Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Incorrect privilege assignment vulnerability in Apache Syncope. When the configured JWKS settings for internal JWT authentication are disclosed (at least protocol and key), an attacker can obtain admin privileges after completing a successful authentication and obtaining a valid low-privileges JWT. This issue affects Apache Syncope: from 3.0.0-M0 through 3.0.16, from 4.0.0-M0 through 4.0.7, from 4.1.0-M0 through 4.1.2. Users are recommended to upgrade to version 4.0.8 / 4.1.3, which fix this issue. Join the discussion | CVE Database V5 | 09/14/2026, 12:24:56 UTC Added: 09/14/2026, 12:47:56 UTC |
0 Apache Syncope versions 3.0.15 through 3.0.16, 4.0.3 through 4.0.7, and 4.1.0-M0 through 4.1.2 contain a vulnerability where sensitive information, specifically the AES key after padding, is inserted into log files. This occurs when a non-standard length AES key is configured, causing Syncope to pad the key with random characters and log the resulting value. Upgrading to versions 4.0.8 or 4.1.3 addresses this issue. Join the discussion | CVE Database V5 | 09/14/2026, 10:42:56 UTC Added: 09/14/2026, 10:47:04 UTC |
0 Apache Syncope versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.7, and 4.1.0-M0 through 4.1.2 contain an authentication bypass vulnerability due to spoofing. This occurs when JWKS settings for internal JWT authentication are disclosed, allowing an attacker who has authenticated successfully and obtained a valid JWT to spoof another user's privileges. Upgrading to versions 4.0.8 or 4.1.3 resolves this issue. Join the discussion | CVE Database V5 | 09/14/2026, 10:38:12 UTC Added: 09/14/2026, 10:47:04 UTC |
0 Apache Syncope contains an improper isolation vulnerability allowing an administrator with Implementation entitlements to create malicious Groovy classes that bypass the Groovy security sandbox. This affects versions from 3.0.0-M0 through 3.0.16, 4.0.0-M0 through 4.0.6, and 4.1.0-M0 through 4.1.1. The issue is fixed in versions 4.0.7 and 4.1.2 by tightening the Groovy sandbox. Join the discussion | CVE Database V5 | 07/20/2026, 14:19:19 UTC Added: 07/20/2026, 14:42:41 UTC |
0 Apache Syncope versions 3.0 through 3.0.16, 4.0 through 4.0.5, and 4.1.0 contain an improper isolation vulnerability. An administrator with sufficient privileges can create malicious Groovy code that executes outside the intended sandbox, including static initializers. This can lead to unauthorized code execution with high impact on confidentiality, integrity, and availability. Fixed versions 4.0.6 and 4.1.1 enforce sandboxing even for static initializers in Groovy code. Join the discussion | CVE Database V5 | 05/25/2026, 14:58:59 UTC Added: 05/25/2026, 15:40:00 UTC |
Showing 1 to 5 of 5 results