Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 Qwik is a performance-focused JavaScript framework. Versions prior to 1.19.2 improperly inferred arrays from dotted form field names during FormData parsing. By submitting mixed array-index and object-property keys for the same path, an attacker could cause user-controlled properties to be written onto values that application code expected to be arrays. When processing application/x-www-form-urlencoded or multipart/form-data requests, Qwik City converted dotted field names (e.g., items.0, items.1) into nested structures. If a path was interpreted as an array, additional attacker-supplied keys on that path—such as items.toString, items.push, items.valueOf, or items.length—could alter the resulting server-side value in unexpected ways, potentially leading to request handling failures, denial of service through malformed array state or oversized lengths, and type confusion in downstream code. This issue was fixed in version 1.19.2. Join the discussion | CVE Database V5 | 03/20/2026, 08:52:41 UTC Added: 03/20/2026, 09:09:22 UTC |
Qwik is a performance focused javascript framework.qwik <=1.19.0 is vulnerable to RCE due to an unsafe deserialization vulnerability in the server$ RPC mechanism that allows any unauthenticated user to execute arbitrary code on the server with a single HTTP request. Affects any deployment where require() is available at runtime. This vulnerability is fixed in 1.19.1. Join the discussion | CVE Database V5 | 03/03/2026, 22:55:38 UTC Added: 03/04/2026, 02:04:50 UTC |
0 CVE-2026-25150 is a critical prototype pollution vulnerability in the QwikDev qwik JavaScript framework versions prior to 1.19.0. The flaw exists in the formToObj() function of the @builder.io/qwik-city middleware, which improperly processes form field names containing dot notation without sanitizing dangerous property names like __proto__, constructor, and prototype. This allows unauthenticated attackers to send crafted HTTP POST requests that modify Object.prototype, potentially leading to privilege escalation, authentication bypass, or denial of service. The vulnerability has a CVSS score of 9.3, indicating critical severity, and affects all deployments using vulnerable qwik versions. Although no known exploits are currently in the wild, the ease of exploitation and impact on integrity make this a high-risk issue. Join the discussion | CVE Database V5 | 02/03/2026, 21:12:50 UTC Added: 02/03/2026, 21:30:11 UTC |
0 CVE-2026-25148 is a medium severity Cross-Site Scripting (XSS) vulnerability in Qwik, a JavaScript framework focused on performance. Versions prior to 1.19.0 are affected due to improper neutralization of input during server-side rendering of virtual attributes, allowing remote attackers to inject malicious scripts. Exploitation requires no authentication but does require user interaction to trigger script execution in the victim's browser within the affected origin context. This vulnerability can lead to theft of sensitive information, session hijacking, or other malicious actions performed on behalf of the user. The issue has been patched in Qwik version 1.19.0. European organizations using affected Qwik versions in web applications are at risk, especially those with public-facing services. Join the discussion | CVE Database V5 | 02/03/2026, 21:12:38 UTC Added: 02/03/2026, 21:30:11 UTC |
CVE-2026-25151 is a Cross-Site Request Forgery (CSRF) vulnerability in QwikDev's Qwik JavaScript framework versions prior to 1.19.0. The issue arises from inconsistent interpretation of HTTP request headers, specifically Content-Type headers, by Qwik City's server-side request handler. This flaw allows remote attackers to bypass CSRF protections by crafting or using multi-valued Content-Type headers, potentially leading to unauthorized actions with elevated integrity impact. The vulnerability has a CVSS score of 5.9 (medium severity) and requires user interaction but no authentication. It affects web applications built on vulnerable Qwik versions and has no known exploits in the wild yet. The issue was patched in version 1.19. Join the discussion | CVE Database V5 | 02/03/2026, 21:12:25 UTC Added: 02/03/2026, 21:30:11 UTC |
CVE-2026-25155 is a medium severity Cross-Site Request Forgery (CSRF) vulnerability in the Qwik JavaScript framework versions prior to 1.12.0. The flaw stems from a typo in the regular expression used by the isContentType function, causing improper parsing of certain Content-Type headers. This parsing error can be exploited by attackers to craft malicious requests that bypass normal CSRF protections, potentially leading to unauthorized actions with high integrity impact but low confidentiality and no availability impact. The vulnerability requires user interaction and remote network access but no authentication. Although no known exploits are reported in the wild, organizations using vulnerable Qwik versions should upgrade to 1.12.0 or later. European organizations that heavily rely on Qwik for web applications, especially in countries with significant software development ecosystems, are at risk. Join the discussion | CVE Database V5 | 02/03/2026, 21:12:13 UTC Added: 02/03/2026, 21:30:11 UTC |
0 CVE-2026-25149 is an Open Redirect vulnerability in QwikDev's Qwik JavaScript framework versions prior to 1.19.0. The flaw exists in Qwik City's default request handler middleware, allowing attackers to redirect users to arbitrary protocol-relative URLs. Exploiting this vulnerability enables attackers to craft phishing links that appear to originate from trusted domains but redirect victims to malicious sites. The vulnerability has a low CVSS score of 2.7 and does not require user interaction or authentication. Although no known exploits are currently in the wild, unpatched systems remain at risk. The issue was patched in version 1.19. Join the discussion | CVE Database V5 | 02/03/2026, 21:11:55 UTC Added: 02/03/2026, 21:30:11 UTC |
0 @builder.io/qwik-city is the meta-framework for Qwik. When a Qwik Server Action QRL is executed it dynamically load the file containing the symbol. When an invalid qfunc is sent, the server does not handle the thrown error. The error then causes Node JS to exit. This vulnerability is fixed in 1.13.0. Join the discussion | CVE Database V5 | 07/09/2025, 18:45:28 UTC Added: 07/09/2025, 18:54:41 UTC |
Showing 1 to 8 of 8 results