Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
Path traversal vulnerability in Apache Zeppelin. When FileSystemNotebookRepo is configured, an authenticated attacker with permission to rename a note, or access to folder operations, could supply traversal segments in note or folder paths. Zeppelin composed these values into filesystem paths using the server's filesystem or Hadoop identity without ensuring that the result remained under the configured notebook directory. This could allow notebook files or directories to be moved, written, or deleted outside the notebook root. This issue affects Apache Zeppelin versions 0.9.0 through 0.12.0. Users are recommended to upgrade to version 0.12.1, which fixes this issue. Join the discussion | GCVE Database | 07/31/2026, 12:30:30 UTC Added: 07/31/2026, 15:37:32 UTC |
Apache Zeppelin versions 0.6.0 through 0.12.0 have a Cross-Site Request Forgery (CSRF) vulnerability due to a permissive default CORS configuration that allows cross-origin state-changing requests and accepts text/plain request bodies. This enables an attacker to trick an authenticated user into performing unintended actions via REST and WebSocket endpoints. The issue is fixed in version 0.12.1. Join the discussion | GCVE Database | 07/30/2026, 18:31:39 UTC Added: 07/30/2026, 23:28:28 UTC |
Apache Zeppelin versions 0.11.1, 0.11.2, and 0.12.0 contain an LDAP injection vulnerability due to improper escaping of special characters in LDAP search filters. This vulnerability is an incomplete fix of a previous issue (CVE-2024-31867). The issue is resolved in version 0.12.1. The CVSS score is 6.5, indicating a medium severity risk. Join the discussion | CVE Database V5 | 07/30/2026, 15:22:39 UTC Added: 07/30/2026, 21:00:42 UTC |
Apache Zeppelin versions 0.6.0 through 0.12.0 contain an LDAP injection vulnerability in the ActiveDirectoryGroupRealm component. This flaw allows an authenticated attacker to inject LDAP filter syntax via the user-search endpoint and potentially expose directory information. The role-lookup path is also affected after successful LDAP authentication. The issue is fixed in version 0.12.1. Join the discussion | CVE Database V5 | 07/30/2026, 15:21:21 UTC Added: 07/30/2026, 16:22:57 UTC |
0 Missing Origin Validation in WebSockets vulnerability in Apache Zeppelin. The attacker could access the Zeppelin server from another origin without any restriction, and get internal information about paragraphs. This issue affects Apache Zeppelin: from 0.11.1 before 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue. Join the discussion | CVE Database V5 | 08/03/2025, 10:13:17 UTC Added: 11/04/2025, 21:24:21 UTC |
0 The attacker can use the raft server protocol in an unauthenticated way. The attacker can see the server's resources, including directories and files. This issue affects Apache Zeppelin: from 0.10.1 up to 0.12.0. Users are recommended to upgrade to version 0.12.0, which fixes the issue by removing the Cluster Interpreter. Join the discussion | CVE Database V5 | 07/12/2025, 16:22:35 UTC Added: 11/04/2025, 21:24:19 UTC |
Showing 1 to 6 of 6 results