Skip to content
Product
Use it
Threat intelligence API
Free key, 70+ endpoints, OpenAPI. The product.
Get started
Pick your stack, make your first call.
Live feed
The console: incidents, filters, entities, search.
Recipes
Runnable examples for the free key.
Free feeds
RSS, ransomware feed, IOC blocklist, MISP — no key.
CLI & agents
tc from a terminal; agent keys with scoped budgets.
The data
Incident records
900 articles a day become ~70 scored incidents.
Dark web
First-party leak-site collection: victims, groups, markets.
Validated IOCs
Indicators with a false-positive gate; STIX, MISP, CSV.
Vulnerabilities
CVEs with EPSS, KEV and exploit status.
Entity graph
Actors, malware, CVEs, companies — pivotable.
For teams
For service providers
Per-client feeds, alerts and branded digests.
Use cases
How teams and builders use the corpus.
About ThreatCluster
What it is and how it is built.
Pricing
Docs
Reference
OpenAPI (Swagger)
Every endpoint, parameter and response model.
ReDoc
The same reference, long-form.
Examples on GitHub
curl, Python and Node quickstarts; daily spec snapshot.
Guides
Quickstart & plans
Key, scopes, budgets, tiers.
Integrations
Splunk, Sentinel, Elastic, agents and terminals, step by step
Export formats
STIX 2.1, MISP, CSV, text.
CLI setup
Install, log in, wire an agent.
No results found
Sign in
Get a free key
No results found
Product
Threat intelligence API
Get started
Live feed
Recipes
Free feeds
CLI & agents
The data
Incident records
Dark web
Validated IOCs
Vulnerabilities
Entity graph
For teams
For service providers
Use cases
About ThreatCluster
Docs
OpenAPI (Swagger)
ReDoc
Examples on GitHub
Quickstart & plans
Integrations
Export formats
CLI setup
Pricing
Contact
Get a free key
Sign in
Back
CWE-79 - Cross-site Scripting (xss)
CWE Weakness
Threat entity extracted from intelligence sources
Sep 25: 4 mentions
Sep 26: 2 mentions
Sep 27: 2 mentions
Sep 28: 12 mentions
Sep 29: 1 mention
Sep 30: 9 mentions
Oct 1: 3 mentions
Sep 25
Sep 28
Oct 1
Entities
›
cwe
›
CWE-79 - Cross-site Scripting (xss)
Frequency
408
occurrences
First Seen
April 16, 2026
Last Seen
October 1, 2026
API
Overview
Recent Events
Profile
Profile
MITRE ATT&CK
1 / 2
Threat Actors
APT28
Fancy Bear
Sofacy
Forest Blizzard
Winter Vivern
Laundry Bear
UNC1151
TA488
Star Blizzard
Void Blizzard
Malware
Vshell
Cobalt Strike
ClickFix
Tools
Nginx
PowerShell
Chrome
Docker
Google Chrome
Nuclei
Burp Suite
CVEs
CVE-2026-42897
CVE-2025-66376
CVE-2026-41723
CVE-2026-41724
CVE-2026-53404
CVE-2026-55955
CVE-2026-55956
CVE-2026-55276
Regions
Ukraine
Russia
Greece
Belarus
Canada
Sectors
Government
Financial
Technology
Healthcare
Manufacturing
Telecommunications
-
REC
Recon
No techniques detected
-
RD
Resource Dev
No techniques detected
3
IA
Initial Access
T1190 - Exploit Public-Facing Application
T1566 - Phishing
T1078 - Valid Accounts
3
EX
Execution
T1059.007 - JavaScript
T1203 - Exploitation for Client Execution
T1053 - Scheduled Task/Job
2
PE
Persistence
T1505.003 - Web Shell
T1574 - Hijack Execution Flow
2
PE
Priv Esc
T1055 - Process Injection
T1068 - Exploitation for Privilege Escalation
1
DE
Defense Evasion
T1027 - Obfuscated Files Or Information
3
CA
Cred Access
T1110 - Brute Force
T1003 - OS Credential Dumping
T1555.003 - Credentials From Web Browsers
-
DI
Discovery
No techniques detected
1
LM
Lateral Mov
T1021 - Remote Services
-
CO
Collection
No techniques detected
1
C2
C2
T1071 - Application Layer Protocol
2
EX
Exfil
T1041 - Exfiltration Over C2 Channel
T1567 - Exfiltration Over Web Service
-
IM
Impact
No techniques detected
19
techniques detected across
9
tactics
Related Clusters (50)
Critical GitLab Vulnerabilities Exploited Within Hours of Disclosure
Sep 11
·
58 sources
81
Russian Hackers Exploit Zimbra Zero-Day for Espionage Campaign
Jul 23
·
47 sources
81
Critical Zero-Day Exploits Target Citrix and Other Major Platforms
2d ago
·
5 sources
80
Critical XSS Vulnerability in SUSE Rancher Exposes Admin Sessions
1d ago
·
1 sources
80
Russian Hackers Exploit Zimbra Zero-Day for Email Theft
Jul 10
·
10 sources
79
Critical CVE-2026-48768 Vulnerability in TypeBot Exposes Users to File Upload Attacks
Jun 18
·
0 sources
79
Critical Stored XSS Vulnerabilities Found in SiYuan Versions Before 3.7.4
Aug 16
·
3 sources
78
CVE-2026-55879: Critical XSS Vulnerability in OpenReplay Leads to Account Takeover
Jul 11
·
1 sources
78
CISA Alerts on Critical Flaws in SimpleHelp, Samsung MagicINFO, and D-Link Devices
Apr 26
·
3 sources
78
Critical SSTI Vulnerability in FOSSBilling Exposes Databases to RCE Attacks
Jun 26
·
2 sources
78
Critical Stored XSS Vulnerability in SiYuan Enables Remote Code Execution
Jun 25
·
2 sources
78
Ghost CMS SQL Injection Exploits 700+ Sites in Ongoing ClickFix Campaign
May 25
·
14 sources
78
China-Linked Hackers Target NGOs with Chrome and Windows Exploits
Sep 15
·
7 sources
78
Chinese Threat Group Exploits Roundcube Vulnerabilities in University Networks
Jul 7
·
8 sources
77
APT28 Exploits Roundcube Vulnerabilities in Targeted Cyber Espionage Campaign
Jul 23
·
0 sources
76
Multiple WordPress Plugins Face Vulnerabilities Requiring Immediate Updates
11h ago
·
0 sources
75
Twitch Chat Messages Exploit OBS Studio via Chromium Vulnerability
5d ago
·
3 sources
75
Critical Vulnerabilities in Umbraco CMS and Linux Kernel Exploited
5d ago
·
4 sources
74
Microsoft's Record Patch Tuesday in June 2026 Addresses 206 Vulnerabilities
Jul 1
·
132 sources
74
July 2026 Security Update: Record CVEs and Critical Vulnerabilities
Jul 14
·
2 sources
74
Microsoft Patches Critical Exchange Server Zero-Day Vulnerability CVE-2026-42897
Jun 11
·
15 sources
74
Multiple CVEs Disclosed on September 8, 2026, Affecting Microsoft Products
Sep 8
·
927 sources
74
SAP Addresses Critical Vulnerabilities in July 2026 Security Updates
Jul 14
·
7 sources
74
Critical SQL Injection and XSS Vulnerabilities in RoundcubeMail Affect Fedora Users
Jun 4
·
2 sources
74
Critical XSS Vulnerability in Chamilo LMS Leads to Admin Account Takeover
Jul 21
·
2 sources
74
Critical XSS and Code Execution Vulnerabilities in Fedora Prometheus Update
Jul 11
·
2 sources
74
Critical Vulnerabilities Found in Apache HTTP Server Affecting Multiple Modules
Jul 8
·
5 sources
74
Critical Vulnerabilities in pgAdmin 4 Expose Databases to Remote Code Execution
Jun 22
·
6 sources
74
Critical XSS and Memory Vulnerabilities in Oracle PHP Releases
Jul 6
·
2 sources
74
High-Severity Stored XSS Vulnerability in HAX CMS (CVE-2026-48527)
May 29
·
1 sources
74
Critical Vulnerabilities and Exploits Targeting Cisco, Canvas, and Microsoft Systems
May 15
·
2 sources
73
Critical XSS Vulnerability in Lukevella Rally Affects Versions Up to 4.7.4
Apr 18
·
0 sources
73
Critical Vulnerabilities in SolarWinds Serv-U Require Immediate Patching
Jul 22
·
3 sources
73
Funnel Builder Plugin Vulnerability Exploited in WooCommerce Attacks
May 15
·
4 sources
73
Critical WordPress XSS2Shell Flaw Enables Admin Takeover and RCE
Aug 11
·
3 sources
73
Critical Apache ActiveMQ Vulnerability Enables Security Header Injection Attacks
Jun 3
·
2 sources
73
Critical XSS Vulnerability in Coturn Affects Fedora 43 and 44
Jun 24
·
2 sources
73
Critical Webmin Vulnerabilities Enable User Impersonation and Root Access
Jun 24
·
2 sources
73
Critical RCE Vulnerability in SiYuan Bazaar Exposes Users to Malicious Packages
Jun 22
·
2 sources
73
Critical Authentication Bypass Vulnerability in Spring Authorization Server
Jul 18
·
1 sources
73
Critical justhtml Sanitization Bypass Vulnerabilities Discovered
Aug 23
·
5 sources
73
Emerging Threats from CVE-2022-26809 and CVE-2023-34362 Exploits
3d ago
·
2 sources
73
Critical GitLab Vulnerabilities Enable XSS and DoS Attacks
May 14
·
3 sources
72
AI Discovers 38 Vulnerabilities in OpenEMR Healthcare Software
Apr 29
·
2 sources
72
TA488 Exploits Outlook Web Access CVE-2026-42897 in New Campaign
Jul 30
·
3 sources
72
Critical Vulnerabilities in React and Next.js Require Immediate Updates
May 8
·
5 sources
72
Denial of Service Vulnerabilities in Nextcloud Affecting Fedora Users
3d ago
·
3 sources
72
Over 100,000 WordPress Sites Vulnerable to Remote Code Execution
Sep 17
·
2 sources
72
Critical CVE-2026-76658 Vulnerability in HPE Fabric Composer
Sep 2
·
2 sources
72
Critical Python Vulnerabilities in openSUSE Affecting Command Injection and Code Execution
May 18
·
2 sources
72
Prev
1 / 10
Next
Related Articles (50)
Kiteworks patches max severity code injection vulnerability
Bleepingcomputer
·
4h ago
SecurityAffairs
securityaffairs.co
·
8h ago
Us Canada Gov
transluce.org
·
11h ago
Wordpress Givewp Plugin 4 16 9 Cross Site Scripting Xss Vulnerability
patchstack.com
·
20h ago
Microsoft starts locking down Entra ID sign
Feeds.4Sysops
·
22h ago
Microsoft to block Entra ID script injection attacks starting October
Bleepingcomputer
·
1d ago
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Securityweek
·
1d ago
Chrome, Firefox Updates Patch Over 100 Vulnerabilities
Securityweek
·
1d ago
CVE 2026 88804
www.tenable.com
·
1d ago
Threat Radar
radar.offseq.com
·
1d ago
GHSA 992f Xh8r Jg2f
github.com
·
1d ago
Warning: Critical Cross-site Scripting (XSS) in Rancher - Kubernetes management platform, Patch I...
Ccb.Belgium.Be
·
1d ago
WEB https://www.sailpoint.com/security-advisories/
www.sailpoint.com
·
1d ago
CVE 2026 87114
access.redhat.com
·
2d ago
Ai Agents
securitylab.github.com
·
2d ago
How we found 24 Android vulnerabilities using our open source AI security agent
Github.Blog
·
2d ago
Rapid7 Vulnerability & Exploit Database
Rapid7
·
2d ago
OpenAI agents used restricted methods to access a UN website
Newsbytesapp
·
2d ago
Openai Unctad
swarmcha.se
·
3d ago
OpenAI agents went the long way round for UN data
Theregister
·
3d ago
CVE-2022
Sploitus
·
3d ago
One Email Closer Edge Unkmasstraction Physics Exploitation
www.proofpoint.com
·
3d ago
CVE-2022
Sploitus
·
3d ago
Fedora 44 Nextcloud 34.0.4 Denial of Service XSS Advisories 2026
Linuxsecurity
·
3d ago
Fedora 45 Nextcloud 34.0.4 Denial of Service and XSS Issues 2026
Linuxsecurity
·
3d ago
OpenAI Halted Model Training After Its Agents Probed Federal Government Websites
Cryptorank
·
4d ago
CVE-2020-9471 : faille élevée umbraco umbraco cms (CVSS 8.8)
Forenshield
·
4d ago
Rapid7 Vulnerability & Exploit Database
Rapid7
·
4d ago
The August 2026 Security Update Review
www.zerodayinitiative.com
·
5d ago
Vulnerable OBS overlay and Chromium flaw enable Twitch chat message code execution
Scworld
·
5d ago
Security Bulletin node/7288641
www.ibm.com
·
6d ago
Malicious Twitch chat messages can trigger code execution on OBS Studio
Cyberinsider
·
6d ago
FuckJsonp-RCE-CVE-2022-26809-SQL-XSS
Sploitus
·
6d ago
CVE-2024
Sploitus
·
Sep 24
OpenAI Agents Probed Websites for Vulnerabilities While Fetching Public Data
Securityweek
·
Sep 24
Hackers now exploit critical Roundcube flaw in code injection attacks
Bleepingcomputer
·
Sep 24
RHSA 2026:71113
access.redhat.com
·
Sep 24
Adobe Patches Critical Flaws in Connect, AEM Forms
Securityweek
·
Sep 23
Synology SA 26 13
www.synology.com
·
Sep 23
Exploit for Cross-site Scripting in Xerox Centreware_Web
Sploitus
·
Sep 23
CVE-2017-20192-formidable
Sploitus
·
Sep 23
Adobe Patch Day 2026-09-22: 10 critical vulnerabilities amid 29 CVEs
Feedly
·
Sep 23
CVE-2026-94426 - Low Vulnerability
Thehackerwire
·
Sep 22
"moderation isn't a security control."
patchstack.com
·
Sep 22
Comment2shell Zero Click Pre Auth Xss To Rce In Wordpress Core
idnsec.com
·
Sep 22
WordPress Comment2Shell Flaw Turns Comments Into RCE
Cyberkendra
·
Sep 22
W Index
en.wikipedia.org
·
Sep 22
WordPress Comment2Shell Flaw Can Turn Anonymous Comment XSS Into RCE via Admin Session
Thehackernews
·
Sep 22
CVE-2020
Sploitus
·
Sep 22
awesome-mobile
Sploitus
·
Sep 21
Prev
1 / 10
Next
Related Entities
APT28
Fancy Bear
Sofacy
Forest Blizzard
Winter Vivern
Laundry Bear
UNC1151
TA488
Star Blizzard
Void Blizzard
APT29
Sql Injection