Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-60023 is a high-severity vulnerability in Apache Answer versions prior to 2.0.2. It allows unauthorized users to retrieve deleted or pending answers through the single-answer read path if the parent question remains visible, exposing sensitive information that should not be accessible. The issue is fixed in version 2.0.2. Join the discussion | CVE Database V5 | 08/05/2026, 15:12:08 UTC Added: 08/05/2026, 16:57:08 UTC |
0 An improper input validation vulnerability exists in Apache Answer through version 2.0.1. The issue arises from a missing ownership check in the avatar-cleanup logic, allowing any authenticated user to delete files uploaded by other users by supplying their file URLs. The vulnerability is fixed in version 2.0.2. Join the discussion | GCVE Database | 08/05/2026, 15:10:08 UTC Added: 08/06/2026, 18:16:35 UTC |
0 Apache Answer versions through 2.0.1 contain an insufficient verification of data authenticity vulnerability. This flaw is due to a missing authorization check in the external-login email binding flow, which allows unauthenticated attackers to take over arbitrary user accounts by tricking victims into clicking a crafted confirmation link. The issue is fixed in version 2.0.2. Join the discussion | GCVE Database | 08/05/2026, 15:09:14 UTC Added: 08/06/2026, 18:16:35 UTC |
0 CVE-2026-48834 is a high-severity vulnerability in Apache Answer up to version 2.0.1. It involves improper handling of length parameter inconsistencies in the Accept-Language header, allowing unauthenticated attackers to cause denial of service by triggering excessive CPU consumption during parsing. The issue is fixed in version 2.0.2. Join the discussion | GCVE Database | 08/05/2026, 15:07:35 UTC Added: 08/06/2026, 18:16:35 UTC |
CVE-2026-34033 is a medium severity vulnerability in Apache Answer affecting versions before 2.0.1. It involves improper neutralization of script-related HTML tags (basic XSS) where user-supplied content is included in notification emails without proper escaping. This allows authenticated users to inject arbitrary HTML into emails sent to other users. The issue is fixed in Apache Answer version 2.0.1. Join the discussion | CVE Database V5 | 06/09/2026, 09:32:07 UTC Added: 06/09/2026, 09:55:54 UTC |
0 Unrestricted Upload of File with Dangerous Type vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. The server did not sufficiently validate user-supplied image URLs, allowing arbitrary external content to be embedded as profile images, which could expose users to unintended external requests and tracking by third-party servers. Users are recommended to upgrade to version 2.0.1, which fixes the issue. Join the discussion | CVE Database V5 | 06/09/2026, 09:32:07 UTC Added: 06/09/2026, 09:55:54 UTC |
0 CVE-2026-25688 is a medium severity vulnerability in Apache Answer up to version 2.0.0. It involves improper neutralization of alternate cross-site scripting (XSS) syntax in AI-generated response content, which is rendered in the browser without proper sanitization. This flaw allows malicious scripts to execute when the content is viewed. The issue is fixed in version 2.0.1. Join the discussion | CVE Database V5 | 06/09/2026, 07:32:23 UTC Added: 06/09/2026, 09:55:54 UTC |
0 Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 1.7.1. An unauthenticated API endpoint incorrectly exposes full revision history for deleted content. This allows unauthorized user to retrieve restricted or sensitive information. Users are recommended to upgrade to version 2.0.0, which fixes the issue. Join the discussion | CVE Database V5 | 02/04/2026, 10:41:58 UTC Added: 02/04/2026, 16:15:10 UTC |
Showing 1 to 8 of 8 results