Vulnerabilities
Summary — last 7 days
New vulnerabilities2,636▼ 301 vs. last week
Critical / high1,352▲ 80 vs. last week
New active exploitation (KEV)5▼ 3 vs. last week
Unscored (no CVSS)58▼ 469 vs. last week
1 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | Medium (5.5) | 0.16% | — | Moonshot AI Kimi-codeAI | 7/27/2026 | 7/27/2026 | Kimi Code (@moonshot-ai/kimi-code) before 0.27.0 implements FetchURL SSRF hardening as a static hostname and IP-literal denylist in assertSafeFetchTarget, without resolving DNS or re-validating hosts after HTTP redirects. An attacker who can influence a FetchURL call (for example via prompt injection) can supply a… |