Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "app.py"
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-36576: n/aCVE-2026-36576 0 CVE-2026-36576 is a critical OS command injection vulnerability in the app.py component of the openlabs docker-wkhtmltopdf-aas project up to commit 9f50579. It allows unauthenticated attackers to execute arbitrary operating system commands via a crafted POST request. The vulnerability has a CVSS score of 9.8, indicating high impact on confidentiality, integrity, and availability. No patch or official remediation information is currently available. There are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 06/03/2026, 00:00:00 UTC Added: 06/03/2026, 15:48:54 UTC |
CVE-2026-10295: Denial of Service in SourceCodester Customer Review AppCVE-2026-10295 0 A vulnerability was found in SourceCodester Customer Review App 1.0. Affected by this vulnerability is the function add_review/save_review/get_all_reviews of the file review_app.py. Performing a manipulation of the argument name/comment results in denial of service. The attack requires a local approach. The exploit has been made public and could be used. Join the discussion | CVE Database V5 | 06/01/2026, 21:45:15 UTC Added: 06/01/2026, 22:33:40 UTC |
CVE-2026-6635: Improper Authentication in rowboatlabs rowboatCVE-2026-6635 0 A security vulnerability has been detected in rowboatlabs rowboat up to 0.1.67. This impacts the function tool_call of the file apps/experimental/tools_webhook/app.py of the component tools_webhook. Such manipulation of the argument X-Tools-JWE leads to improper authentication. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 04/20/2026, 11:45:12 UTC Added: 04/20/2026, 14:01:11 UTC |
CVE-2026-5630: Cross Site Scripting in assafelovic gpt-researcherCVE-2026-5630 0 CVE-2026-5630 is a cross-site scripting (XSS) vulnerability in the assafelovic gpt-researcher product up to version 3.4.3. The flaw exists in an unknown function within the Report API component located in backend/server/app.py. This vulnerability can be exploited remotely and requires user interaction. Although the issue was reported early to the project, no response or fix has been provided yet. The CVSS 4.0 base score is 5.3, indicating a medium severity level. Join the discussion | CVE Database V5 | 04/06/2026, 06:15:12 UTC Added: 04/06/2026, 07:00:30 UTC |
CVE-2026-5577: SQL Injection in Song-Li cross_browserCVE-2026-5577 0 CVE-2026-5577 is a SQL injection vulnerability in the Song-Li cross_browser product affecting the details endpoint in the flask/uniquemachine_app.py file. The vulnerability allows remote attackers to manipulate the ID argument to execute SQL injection attacks. The product uses a rolling release model, so specific affected or fixed versions are not clearly identified. The vendor was contacted but did not respond, and no patch or official remediation is currently available. The vulnerability has a medium severity rating with a CVSS score of 6.9. Public disclosure of the exploit exists, but there are no known exploits in the wild at this time. Join the discussion | CVE Database V5 | 04/05/2026, 15:30:14 UTC Added: 04/05/2026, 15:45:30 UTC |
CVE-2026-33057: CWE-94: Improper Control of Generation of Code ('Code Injection') in mesop-dev mesopCVE-2026-33057 0 Mesop is a Python-based UI framework that allows users to build web applications. In versions 1.2.2 and below, an explicit web endpoint inside the ai/ testing module infrastructure directly ingests untrusted Python code strings unconditionally without authentication measures, yielding standard Unrestricted Remote Code Execution. Any individual capable of routing HTTP logic to this server block will gain explicit host-machine command rights. The AI codebase package includes a lightweight debugging Flask server inside ai/sandbox/wsgi_app.py. The /exec-py route accepts base_64 encoded raw string payloads inside the code parameter natively evaluated by a basic POST web request. It saves it rapidly to the operating system logic path and injects it recursively using execute_module(module_path...). This issue has been fixed in version 1.2.3. Join the discussion | CVE Database V5 | 03/20/2026, 07:16:59 UTC Added: 03/20/2026, 07:39:36 UTC |
CVE-2026-27897: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in WanderingAstronomer VociferousCVE-2026-27897 0 Vociferous provides cross-platform, offline speech-to-text with local AI refinement. Prior to 4.4.2, the vulnerability exists in src/api/system.py within the export_file route. The application accepts a JSON payload containing a filename and content. While the developer intended for a native UI dialog to handle the file path, the API does not validate the filename string before it is processed by the backends filesystem logic. Because the API is unauthenticated and the CORS configuration in app.py is overly permissive (allow_origins=["*"] or allowing localhost), an external attacker can bypass the UI entirely. By using directory traversal sequences (../), an attacker can force the app to write arbitrary data to any location accessible by the current user's permissions. This vulnerability is fixed in 4.4.2. Join the discussion | CVE Database V5 | 03/11/2026, 15:30:19 UTC Added: 03/11/2026, 15:59:57 UTC |
CVE-2024-34527: n/aCVE-2024-34527 0 spaces_plugin/app.py in SolidUI 0.4.0 has an unnecessary print statement for an OpenAI key. The printed string might be logged. Join the discussion | CVE Database V5 | 05/05/2024, 00:00:00 UTC Added: 02/25/2026, 21:40:35 UTC |
CVE-2026-2975: Information Disclosure in FastApiAdminCVE-2026-2975 0 A security flaw has been discovered in FastApiAdmin up to 2.2.0. Affected by this vulnerability is the function reset_api_docs of the file /backend/app/plugin/init_app.py of the component Custom Documentation Endpoint. The manipulation results in information disclosure. The attack may be performed from remote. The exploit has been released to the public and may be used for attacks. Join the discussion | CVE Database V5 | 02/23/2026, 06:02:07 UTC Added: 02/23/2026, 06:32:13 UTC |
CVE-2026-25527: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in dgtlmoon changedetection.ioCVE-2026-25527 0 changedetection.io is a free open source web page change detection tool. In versions prior to 0.53.2, the `/static/<group>/<filename>` route accepts `group=".."`, which causes `send_from_directory("static/..", filename)` to execute. This moves the base directory up to `/app/changedetectionio`, enabling unauthenticated local file read of application source files (e.g., `flask_app.py`). Version 0.53.2 fixes the issue. Join the discussion | CVE Database V5 | 02/19/2026, 14:18:18 UTC Added: 02/19/2026, 14:47:24 UTC |
Showing 1 to 10 of 12 results