Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threat Intelligence
Click on any threat for detailed analysis and mitigation recommendations
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.70, AutoGPT's autogpt_platform/backend/backend/api/features/integrations/router.py webhook_ingress_generic route selected get_webhook_manager(provider) from the untrusted provider URL segment without verifying webhook.provider, allowing a request to /compass/webhooks/{webhook_id}/ingress to use CompassWebhookManager's inherited no-op BaseWebhooksManager.verify_signature instead of GenericWebhooksManager.verify_signature, bypass X-Webhook-Secret for a configured secret_token, and execute a generic webhook graph as its owner. This issue is fixed in version 0.6.70. Join the discussion | CVE Database V5 | 08/11/2026, 14:32:11 UTC Added: 08/11/2026, 14:57:23 UTC |
0 AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.52, an authenticated user can bypass the SSRF / private-IP protections in SendWebRequestBlock and reach internal network services. _is_ip_blocked() in backend/backend/util/request.py does not normalize IPv4-mapped IPv6 addresses before checking resolved IPs against the blocked IPv4 ranges, and does not block special-use ranges such as 100.64.0.0/10 (CGNAT, RFC 6598). A hostname that resolves to an IPv4-mapped IPv6 address therefore passes validation and the request reaches the embedded internal IPv4 endpoint. This affects all AutoGPT Platform deployments. This vulnerability is fixed in 0.6.52. Join the discussion | CVE Database V5 | 06/26/2026, 16:04:54 UTC Added: 06/26/2026, 16:52:23 UTC |
0 CVE-2026-33234 is a Server-Side Request Forgery (SSRF) vulnerability in Significant-Gravitas AutoGPT versions 0.1.0 through 0.6.51. The vulnerability arises because the SendEmailBlock accepts user-supplied SMTP server and port inputs and passes them directly to Python's smtplib. SMTP() without IP address validation. This bypasses the platform's usual SSRF protections, allowing an authenticated user on a shared deployment to perform internal network port scanning and service fingerprinting. The issue was fixed in version 0.6. Join the discussion | CVE Database V5 | 05/19/2026, 00:51:41 UTC Added: 05/19/2026, 01:21:39 UTC |
Showing 1 to 3 of 3 results