Vulnerabilities
Summary — last 7 days
New vulnerabilities2,663▼ 380 vs. last week
Critical / high1,289▼ 36 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)244▼ 274 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.8) | 0.19% | — | Google GenkitAI | 8/11/2026 | 8/26/2026 | Genkit does not properly validate host request headers. Any host on the developer's network, and any website the developer visits (via DNS rebinding), can reach POST /api/runAction on the Dev UI server (default port 4000) and execute any registered Genkit action and read the result. Fixed on 2026-06-18. |