Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-75045 — JetBrains YouTrack Unauthenticated Backup Disclosure Vulnerability

In JetBrains YouTrack before 2025.3.156085, 2026.1.13913, 2026.2.18112 an unauthenticated attacker could download database backups via shared draft signature

youtrack | Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
8.1 HIGH
CVE-2026-75044 — JetBrains YouTrack Improper Authorization Vulnerability

In JetBrains YouTrack before 2025.3.156085, 2026.1.13914, 2026.2.18095 missing authorisation allowed an authenticated user to delete arbitrary entities via the mailbox endpoint

youtrack | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.5 MEDIUM
CVE-2026-74858 — jae-jae fetcher-mcp URL Validation security-credentials fetch_urls server-side request fo…

A vulnerability has been found in jae-jae fetcher-mcp up to 0.3.9. Impacted is the function fetch_url/fetch_urls of the file /latest/meta-data/iam/security-credentials/ of the component URL Validatio…

Remote | Server-Side Request Forgery
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-73646 — PostCSS: Path Traversal in Previous Source Map Auto-Loading (sourceMappingURL) leads to A…

PostCSS takes a CSS file and provides an API to analyze and modify its rules by transforming the rules into an Abstract Syntax Tree. Prior to 8.5.18, lib/previous-map.js loadMap() passes attacker-con…

Remote | Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-71479 — New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_com…

new-api | Remote | Misconfiguration
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.9 MEDIUM
CVE-2026-68762 — JetBrains Ktor WebSocket Decompression Denial of Service

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

ktor | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-64868 — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body re…

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/w…

new-api | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.1 MEDIUM
CVE-2026-64866 — New API: Admin can reset passkeys for same-level or higher-privileged users

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageT…

new-api | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.0 MEDIUM
CVE-2026-64865 — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_mod…

new-api | Remote | Race Condition
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-64859 — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, retur…

new-api | Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-59829 — Discourse: Review queue exposes flag-related private message excerpts to category group m…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and p…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-55704 — Discourse: Shared-draft titles and excerpts leak through group post serialization

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, co…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.3 CRITICAL
CVE-2026-55674 — Discourse: Cache poisoning/XSS via color scheme cookies

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_s…

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-53960 — Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.3 HIGH
CVE-2026-40144 — Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input proces…

| Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27772 — Uptrain vulnerable to remote code execution via `/new_run` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27771 — Uptrain vulnerable to remote code execution via `/add_prompts` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27770 — UpTrain vulnerable to Remote code execution at `/create_project`

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `check…

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.7 HIGH
CVE-2025-27621 — UpTrain has a Constant Default API Key

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the use…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
0.0 NA
CVE-2026-61666 — websocket-driver: Denial of service via malformed Host header

websocket-driver is a WebSocket protocol handler with pluggable I/O. Prior to 0.8.2, WebSocket::Driver.server() passes a malformed Host header to URI.parse in lib/websocket/http/request.rb without ca…

| Misconfiguration
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11191 Results