Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:maven/org.apache.ofbiz/ofbiz

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-50223 is a high-severity code injection vulnerability in Apache OFBiz that allows a low-privileged authenticated user with Content/DataResource editing rights to perform template injection attacks potentially leading to remote code execution. The vulnerability affects versions of Apache OFBiz before 24.09.07. Users are advised to upgrade to version 24.09.07, which addresses this issue.

Join the discussion

CVE-2026-46586 is a high-severity vulnerability in Apache OFBiz prior to version 24.09.06 involving improper control of code generation, specifically code injection and eval injection issues. This allows an attacker with low privileges to execute arbitrary code without user interaction, potentially leading to full compromise of confidentiality, integrity, and availability. The vulnerability is fixed in Apache OFBiz version 24.09.06. No known exploits are reported in the wild at this time.

Join the discussion

CVE-2026-45434 is a critical improper authentication vulnerability in Apache OFBiz before version 24.09.06. The flaw exists in the password-change logic and can lead to remote code execution without requiring authentication. The vulnerability has a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. Users are advised to upgrade to Apache OFBiz version 24.09.06, which addresses this issue.

Join the discussion

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

CVE-2026-35086 is a medium severity vulnerability in Apache OFBiz affecting its email services. It involves improper control of code generation, classified as a code injection issue (CWE-94). The vulnerability exists in versions before 24.09.06. Users are advised to upgrade to version 24.09.06 where the issue is fixed. The CVSS score is 6.5, indicating a network exploitable vulnerability with low impact on confidentiality and integrity and no impact on availability.

Join the discussion

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

Join the discussion

Showing 1 to 10 of 24 results

Filters:Package: pkg:maven/org.apache.ofbiz/ofbiz
Page 1 of 3
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses