Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-75044 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

youtrack | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-74858 — jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request fo…

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validatio…

Remote | Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-73646 — PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to A…

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-con…

Remote | Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-71479 — New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_com…

new-api | Remote | Misconfiguration
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.9 MEDIUM
CVE-2026-68762 — JetBrains Ktor WebSocket Decompression Denial of Service

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

ktor | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-64868 — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body re…

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/w…

new-api | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.1 MEDIUM
CVE-2026-64866 — New API: Admin can reset passkeys for same-level or higher-privileged users

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageT…

new-api | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.0 MEDIUM
CVE-2026-64865 — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_mod…

new-api | Remote | Race Condition
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-64859 — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, retur…

new-api | Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-59829 — Discourse: Review queue exposes flag-related private message excerpts to category group m…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and p…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-55704 — Discourse: Shared-draft titles and excerpts leak through group post serialization

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, co…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.3 CRITICAL
CVE-2026-55674 — Discourse: Cache poisoning/XSS via color scheme cookies

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_s…

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-53960 — Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.3 HIGH
CVE-2026-40144 — Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input proces…

| Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27772 — Uptrain vulnerable to remote code execution via `/new_run` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27771 — Uptrain vulnerable to remote code execution via `/add_prompts` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27770 — UpTrain vulnerable to Remote code execution at `/create_project`

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `check…

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.7 HIGH
CVE-2025-27621 — UpTrain has a Constant Default API Key

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the use…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.1 MEDIUM
CVE-2026-73851 — Kiota: Path traversal in generated plugin manifest static_template.file reference (percen…

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that r…

kiota | Remote | Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.7 HIGH
CVE-2026-71567 — User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly appl…

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11263 Results