Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2811▲ 64 respecto a la semana anterior
Críticas / altas1484▲ 296 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 448 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.1) | 0.39% | — | Quantumnous New-apiAI | 31/8/2026 | 2/9/2026 | A vulnerability was determined in QuantumNous new-api up to 1.0.0-rc.15. Affected by this issue is some unknown functionality of the file /api/usage/token/ of the component Revoked API Token Handler. Executing a manipulation can lead to session expiration. The attack may be performed from remote. The exploit has been… | |
| Aplazada | Crítica (9.1) | 0.65% | — | Newapi NEW APIAI | 17/8/2026 | 18/9/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.18, user-controlled image n, video seconds and duration, max_tokens, max_completion_tokens, maxOutputTokens, audio duration, and billing-expression quantities can overflow conversions in… | |
| Aplazada | Alta (7.5) | 0.64% | — | Newapi NEW APIAI | 17/8/2026 | 18/9/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.11, POST /api/stripe/webhook, POST /api/creem/webhook, and POST /api/waffo/webhook read and log full request bodies before signature validation in router/api-router.go and the payment controllers,… | |
| Aplazada | Media (5.1) | 0.47% | — | Newapi NEW APIAI | 17/8/2026 | 18/9/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. From 0.9.1.3 until 1.0.0-rc.7, AdminResetPasskey in controller/passkey.go lacks the canManageTargetRole authorization check for DELETE /api/user/:id/reset_passkey, allowing a lower-privileged administrator to… | |
| Aplazada | Media (6) | 0.29% | — | Newapi NEW APIAI | 17/8/2026 | 18/9/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.16, repeated PUT /api/user/self requests that update language or sidebar_modules can race relay billing because controller/user.go calls User.Update and updateUserCache performs a full… | |
| Aplazada | Crítica (9.1) | 0.63% | — | Newapi NEW APIAI | 17/8/2026 | 18/9/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 1.0.0-rc.7, the admin user list and user lookup APIs, including GET /api/user/, return User.AccessToken as access_token because User model objects are serialized after queries use Omit("password"),… | |
| Analizada | Media (5.3) | 0.19% | — | Newapi NEW API | 9/7/2026 | 16/7/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET /api/oauth/email/bind and GET /api/oauth/wechat/bind used GET requests for state-changing account operations, allowing an attacker to… | |
| Analizada | Alta (7.7) | 0.44% | — | Newapi NEW API | 9/7/2026 | 16/7/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not apply IP filtering to hostnames; with ApplyIPFilterForDomain disabled by default, URL validation checked domain allow/block rules but did… | |
| Aplazada | Baja (2.9) | 0.46% | — | Quantumnous New-apiAI | 23/5/2026 | 23/7/2026 | A security vulnerability has been detected in QuantumNous new-api up to 0.12.1. This affects the function RelayMidjourneyImage/GetByOnlyMJId of the file router/relay-router.go of the component Midjourney Image Relay Endpoint. Such manipulation leads to authorization bypass. The attack can be launched remotely. The… | |
| Aplazada | Baja (2.1) | 0.32% | — | Quantumnous New-apiAI | 23/5/2026 | 23/7/2026 | A weakness has been identified in QuantumNous new-api up to 0.12.1. The impacted element is the function SearchUserTopUps/SearchAllTopUps of the file model/topup.go of the component self Endpoint. This manipulation causes sql injection. The attack can be initiated remotely. The exploit has been made available to the… | |
| Analizada | Alta (7.1) | 0.30% | — | Newapi NEW API | 8/5/2026 | 24/7/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-59146) and hardened in v0.9.6 (CVE-2025-62155) does not block the unspecified address 0.0.0.0. A regular (non-admin) user… | |
| Analizada | Alta (8.2) | 0.75% | — | Newapi NEW API | 8/5/2026 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook handler that allows an unauthenticated attacker to forge webhook events and credit arbitrary quota to their account without making any payment.… | |
| Analizada | Media (4.9) | 0.46% | — | Newapi NEW API | 23/3/2026 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verification flow allows an authenticated user with a registered passkey to satisfy secure verification without completing a WebAuthn assertion. As… | |
| Analizada | Media (6.5) | 0.36% | — | Newapi NEW API | 23/3/2026 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR) vulnerability in the video proxy endpoint (`GET /v1/videos/:task_id/content`) allows any authenticated user to access video content… | |
| Analizada | Media (5.4) | 0.27% | — | Newapi NEW API | 24/2/2026 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in component `MarkdownRenderer.jsx`, allowing for Cross-Site Scripting(XSS) when the model outputs items containing `<script>` tag. Version… | |
| Analizada | Alta (7.1) | 0.64% | — | Newapi NEW API | 24/2/2026 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerability in the `/api/token/search` endpoint allows authenticated users to cause denial of service through resource exhaustion by crafting… | |
| Aplazada | Alta (8.5) | 0.28% | — | Newapi NEW APIAI | 25/11/2025 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.9.6, a recently patched SSRF vulnerability contains a bypass method that can bypass the existing security fix and still allow SSRF to occur. Because the existing fix only applies security… | |
| Aplazada | Media (4.3) | 0.20% | — | MO JWT Generate NEW API KEY WP Login AND Register Using JWTAI | 19/11/2025 | 17/6/2026 | The WP Login and Register using JWT plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mo_jwt_generate_new_api_key' function in all versions up to, and including, 3.0.0. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Alta (8.5) | 0.24% | — | Newapi NEW APIAI | 9/10/2025 | 17/6/2026 | New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. An authenticated Server-Side Request Forgery (SSRF) vulnerability exists in versions prior to 0.9.0.5. A feature within the application allows authenticated users to submit a URL for the server to process its… | |
| Analizada | Alta (8.8) | 0.42% | — | Newapi NEW API | 22/8/2025 | 17/6/2026 | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS). |