Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-71479 — New API: Integer overflow in quota billing yields negative charges (self-crediting)

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_com…

new-api | Remote | Misconfiguration
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.9 MEDIUM
CVE-2026-68762 — JetBrains Ktor WebSocket Decompression Denial of Service

In JetBrains Ktor before 3.4.1 potential DoS attack via WebSocket decompression was possible

ktor | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.5 HIGH
CVE-2026-64868 — New API: Unauthenticated payment webhooks allow memory and disk DoS via unbounded body re…

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/w…

new-api | Remote | Denial of Service
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.1 MEDIUM
CVE-2026-64866 — New API: Admin can reset passkeys for same-level or higher-privileged users

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageT…

new-api | Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.0 MEDIUM
CVE-2026-64865 — New API: Redis user quota cache overwrite via PUT /api/user/self allows quota bypass

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_mod…

new-api | Remote | Race Condition
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.1 CRITICAL
CVE-2026-64859 — New API: User List API Leaks Root User Access Token Leading to Privilege Escalation

New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, retur…

new-api | Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-59829 — Discourse: Review queue exposes flag-related private message excerpts to category group m…

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.1, on sites with category group moderation enabled, the review queue could include an excerpt (and p…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-55704 — Discourse: Shared-draft titles and excerpts leak through group post serialization

Discourse is an open-source discussion platform. Prior o 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, users who were allowed to view a group’s activity, but were not permitted to see shared drafts, co…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.3 CRITICAL
CVE-2026-55674 — Discourse: Cache poisoning/XSS via color scheme cookies

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, an unauthenticated attacker could send a single request with a crafted color_scheme_id (or dark_s…

Remote | Cross-Site Scripting
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
5.3 MEDIUM
CVE-2026-53960 — Discourse: Hidden first-post excerpt is emitted in Q&A schema JSON-LD

Discourse is an open-source discussion platform. Prior to 2026.1.6, 2026.5.2, 2026.6.1, and 2026.7.0, hidden or otherwise unviewable first-post content was leaked as an excerpt in the publicly-served…

Remote | Information Disclosure
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.3 HIGH
CVE-2026-40144 — Memory corruption vulnerability in Endpoint Privilege Management (Windows deployments)

A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input proces…

| Memory Corruption
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27772 — Uptrain vulnerable to remote code execution via `/new_run` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/new_run` endpoint is vulnerable to remote code execution via the `checks` and …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27771 — Uptrain vulnerable to remote code execution via `/add_prompts` endpoint

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/add_prompts` endpoint is vulnerable to remote code execution via the `checks` …

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.4 HIGH
CVE-2025-27770 — UpTrain vulnerable to Remote code execution at `/create_project`

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the `/create_project` endpoint is vulnerable to remote code execution via the `check…

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.7 HIGH
CVE-2025-27621 — UpTrain has a Constant Default API Key

UpTrain is an open-source platform to evaluate and improve generative AI applications. In version 0.7.1 and prior, the UpTrain backend creates a new default user with a static username, where the use…

Remote | Authentication
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.1 MEDIUM
CVE-2026-73851 — Kiota: Path traversal in generated plugin manifest static_template.file reference (percen…

Kiota is an OpenAPI based HTTP Client code generator. Prior to 1.29.1 and 1.34.0, an attacker who controls or tampers with the OpenAPI description consumed by Kiota can supply a file reference that r…

kiota | Remote | Path Traversal
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
7.7 HIGH
CVE-2026-71567 — User-controlled variables inserted unescaped into shell scripts and Kubernetes manifests

In openshift-metal3/fakefish there is a repeated pattern in some of the scripts where shell variables are injected without quoting them either into command lines or into manifests. This mostly appl…

Remote | Injection
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
9.3 CRITICAL
CVE-2026-71566 — KubeVirt backend is not authenticated

FakeFish handles incoming credentials by passing them down to scripts. This works for real hardware because in the end it's up to the BMC to validate them. However, KubeVirt relies on a KUBECONFIG …

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
4.3 MEDIUM
CVE-2026-16049 — _GitLab Plugin allows cross-channel post injection and phishing via missing channel permi…

Mattermost Plugins versions <=11.8 10.20.11 11.5.7.0 _The Mattermost GitLab plugin fails to verify channel permissions when processing API requests with a caller-supplied_ {{post_id}}_, and fails to …

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
6.3 MEDIUM
CVE-2026-16048 — Channel member roles accept out-of-scope roles

Mattermost versions 11.8.x <= 11.8.2, 11.7.x <= 11.7.6, 10.11.x <= 10.11.21 fail to restrict channel member role assignment to channel-scoped roles which allows a channel administrator to gain additi…

Remote | Authorization
Aug 17, 2026 Aug 17, 2026
Aug 17, 2026
Aug 17, 2026
Showing 20 of 11239 Results