Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 A Server-Side Request Forgery (SSRF) and Local File Inclusion (LFI) vulnerability exists in Apache MyFace Core. This affects older unsupported versions and can be mitigated by upgrading to fixed versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4. No CVSS score is available for this vulnerability. Join the discussion | GCVE Database | 09/16/2026, 21:32:43 UTC Added: 09/17/2026, 02:00:14 UTC |
0 A remote attacker could cause excessive resource consumption by supplying specially crafted request parameters, potentially resulting in a denial of service condition. Older unsupported versions may also be affected. Users are recommended to upgrade to versions 2.3.12, 2.3-next-M9, 3.0.4, 4.0.4, or 4.1.4, which fix this issue. Join the discussion | CVE Database V5 | 09/16/2026, 19:17:01 UTC Added: 09/16/2026, 19:32:03 UTC |
0 In Siglet current and past versions the refresh token handler do not enforce proof of possession of the issuer DID. Join the discussion | CVE Database V5 | 09/14/2026, 15:32:36 UTC Added: 09/14/2026, 15:47:16 UTC |
0 Silverpeas Core versions up to and including 6.4.6 contain a Cross Site Scripting (XSS) vulnerability in the Multimedia library application introduction component. This vulnerability allows an attacker to inject malicious scripts that could be executed in the context of a user's browser session. The vulnerability has a medium severity rating with a CVSS score of 6.1. No official patch or remediation information is provided in the available data. Join the discussion | CVE Database V5 | 09/08/2026, 00:00:00 UTC Added: 09/08/2026, 20:52:42 UTC |
0 Silverpeas Core versions up to and including 6.4.6 contain a Cross Site Scripting (XSS) vulnerability in the wysiwyg-CKEditor image upload feature. This vulnerability allows an attacker to inject malicious scripts that can be executed in the context of the affected application. The vulnerability has a CVSS score of 6.1, indicating a medium severity level. Join the discussion | CVE Database V5 | 09/08/2026, 00:00:00 UTC Added: 09/08/2026, 20:52:42 UTC |
0 Silverpeas Core version 6.4.6 contains a Cross Site Scripting (XSS) vulnerability in its Document management file upload feature. This vulnerability allows an attacker to execute malicious scripts in the context of a user's browser session. The vulnerability has a medium severity rating with a CVSS score of 6.1. Join the discussion | CVE Database V5 | 09/08/2026, 00:00:00 UTC Added: 09/08/2026, 20:52:42 UTC |
HAPI FHIR is a complete implementation of the HL7 FHIR standard for healthcare interoperability in Java. Prior to 6.9.11, XhtmlParser.java imposes no maximum element nesting depth, so a deeply nested text.div narrative triggers unbounded recursion between parseElementInner() and parseElement(), raising a StackOverflowError. An attacker who can submit FHIR resources containing such narratives can thus crash a parsing or validation worker thread, affecting validator services and any application that parses attacker-supplied FHIR JSON or XML. This issue is fixed in version 6.9.11. Join the discussion | CVE Database V5 | 08/07/2026, 20:03:17 UTC Added: 08/08/2026, 12:51:35 UTC |
0 Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services: * Reading of GeoTIFF files having the GEO_METADATA tag defined by the Defense Geospatial Information Working Group (DGIWG). * Parsing of ISO 19115 metadata in XML format. * Parsing of Coordinate Reference Systems defined in the GML format. * Parsing of files in GPS Exchange Format (GPX). This issue affects Apache SIS from versions 0.4 through 1.5 inclusive. Users are recommended to upgrade to version 1.6, which will fix the issue. In the meantime, the security vulnerability can be avoided by launching Java with the javax.xml.accessExternalDTD system property sets to a comma-separated list of authorized protocols. For example: java -Djavax.xml.accessExternalDTD="" ... Join the discussion | CVE Database V5 | 01/05/2026, 13:45:21 UTC Added: 01/05/2026, 14:03:09 UTC |
Showing 1 to 8 of 8 results