Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Apache CloudStack's NAS backup provider… (CVE-2026-47359)CVE-2026-47359 0 Apache CloudStack contains an OS Command Injection vulnerability in its NAS backup provider plugin. The addBackupRepository and updateBackupRepository APIs accept unsanitized command options, allowing a malicious operator to inject arbitrary commands executed on the KVM hypervisor host during backup restore operations. This affects versions from 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0. Fixed versions are 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:04 UTC Added: 08/21/2026, 14:22:27 UTC |
Improper Access Control vulnerability in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing cross-tenant manipulation of the Kubernetes… (CVE-2026-62440)CVE-2026-62440 0 An improper access control vulnerability exists in Apache CloudStack's Kubernetes Service (CKS) plugin, allowing unauthorized cross-tenant manipulation of Kubernetes clusters during node addition and removal. This affects Apache CloudStack versions from 4.21.0.0 through 4.22.1.0. The issue is resolved in version 4.22.1.1 and later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:27 UTC |
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Lock User Functionality. (CVE-2026-61399)CVE-2026-61399 0 An improper encoding or escaping of output vulnerability exists in Apache CloudStack's UI related to the Lock User functionality. This vulnerability affects versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue has been fixed in versions 4.20.3.1 and 4.22.1.1 or later. Users are advised to upgrade to these fixed versions to remediate the vulnerability. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Server-Side Request Forgery (SSRF) vulnerability in Apache CloudStack's webhook module, exploitable via webhook delivery requests. (CVE-2026-59085)CVE-2026-59085 0 A Server-Side Request Forgery (SSRF) vulnerability exists in the webhook module of Apache CloudStack. This vulnerability can be exploited via webhook delivery requests. It affects Apache CloudStack versions from 4.20.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue is fixed in versions 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Cleartext Storage of Sensitive Information vulnerability in Apache CloudStack with AsyncJob storage in the database. (CVE-2026-59657)CVE-2026-59657 0 Apache CloudStack versions 4.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 contain a vulnerability where sensitive information is stored in cleartext within the AsyncJob database storage. This issue is identified as CVE-2026-59657 and relates to CWE-312 (Cleartext Storage of Sensitive Information). Upgrading to versions 4.20.3.1 or 4.22.1.1 or later addresses this vulnerability. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth authentication plugin while listing OAuth… (CVE-2026-59655)CVE-2026-59655 0 An exposure of sensitive information vulnerability exists in Apache CloudStack's OAuth authentication plugin when listing OAuth providers. This affects versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue allows unauthorized actors to access sensitive data. Fixed versions are 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's LDAP authentication plugin while listing LDAP… (CVE-2026-59780)CVE-2026-59780 0 Apache CloudStack versions from 4.2.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 have a vulnerability in the LDAP authentication plugin that allows any authenticated user with access to the listLdapConfigurations API to list LDAP configurations, exposing sensitive information. By default, this API is accessible to all default roles. The issue is fixed in versions 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Improper Encoding or Escaping of Output vulnerability in Apache CloudStack's UI while using Instance Reset Password functionality. (CVE-2026-61398)CVE-2026-61398 0 An improper encoding or escaping of output vulnerability exists in Apache CloudStack's UI during the Instance Reset Password functionality. This affects versions from 4.15.1.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue is fixed in versions 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache CloudStack's run and get diagnostics… (CVE-2026-61400)CVE-2026-61400 0 Apache CloudStack versions 4.20.0.0 through 4.20.3.0 and 4.21.0.0 through 4.22.1.0 contain a command injection vulnerability in the run and get diagnostics functionality for system VMs and virtual routers. Authenticated users with admin permissions to invoke getDiagnosticsData or runDiagnostics APIs can execute arbitrary commands as root or diagnostics-process user on affected instances. This can lead to full compromise of the instance and potential lateral movement within the CloudStack infrastructure. The vulnerability is fixed in versions 4.20.3.1 and 4.22.1.1 or later. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth… (CVE-2026-61397)CVE-2026-61397 0 A vulnerability in Apache CloudStack's OAuth2 authentication plugin and Google OAuth integration allows exposure of sensitive information to unauthorized actors. This affects Apache CloudStack versions from 4.19.0.0 through 4.20.3.0 and from 4.21.0.0 through 4.22.1.0. The issue is fixed in versions 4.20.3.1 and 4.22.1.1. Join the discussion | GCVE Database | 08/21/2026, 09:32:05 UTC Added: 08/21/2026, 14:22:26 UTC |
Showing 1 to 10 of 34 results