Threat Intelligence Database
Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Search Results: "auth.py"
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-10175: Code Injection in Aider-AI AiderCVE-2026-10175 0 A security flaw has been discovered in Aider-AI Aider 0.86.3. Affected by this vulnerability is the function editor_coder.run of the file auth.py of the component Architect Mode. Performing a manipulation results in code injection. Remote exploitation of the attack is possible. The exploit has been released to the public and may be used for attacks. The project was informed of the problem early through an issue report but has not responded yet. Join the discussion | CVE Database V5 | 05/31/2026, 08:45:07 UTC Added: 05/31/2026, 09:03:34 UTC |
CVE-2026-41588: CWE-208: Observable Timing Discrepancy in inducer relateCVE-2026-41588 0 RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16. Join the discussion | CVE Database V5 | 05/08/2026, 14:51:04 UTC Added: 05/08/2026, 15:21:57 UTC |
CVE-2026-41505: CWE-338: Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) in inducer relateCVE-2026-41505 0 RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() function. This issue has been patched via commit 2f68e16. Join the discussion | CVE Database V5 | 05/07/2026, 13:35:02 UTC Added: 05/07/2026, 14:36:46 UTC |
CVE-2026-7713: Improper Authorization in crocodilestick Calibre-Web-AutomatedCVE-2026-7713 0 A vulnerability was detected in crocodilestick Calibre-Web-Automated up to 4.0.6. Affected by this vulnerability is the function generate_auth_token of the file cps/kobo_auth.py of the component Kobo auth-token Route. The manipulation results in improper authorization. The attack may be performed from remote. The exploit is now public and may be used. Upgrading to version 4.0.7 addresses this issue. The patch is identified as 9f50bb2c16160564c9f8777dc2ceed3eb95e4807. The affected component should be upgraded. Join the discussion | CVE Database V5 | 05/04/2026, 00:00:32 UTC Added: 05/04/2026, 00:22:19 UTC |
CVE-2026-7709: Improper Authorization in janeczku Calibre-WebCVE-2026-7709 0 CVE-2026-7709 is a medium severity vulnerability in janeczku Calibre-Web up to version 0.6.26. It involves improper authorization due to manipulation of the user_id argument in the generate_auth_token function within cps/kobo_auth.py. The vulnerability can be exploited remotely without user interaction. Although an exploit is publicly available, there is no vendor response or official patch as of the publication date. Join the discussion | CVE Database V5 | 05/03/2026, 23:00:16 UTC Added: 05/03/2026, 23:21:55 UTC |
CVE-2026-7579: Hard-coded Credentials in AstrBotDevs AstrBotCVE-2026-7579 0 A security vulnerability has been detected in AstrBotDevs AstrBot up to 4.16.0. This issue affects some unknown processing of the file astrbot/dashboard/routes/auth.py of the component Dashboard. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way. Join the discussion | CVE Database V5 | 05/01/2026, 11:30:15 UTC Added: 05/01/2026, 11:51:29 UTC |
CVE-2025-15598: Improper Verification of Cryptographic Signature in Dataease SQLBotCVE-2025-15598 0 A vulnerability was found in Dataease SQLBot up to 1.5.1. This impacts the function validateEmbedded of the file backend/apps/system/middleware/auth.py of the component JWT Token Handler. Performing a manipulation results in improper verification of cryptographic signature. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is said to be difficult. The exploit has been made public and could be used. A comment in the source code warns users about using this feature. The vendor was contacted early about this disclosure. Join the discussion | CVE Database V5 | 03/03/2026, 09:32:06 UTC Added: 03/03/2026, 09:48:36 UTC |
CVE-2026-2215: Use of Default Cryptographic Key in rachelos WeRSS we-mp-rssCVE-2026-2215 0 A vulnerability was detected in rachelos WeRSS we-mp-rss up to 1.4.8. This issue affects some unknown processing of the file core/auth.py of the component JWT Handler. Performing a manipulation of the argument SECRET_KEY results in use of default cryptographic key. The attack can be initiated remotely. The attack is considered to have high complexity. The exploitability is assessed as difficult. The exploit is now public and may be used. Join the discussion | CVE Database V5 | 02/09/2026, 04:32:06 UTC Added: 02/09/2026, 05:16:50 UTC |
Showing 1 to 8 of 8 results