Threats Tagged 'cve'
View all threats tagged with 'cve'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cve'
Click on any threat for detailed analysis and mitigation recommendations
0 CVE-2026-18179 is a medium severity vulnerability in IBM Financial Transaction Manager (FTM) for RedHat OpenShift versions 4.0.6.0 through 4.0.10.0. It involves missing authorization controls that could allow a remote attacker to clear active chat sessions without proper permissions. Join the discussion | CVE Database V5 | 09/23/2026, 13:53:27 UTC Added: 09/23/2026, 14:03:14 UTC |
0 CVE-2026-59167 is a critical stored cross-site scripting (XSS) vulnerability in JiHong88 suneditor, a lightweight JavaScript WYSIWYG editor. Versions prior to 2.47.11 have a sanitizer flaw in src/lib/core.js that fails to consistently reject namespaced or custom HTML elements, allowing event-handler attributes to persist on crafted elements. This enables attackers to execute arbitrary scripts in the browser context when users interact with malicious editor content. The issue is resolved in version 2.47.11. Join the discussion | CVE Database V5 | 09/23/2026, 13:52:56 UTC Added: 09/23/2026, 14:03:14 UTC |
0 IBM Financial Transaction Manager (FTM) for RedHat OpenShift contains a missing authorization vulnerability that could allow a remote attacker to perform unauthorized payment actions. This flaw affects versions from 4.0.6.0 through 4.0.10.0. The vulnerability has a high severity rating with a CVSS score of 7.1. No known exploits are reported in the wild, and no patch information is currently provided. Join the discussion | CVE Database V5 | 09/23/2026, 13:52:26 UTC Added: 09/23/2026, 14:03:14 UTC |
0 CVE-2026-86678 is a high-severity authorization bypass vulnerability in ZohoCorp ManageEngine Applications Manager. Versions 182000 and below allow a low-privileged user to obtain an administrator's API key and perform administrator-level actions. This flaw is categorized under CWE-639, indicating improper authorization. The vulnerability has a CVSS 3.1 score of 8.8, reflecting high impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/23/2026, 13:41:27 UTC Added: 09/23/2026, 13:48:17 UTC |
CVE-2026-86677 is a high-severity SQL injection vulnerability in ZohoCorp ManageEngine Applications Manager versions prior to 182100. It allows a low-privileged user to execute unauthorized SQL commands, potentially leading to administrator access and remote code execution. Join the discussion | CVE Database V5 | 09/23/2026, 13:36:03 UTC Added: 09/23/2026, 13:48:17 UTC |
0 ZohoCorp ManageEngine Applications Manager versions prior to 182300 contain a permissions validation vulnerability that allows low-privileged users to execute administrator-configured MBean actions on monitors outside their assigned scope. This issue is due to missing authentication for a critical function, classified as CWE-306. The vulnerability has a CVSS 3.1 score of 7.6, indicating high severity with low attack complexity and no user interaction required. Join the discussion | CVE Database V5 | 09/23/2026, 13:17:16 UTC Added: 09/23/2026, 13:33:29 UTC |
0 ZohoCorp ManageEngine Applications Manager versions 182200 and below contain a hard-coded Google Cloud service-account private key in the installer. This vulnerability allows unauthenticated attackers to impersonate the service account and access or modify associated cloud resources. The issue is tracked as CVE-2026-86708 and has a critical severity with a CVSS score of 10. A patch is available to remediate this vulnerability. Join the discussion | CVE Database V5 | 09/23/2026, 13:11:31 UTC Added: 09/23/2026, 13:33:29 UTC |
CVE-2026-95676 is a high-severity vulnerability in WatchGuard AuthPoint Authentication Gateway versions 4.2.2 up to but not including 7.5.1. It involves a missing or improper authentication check in the LDAP Sync first-factor authentication process, allowing a remote attacker to bypass single-factor password verification under non-default operating conditions. Multi-factor authentication remains effective, so additional factors still protect the system. Join the discussion | CVE Database V5 | 09/23/2026, 12:52:04 UTC Added: 09/23/2026, 13:03:17 UTC |
ManageEngine OpManager MSP versions 12.8.709 and earlier contain a critical remote code execution vulnerability in the Notification Profile module. This vulnerability is due to improper neutralization of special elements used in OS commands (CWE-78), allowing an attacker with limited privileges to execute arbitrary commands remotely. The vulnerability has a high CVSS score of 9.9, indicating severe impact on confidentiality, integrity, and availability. Join the discussion | CVE Database V5 | 09/23/2026, 12:41:25 UTC Added: 09/23/2026, 12:48:27 UTC |
0 ManageEngine OpManager versions 12.8.710 and earlier with the Application Manager Plugin enabled are affected by an authentication bypass vulnerability. This flaw allows unauthorized users with limited privileges to access critical functions without proper authentication. The vulnerability is identified as CWE-306 (Missing Authentication for Critical Function). Join the discussion | CVE Database V5 | 09/23/2026, 12:35:00 UTC Added: 09/23/2026, 12:48:27 UTC |
Showing 1 to 10 of 98327 results