Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 In JetBrains YouTrack before 2026.1.14047 predefined search fields leaked all group names to any user, regardless of visibility permission Join the discussion | GCVE Database | 09/07/2026, 16:26:48 UTC Added: 09/08/2026, 04:37:39 UTC |
0 CVE-2026-86498 is a high-severity vulnerability in JetBrains YouTrack that affects versions before 2025.3.160480 and 2026.1.14047. It allows PUT requests on link sub-resources to modify linked entities without requiring update permissions, violating proper access control. Join the discussion | CVE Database V5 | 09/07/2026, 16:26:48 UTC Added: 09/07/2026, 16:37:47 UTC |
0 In JetBrains YouTrack before 2026.2.18769 changing a mailbox host without re-authentication allowed a project administrator to exfiltrate stored mailbox credentials Join the discussion | GCVE Database | 09/07/2026, 16:26:47 UTC Added: 09/08/2026, 04:37:38 UTC |
0 In JetBrains YouTrack before 2026.2.18634 cloning a whiteboard allowed unauthorized changes to links on inaccessible issues Join the discussion | GCVE Database | 09/07/2026, 16:26:46 UTC Added: 09/08/2026, 04:37:39 UTC |
0 In JetBrains YouTrack before 2026.2.18634 signed URL reuse allowed disclosure of restricted project icons Join the discussion | GCVE Database | 09/07/2026, 16:26:41 UTC Added: 09/08/2026, 04:37:43 UTC |
0 CVE-2026-86479 is a high-severity vulnerability in JetBrains YouTrack that allows unauthorized access to restricted REST API resources due to missing authorization checks (CWE-862). This affects versions before 2026.2.18788, 2026.1.14055, and 2025.3.161254. The vulnerability enables an attacker with limited privileges to access sensitive data via an IDOR (Insecure Direct Object Reference) flaw. No known exploits are reported in the wild, and no official patch links are provided in the available data. Join the discussion | CVE Database V5 | 09/07/2026, 16:26:41 UTC Added: 09/07/2026, 16:37:43 UTC |
0 CVE-2026-86478 is a critical authentication vulnerability in JetBrains YouTrack before versions 2025.3.161254 and 2026.1.14042. It allows unauthenticated attackers to take over accounts by exploiting improper authentication in the YouTrack Helpdesk component via self-asserted email addresses. Join the discussion | CVE Database V5 | 09/07/2026, 16:26:40 UTC Added: 09/07/2026, 16:37:43 UTC |
0 In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas Join the discussion | CVE Database V5 | 05/29/2026, 18:15:54 UTC Added: 05/29/2026, 18:33:55 UTC |
0 CVE-2026-49370 is a low-severity information disclosure vulnerability in JetBrains YouTrack versions before 2026.1.13162. It involves the exposure of information through fetchApp requests. The vulnerability has a CVSS score of 3.4, indicating limited impact. There is no confirmed patch or official remediation guidance available at this time. No known exploits are reported in the wild. The vulnerability requires high privileges and user interaction to be exploited. Join the discussion | CVE Database V5 | 05/29/2026, 18:15:47 UTC Added: 05/29/2026, 18:33:46 UTC |
0 CVE-2026-49369 is a medium severity vulnerability in JetBrains YouTrack versions before 2026.1.13162 that allows information disclosure on the Users and Groups pages. The issue is classified under CWE-863, which relates to improper authorization. The vulnerability does not require user interaction and can be exploited remotely with low complexity, but requires some level of privileges. There is no official patch or remediation level confirmed yet. No known exploits are reported in the wild. The impact is limited to confidentiality loss without affecting integrity or availability. Join the discussion | CVE Database V5 | 05/29/2026, 18:15:46 UTC Added: 05/29/2026, 18:33:46 UTC |
Showing 1 to 10 of 11 results