Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-8740 is a medium severity vulnerability in Sanluan PublicCMS version 5.202506.d. It involves improper neutralization of special elements in the template engine within the execute function of TemplateResultDirective.java. This flaw allows remote attackers to manipulate templateContent arguments, potentially leading to unintended behavior. An exploit has been published, but there is no vendor response or official patch available at this time. Join the discussion | CVE Database V5 | 05/17/2026, 08:00:12 UTC Added: 05/17/2026, 09:06:42 UTC |
A vulnerability was detected in Sanluan PublicCMS 5.202506.d. The affected element is the function getSignKey of the file publiccms-core/src/main/java/com/publiccms/logic/component/config/SafeConfigComponent.java. The manipulation of the argument privatefile_key results in use of hard-coded cryptographic key . The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/17/2026, 07:45:12 UTC Added: 05/17/2026, 08:06:38 UTC |
A security vulnerability has been detected in Sanluan PublicCMS 5.202506.d. Impacted is the function TradeOrderController.pay/TradePaymentController.pay/AccountGatewayComponent.pay of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeOrderController.java of the component Trade Payment Flow. The manipulation leads to business logic errors. Remote exploitation of the attack is possible. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/17/2026, 07:30:10 UTC Added: 05/17/2026, 08:06:38 UTC |
0 CVE-2026-6797 is a medium severity vulnerability in Sanluan PublicCMS versions up to 6.202506.d. It involves the ZipSecureFile.setMinflateRatio function in the DocToHtmlUtils.java file, where crafted input can cause resource consumption. The vulnerability can be exploited remotely without user interaction or privileges. The vendor has not responded to the disclosure, and no patch or official remediation is currently available. Join the discussion | CVE Database V5 | 04/21/2026, 20:45:13 UTC Added: 04/21/2026, 21:01:37 UTC |
A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the component Failed Login Handler. This manipulation of the argument errorPassword causes cleartext storage in a file or on disk. It is possible to initiate the attack remotely. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/21/2026, 20:30:18 UTC Added: 04/21/2026, 20:46:07 UTC |
0 A weakness has been identified in Sanluan PublicCMS 6.202506.d. This impacts the function saveMetadata of the file TemplateCacheComponent.java of the component Template Cache Generation. Executing a manipulation can lead to path traversal. The attack can be executed remotely. The exploit has been made available to the public and could be used for attacks. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 02/27/2026, 04:32:10 UTC Added: 02/27/2026, 19:11:13 UTC |
A vulnerability was found in Sanluan PublicCMS up to 5.202506.d. Affected is the function delete of the file publiccms-trade/src/main/java/com/publiccms/controller/web/trade/TradeAddressController.java of the component Trade Address Deletion Endpoint. Performing a manipulation of the argument ids results in improper authorization. The attack may be initiated remotely. The exploit has been made public and could be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 01/18/2026, 06:02:06 UTC Added: 01/18/2026, 06:26:45 UTC |
Showing 1 to 7 of 7 results