing API endpoints without password, token, or CSRF protection. This allows attackers on shared networks to discover and access Trilium instances without authentication, potentially leading to unauthorized data access, phishing, or local system compromise. The issue is fixed in version 0.102.2. Join the discussion | CVE Database V5 | 05/20/2026, 19:05:41 UTC Added: 05/20/2026, 19:34:39 UTC |
0 Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Electron configuration is vulnerable to TCC Bypass via Prompt Spoofing, allowing local attackers to trigger misleading macOS permission prompts by running malicious code under the identity of the trusted app. The root cause is that the RunAsNode fuse allows launching the app in a special Node.js mode using -e to execute arbitrary system commands with Trilium Notes's permissions and identity. An attacker can leverage this through a subprocess to request any sensitive permissions, such as access to hardware (camera, microphone) and TCC-protected files, causing the TCC system prompt to appear as if the request came from Trilium rather than the attacker's code, because macOS treats the subprocess as part of the parent application. Exploitation allows access to TCC-protected resources like the screen, camera, microphone, and folders such as ~/Documents and ~/Downloads, undermining macOS's security model and UI integrity through social engineering. This issue has been fixed in version 0.102.2. Join the discussion | CVE Database V5 | 05/19/2026, 23:54:46 UTC Added: 05/20/2026, 00:18:42 UTC |
0 Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, allowing an authenticated attacker to read sensitive arbitrary files from the server's filesystem. The uploadModifiedFileToAttachment function, which is called when a POST request is received to /api/attachments/{attachmentId}/upload-modified-file, replaces the content of the attachment with the content from another file (whose path is provided in filePath of Request body). After which the content of the attachment can be viewed at /api/attachments/{attachmentId}/download. This exposes sensitive system files such as SSH keys, credentials, configs, and OS files, potentially leading to remote code execution and compromise of co-hosted applications. This issue has been fixed in version 0.102.2. Join the discussion | CVE Database V5 | 05/19/2026, 23:32:54 UTC Added: 05/19/2026, 23:48:50 UTC |
Trilium Notes is an open-source, cross-platform hierarchical note taking application with focus on building large personal knowledge bases. Prior to 0.101.0, a critical timing attack vulnerability in Trilium's sync authentication endpoint allows unauthenticated remote attackers to recover HMAC authentication hashes byte-by-byte through statistical timing analysis. This enables complete authentication bypass without password knowledge, granting full read/write access to victim's knowledge base. This vulnerability is fixed in 0.101.0. Join the discussion | CVE Database V5 | 02/06/2026, 21:21:19 UTC Added: 02/07/2026, 08:01:02 UTC |
Showing 1 to 8 of 8 results