Skip to main content

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Package: pkg:pypi/erpnext

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-38431: n/aCVE-2026-38431
0

ERPNext versions up to v15.103.1 are affected by a Server-Side Template Injection (SSTI) vulnerability. This flaw allows an attacker with permissions to create or edit email templates to inject malicious template expressions that execute on the server during template rendering. The vulnerability has a critical severity rating with a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No official patch or remediation guidance is currently provided by the vendor. There are no known exploits in the wild at this time.

Join the discussion
CVE-2025-66437: n/aCVE-2025-66437
0

An SSTI (Server-Side Template Injection) vulnerability exists in the get_address_display method of Frappe ERPNext through 15.89.0. This function renders address templates using frappe.render_template() with a context derived from the address_dict parameter, which can be either a dictionary or a string referencing an Address document. Although ERPNext uses a custom Jinja2 SandboxedEnvironment, dangerous functions like frappe.db.sql remain accessible via get_safe_globals(). An authenticated attacker with permission to create or modify an Address Template can inject arbitrary Jinja expressions into the template field. By creating an Address document with a matching country, and then calling the get_address_display API with address_dict="address_name", the system will render the malicious template using attacker-controlled data. This leads to server-side code execution or database information disclosure.

Join the discussion

Showing 1 to 2 of 2 results

Filters:Package: pkg:pypi/erpnext
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses