Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2025-15039 is a critical vulnerability in WSO2 Identity Server affecting multiple versions. It involves a protection mechanism failure in the Conditional Authentication (Adaptive Authentication) script, which does not properly enforce completion of all required authentication steps in certain multi-step authentication flows. This flaw allows attackers to bypass intermediate authentication challenges under specific conditions, potentially gaining unauthorized access to user accounts. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:23 UTC Added: 08/06/2026, 08:11:46 UTC |
0 CVE-2025-13394 is a Cross-Site Request Forgery (CSRF) vulnerability in the Ajax processor of the Carbon console within WSO2 Identity Server. The vulnerability arises because state-changing operations use the HTTP GET method and rely on the SameSite=Lax cookie attribute for CSRF mitigation, which can be bypassed. This allows attackers to trick authenticated users into unknowingly performing unauthorized actions. Exploitation requires the Carbon console and related services to be publicly accessible, which is against WSO2's security recommendations. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:17 UTC Added: 08/06/2026, 08:11:46 UTC |
0 CVE-2025-12627 is a vulnerability in WSO2 Identity Server versions 7.0.0 and 7.1.0 where the user impersonation flow does not properly expire refresh tokens. This allows an attacker with an access token for an impersonated user to use the refresh token to obtain new access tokens, extending unauthorized access. The flaw compromises log integrity and traceability by masking the true actor. The CVSS score is low, reflecting limited impact on confidentiality and availability but some impact on integrity. Join the discussion | CVE Database V5 | 08/06/2026, 07:33:12 UTC Added: 08/06/2026, 08:11:46 UTC |
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser to redirect to a malicious website, modify the UI of the webpage, or retrieve information from the browser. However, the impact is mitigated by the use of httpOnly flags on session-related cookies, preventing session hijacking. Join the discussion | CVE Database V5 | 07/06/2026, 10:16:53 UTC Added: 07/06/2026, 10:21:55 UTC |
In multi-tenanted deployments, the application consent management mechanism fails to correctly isolate consent scopes between tenants. Consent granted by a user for a specific SaaS application within one tenant can be incorrectly applied to SaaS applications with the same name in other tenants, leading to unintended cross-tenant consent sharing. This vulnerability may result in the exposure of user data across tenants, enabling SaaS applications in different tenants to access and modify information without explicit user authorization. This can lead to unauthorized data access and privacy violations. This vulnerability has no impact if the deployment does not support multi-tenancy. Join the discussion | CVE Database V5 | 07/04/2026, 12:49:06 UTC Added: 07/04/2026, 13:22:07 UTC |
0 The Magic Link authentication flow accepts multiple invalid authentication requests without adequate rate limiting or resource control, leading to uncontrolled memory usage growth. This vulnerability can result in a denial-of-service condition, causing service unavailability for deployments that utilize the Magic Link authenticator. The impact is limited to these specific deployments and requires repeated invalid authentication attempts to trigger. Join the discussion | CVE Database V5 | 05/11/2026, 10:16:52 UTC Added: 05/11/2026, 11:22:10 UTC |
Due to not validating the organization context when executing adaptive authentication flows, the WSO2 Identity Server allows adaptive authentication logic to be triggered on unintended organizations. A malicious actor with privileges to configure adaptive authentication within one organization can leverage this functionality to execute authentication logic on other organizations and sub-organizations. This flaw allows bypassing authorization boundaries between organizations, leading to unauthorized access to critical operations and user accounts in other organizations. When adaptive authentication is enabled in a multi-organization deployment, a malicious actor with privileges to configure adaptive authentication in one organization could exploit this feature to perform critical operations in other organizations without authorization. This may result in privilege escalation, unauthorized access to resources, and potential account takeover across organizations. Join the discussion | CVE Database V5 | 05/11/2026, 10:12:39 UTC Added: 05/11/2026, 11:22:10 UTC |
CVE-2024-0391 is a medium severity vulnerability in WSO2 Identity Server versions 5.10.0 through 7.0.0. It involves an observable response discrepancy in the email OTP flow's user account lock state check, which fails to properly validate user input. This flaw allows an attacker to determine whether specific usernames are registered in the system. Such information disclosure can facilitate brute-force and social engineering attacks, increasing risks to user data and organizational security. Join the discussion | CVE Database V5 | 05/11/2026, 08:45:33 UTC Added: 05/11/2026, 10:06:25 UTC |
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious JavaScript payloads, enabling reflected cross-site scripting. An attacker can leverage this vulnerability to redirect the user's browser to a malicious website, modify the user interface of the web page, retrieve information from the browser, or cause other harmful actions. However, due to the protection of session-related cookies with the httpOnly flag, session hijacking is not possible. Join the discussion | CVE Database V5 | 04/29/2026, 08:08:37 UTC Added: 04/29/2026, 08:36:22 UTC |
0 Active access tokens are not revoked or invalidated when a user account is locked within WSO2 Identity Server. This failure to enforce revocation allows previously issued, valid tokens to remain usable, enabling continued access to protected resources by locked user accounts. The security consequence is that a locked user account can maintain access to protected resources through the use of existing, unexpired access tokens. This creates a security gap where access control policies are bypassed, potentially leading to unauthorized data access or actions until the tokens naturally expire. Join the discussion | CVE Database V5 | 04/16/2026, 10:25:19 UTC Added: 04/16/2026, 10:47:04 UTC |
Showing 1 to 10 of 14 results