Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-73665: CWE-862: Missing Authorization in FreePBX ucpCVE-2026-73665 0 CVE-2026-73665 is a critical vulnerability in FreePBX UCP prior to version 17.0.9. It involves missing authorization checks in the UCP Node server, allowing unauthenticated clients to connect to custom namespaces without proper authentication. This can lead to arbitrary command execution as the asterisk service user. The issue is fixed in FreePBX version 17.0.9. Join the discussion | CVE Database V5 | 08/13/2026, 21:32:02 UTC Added: 08/13/2026, 21:56:43 UTC |
CVE-2026-73664: CWE-269: Improper Privilege Management in FreePBX backupCVE-2026-73664 0 FreePBX is an open source IP PBX. From 17.0.5.34 until 17.0.11, the publicKeySave AJAX endpoint in Backup.class.php accepts an authenticated administrator's SSH public key and appends it to /home/asterisk/.ssh/authorized_keys for the asterisk system user without reliably enforcing backup-only command and source restrictions. The key grants persistent shell access that can execute arbitrary commands, access FreePBX and call data, modify system files, and disrupt services. This issue is fixed in version 17.0.11. Join the discussion | CVE Database V5 | 08/13/2026, 21:30:37 UTC Added: 08/13/2026, 21:56:43 UTC |
CVE-2026-73039: Authorization Bypass Through User-Controlled Key in Fosowl AgenticSeekCVE-2026-73039 0 streama contains an insecure direct object reference vulnerability in ViewingStatusController that allows authenticated users to read and delete other users' viewing status records. Attackers can enumerate all users' watch progress, delete arbitrary viewing history, and manipulate other users' Continue Watching dashboards by supplying arbitrary primary keys without ownership verification. Join the discussion | CVE Database V5 | 08/13/2026, 21:34:04 UTC Added: 08/13/2026, 21:56:43 UTC |
CVE-2026-19751: Server-Side Request Forgery in EnzoVezzaro mcp-dominican-layerCVE-2026-19751 0 A flaw has been found in EnzoVezzaro mcp-dominican-layer up to 39dd373786712650097ad31db27d5c477c8f9c82. The affected element is the function axios.get of the file src/index.ts of the component parse-csv tool. This manipulation of the argument csvUrl causes server-side request forgery. The attack is possible to be carried out remotely. The exploit has been published and may be used. This product adopts a rolling release strategy to maintain continuous delivery. Therefore, version details for affected or updated releases cannot be specified. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 08/13/2026, 21:45:08 UTC Added: 08/13/2026, 21:56:43 UTC |
CVE-2026-73663: CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in FreePBX missedcallCVE-2026-73663 0 FreePBX missedcall module versions from 16.0.0 up to but not including 16.0.11 and 17.0.0 up to but not including 17.0.4 contain an SQL injection vulnerability. This flaw allows unauthenticated attackers to inject SQL commands via crafted SIP From headers, potentially corrupting the database and modifying administrator accounts to gain unauthorized remote access. The vulnerability is fixed in versions 16.0.11 and 17.0.4. Join the discussion | CVE Database V5 | 08/13/2026, 21:29:14 UTC Added: 08/13/2026, 21:41:43 UTC |
CVE-2026-73662: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in FreePBX musicCVE-2026-73662 0 FreePBX Music on Hold module versions from 17.0.1 up to but not including 17.0.7 contain a vulnerability that allows an authenticated administrator to execute arbitrary OS commands as the asterisk service user. This occurs because dangerous command-line options for audio players like /usr/bin/mpg123 are not properly filtered, enabling command injection. The issue is fixed in version 17.0.7. Join the discussion | CVE Database V5 | 08/13/2026, 21:27:14 UTC Added: 08/13/2026, 21:41:43 UTC |
CVE-2026-73661: CWE-15: External Control of System or Configuration Setting in FreePBX frameworkCVE-2026-73661 0 A vulnerability in the FreePBX Framework module prior to versions 16.0.47 and 17.0.30 allows an authenticated user with backup-restore or write access to backup files to restore a crafted backup that disables authentication by setting AUTHTYPE to none. This bypasses the user interface's protections and can lead to authentication bypass during restoration. The issue is fixed in versions 16.0.47 and 17.0.30. Join the discussion | CVE Database V5 | 08/13/2026, 21:25:26 UTC Added: 08/13/2026, 21:41:43 UTC |
CVE-2026-73660: CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in FreePBX ttsCVE-2026-73660 0 CVE-2026-73660 is a high-severity OS command injection vulnerability in the FreePBX Text-To-Speech (TTS) module. It affects versions prior to 16.0.6 and 17.0.5.4. An authenticated administrator can exploit this flaw by saving a specially crafted TTS destination name that is improperly neutralized, leading to arbitrary command execution as the asterisk service user. This vulnerability is fixed in FreePBX versions 16.0.6 and 17.0.5.4. Join the discussion | CVE Database V5 | 08/13/2026, 21:23:01 UTC Added: 08/13/2026, 21:41:43 UTC |
CVE-2026-73659: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in triggerdotdev trigger.devCVE-2026-73659 0 Trigger.dev versions from 4.4.2 up to but not including 4.5.0 contain a path traversal vulnerability in the packet presign routes. This flaw allows a caller-controlled filename to escape the intended restricted directory, enabling unauthorized read or overwrite access to other organizations' offloaded task payloads and outputs in multi-organization self-hosted instances. The vulnerability is fixed in version 4.5.0. Join the discussion | CVE Database V5 | 08/13/2026, 21:19:48 UTC Added: 08/13/2026, 21:41:43 UTC |
CVE-2026-73658: CWE-20: Improper Input Validation in triggerdotdev trigger.devCVE-2026-73658 0 CVE-2026-73658 is a high-severity vulnerability in trigger.dev, a platform for building and deploying AI agents and workflows. Versions from 4.4.2 up to but not including 4.5.0-rc.5 contain improper input validation in the Aws4FetchClient component, allowing user-controlled packet keys to be assigned to URL pathnames without proper normalization and ownership checks. This flaw enables an attacker with a valid environment API key to obtain presigned URLs for other tenants' object-store keys, potentially reading or overwriting task payloads. The issue is fixed starting from version 4.5.0-rc.5. The vulnerability has a CVSS score of 8.2, indicating high impact on confidentiality and integrity but no impact on availability. Join the discussion | CVE Database V5 | 08/13/2026, 21:16:59 UTC Added: 08/13/2026, 21:41:43 UTC |
Showing 1 to 10 of 23928 results