Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
0 deeptutor version 1.4.0 contains a code injection vulnerability in the ExecTool.execute function. This flaw allows a remote attacker to execute arbitrary shell commands on the service environment via the live tutorbot WebSocket interface. No patch or remediation information is currently available. Join the discussion | CVE Database V5 | 10/01/2026, 00:00:00 UTC Added: 10/02/2026, 14:55:32 UTC |
0 deeptutor version 1.4.0 has a path traversal vulnerability in the EditFileTool.execute function. This flaw allows a remote attacker, via the live tutorbot WebSocket interface, to write or modify files at arbitrary absolute paths outside the intended bot workspace. Join the discussion | CVE Database V5 | 10/01/2026, 00:00:00 UTC Added: 10/02/2026, 14:55:32 UTC |
0 deeptutor version 1.4.0 has an authorization bypass vulnerability in the TutorBotManager.write_bot_file function. This flaw allows a remote attacker to enumerate bot IDs and overwrite whitelisted control files of other bots via the HTTP tutorbot file route. Join the discussion | CVE Database V5 | 10/01/2026, 00:00:00 UTC Added: 10/02/2026, 14:55:32 UTC |
0 deeptutor version 1.4.0 has an authorization bypass vulnerability in the TurnRuntimeManager.regenerate_last_turn function. This flaw allows a remote attacker to use a user-controlled object identifier to enumerate or obtain another user's session_id and trigger regeneration on that session. No CVSS score is available for this vulnerability. Join the discussion | CVE Database V5 | 10/01/2026, 00:00:00 UTC Added: 10/02/2026, 14:55:32 UTC |
0 DeepTutor 1.4.0 contains an authorization bypass vulnerability in the book confirmation flow. An unauthenticated or unauthorized caller can reuse a publicly exposed book_id to submit a confirm-proposal request for an existing book, causing unauthorized overwrites of persisted metadata and spine content. Join the discussion | CVE Database V5 | 10/01/2026, 00:00:00 UTC Added: 10/01/2026, 21:46:49 UTC |
0 DeepTutor before version 1.4.10 contains an authorization bypass vulnerability that allows low-privilege users to invoke unrestricted MCP tools due to the allowed_mcp_tools function returning None instead of a denied result when mcp_tools is omitted from a user's grant in deeptutor/multi_user/tool_access.py. Attackers or prompt-injected content acting within a user session can enumerate and invoke any configured MCP tool, including filesystem, shell, and browser servers, gaining unauthorized access to sensitive deployment resources. Join the discussion | CVE Database V5 | 06/30/2026, 18:31:38 UTC Added: 06/30/2026, 16:51:59 UTC |
Showing 1 to 6 of 6 results