Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
JeecgBoot versions through 3.9.2 have a broken access control vulnerability allowing authenticated low-privilege users to fully manage OpenAPI credentials via endpoints lacking proper authorization. This enables attackers to list, add, edit, and delete all API key pairs, with secret keys exposed in plaintext, risking credential theft and unauthorized API access. Join the discussion | GCVE Database | 06/30/2026, 18:31:40 UTC Added: 06/30/2026, 23:36:02 UTC |
0 An open redirect vulnerability exists in JeecgBoot versions 3.9.0 through 3.9.2 in the Third-Party Login component. The issue arises from improper handling of the argument to HttpServletResponse.sendRedirect in the ThirdLoginController.java file. Exploitation requires user interaction via social engineering to click a malicious OAuth login link. The vulnerability has low exploitability and a low CVSS score of 2.3. The third-party login feature is optional and may not be enabled in many deployments. Join the discussion | CVE Database V5 | 06/08/2026, 09:30:10 UTC Added: 06/08/2026, 10:04:05 UTC |
CVE-2026-11464: Information Disclosure in JeecgBootCVE-2026-11464 0 A vulnerability was identified in JeecgBoot up to 3.9.2. Affected by this vulnerability is the function queryPageList of the file src\main\java\org\jeecg\modules\system\controller\SysUserController.java of the component User List Endpoint. The manipulation of the argument salt leads to information disclosure. The attack may be initiated remotely. The attack is considered to have high complexity. The exploitation appears to be difficult. The exploit is publicly available and might be used. A fix is planned for the upcoming release. Join the discussion | CVE Database V5 | 06/07/2026, 22:30:11 UTC Added: 06/07/2026, 22:48:36 UTC |
0 A security flaw has been discovered in jeecgboot The server processes these URLs up to 3.9.1. This affects the function FileDownloadUtils.download2DiskFromNet of the file /airag/app/debug of the component Cloud Instance Metadata Endpoint. The manipulation results in server-side request forgery. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Upgrading to version 3.9.2 mitigates this issue. It is suggested to upgrade the affected component. Join the discussion | CVE Database V5 | 06/01/2026, 08:30:10 UTC Added: 06/01/2026, 09:18:38 UTC |
0 A vulnerability has been found in JeecgBoot 3.9.1. This issue affects some unknown processing of the file /openapi/call/ of the component OpenAPI Endpoint. Such manipulation leads to improper authentication. The attack can be executed remotely. A high complexity level is associated with this attack. The exploitability is assessed as difficult. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/24/2026, 10:15:10 UTC Added: 05/24/2026, 10:31:37 UTC |
0 A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginController.java of the component mLogin Endpoint. This manipulation causes authorization bypass. The attack is possible to be carried out remotely. The attack is considered to have high complexity. The exploitability is regarded as difficult. The exploit has been published and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/09/2026, 20:15:11 UTC Added: 05/09/2026, 20:36:41 UTC |
0 A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/CommonController.java of the component SVG File Handler. The manipulation results in cross site scripting. The attack can be executed remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/09/2026, 20:00:11 UTC Added: 05/09/2026, 20:23:29 UTC |
0 A security flaw has been discovered in JeecgBoot up to 3.9.1. This vulnerability affects the function CommonController.uploadImgByHttp/HttpFileToMultipartFileUtil.httpFileToMultipartFile/HttpFileToMultipartFileUtil.downloadImageData of the file CommonController.java of the component uploadImgByHttpEndpoint. Performing a manipulation results in server-side request forgery. The attack can be initiated remotely. The exploit has been released to the public and may be used for attacks. Upgrading the affected component is recommended. The vendor confirmed the issue and will provide a fix in the upcoming release. Join the discussion | CVE Database V5 | 05/02/2026, 06:15:12 UTC Added: 05/02/2026, 06:51:24 UTC |
0 A vulnerability was identified in JeecgBoot up to 3.9.1. This affects the function OpenApiController.add/OpenApiController.call of the file OpenApiController.java of the component OpenApi Service. Such manipulation of the argument originUrl database leads to server-side request forgery. It is possible to launch the attack remotely. The exploit is publicly available and might be used. It is suggested to upgrade the affected component. The vendor confirmed the issue and will provide a fix in the upcoming release. Join the discussion | CVE Database V5 | 05/02/2026, 04:45:12 UTC Added: 05/02/2026, 05:21:55 UTC |
0 A vulnerability was determined in JeecgBoot up to 3.9.1. Affected by this issue is the function checkPathTraversalBatch of the file FileDownloadUtils.jav of the component LoadFile Endpoint. This manipulation of the argument files causes server-side request forgery. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The affected component should be upgraded. The vendor confirmed the issue and will provide a fix in the upcoming release. Join the discussion | CVE Database V5 | 05/02/2026, 04:15:11 UTC Added: 05/02/2026, 05:21:55 UTC |
Showing 1 to 10 of 24 results