Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Apache Answer versions prior to 2.0.2 contain an insufficient session expiration vulnerability where administrative API keys remain valid even after the associated administrator account is demoted, suspended, marked inactive, or deleted. This allows continued unauthorized access until the keys are explicitly revoked. The issue is fixed in version 2.0.2. Join the discussion | GCVE Database | 08/05/2026, 18:31:36 UTC Added: 08/07/2026, 05:57:02 UTC |
0 CVE-2026-60053 is a critical vulnerability in Apache Answer versions prior to 2.0.2. It involves insufficient session expiration where administrative API keys remain valid even after the associated administrator account is demoted, suspended, marked inactive, or deleted. This flaw allows continued unauthorized access until the keys are explicitly removed. The issue is resolved in Apache Answer version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:13:10 UTC Added: 08/05/2026, 16:57:08 UTC |
0 CVE-2026-60023 is a high-severity vulnerability in Apache Answer that allows unauthorized users to access deleted or pending answers through the single-answer read path if the parent question remains visible. This exposure of sensitive information could lead to unauthorized disclosure of answer content that should have been inaccessible. The issue affects Apache Answer versions prior to 2.0.2. Upgrading to version 2.0.2 resolves the vulnerability. Join the discussion | GCVE Database | 08/05/2026, 15:12:08 UTC Added: 08/06/2026, 18:16:35 UTC |
0 CVE-2026-50749 is an improper authorization vulnerability in Apache Answer affecting versions prior to 2.0.2. Authenticated users without review permissions can reject arbitrary pending edit-revisions due to a missing authorization check. The issue is fixed in version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:11:05 UTC Added: 08/05/2026, 16:57:08 UTC |
0 CVE-2026-48912 is an improper input validation vulnerability in Apache Answer up to version 2.0.1. The flaw allows any authenticated user to delete other users' uploaded files by exploiting a missing ownership check in the avatar-cleanup logic. The issue is fixed in version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:10:08 UTC Added: 08/05/2026, 16:57:08 UTC |
0 CVE-2026-48911 is a high-severity vulnerability in Apache Answer up to version 2.0.1. It involves a missing authorization check in the external-login email binding flow, allowing unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. The issue is fixed in version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:09:14 UTC Added: 08/05/2026, 16:57:08 UTC |
0 CVE-2026-48834 is a high-severity vulnerability in Apache Answer up to version 2.0.1. It involves improper handling of length parameter inconsistencies, allowing unauthenticated attackers to cause a denial of service by sending a specially crafted Accept-Language header that triggers excessive CPU consumption during parsing. The issue is fixed in version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:07:35 UTC Added: 08/05/2026, 16:57:08 UTC |
0 Improper Restriction of Security Token Assignment vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Previously issued administrative tokens were not invalidated after an administrator account was suspended, deleted, or deactivated, allowing continued access to administrative APIs until the token expired. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Join the discussion | CVE Database V5 | 06/10/2026, 14:57:00 UTC Added: 06/10/2026, 16:03:35 UTC |
0 Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The unlisted question feature did not enforce access restrictions on direct API endpoints, allowing authenticated users to discover and access unlisted questions, their answers, comments, and revision history. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Join the discussion | CVE Database V5 | 06/09/2026, 09:32:07 UTC Added: 06/09/2026, 09:55:54 UTC |
0 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. A crafted TIFF image could trigger excessive memory allocation during image decoding, allowing an authenticated user to cause the server process to crash. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Join the discussion | CVE Database V5 | 06/09/2026, 09:32:07 UTC Added: 06/09/2026, 09:55:54 UTC |
Showing 1 to 10 of 11 results