Vulnerabilities

Summary — last 7 days

New vulnerabilities2,726▼ 82 vs. last week
Critical / high1,416▲ 189 vs. last week
New active exploitation (KEV)5▼ 5 vs. last week
Unscored (no CVSS)100▼ 400 vs. last week
–

4 results, sorted by published date (most recent first)

CVEStatusSeverityEPSS Active exploitationAffected technologiesPublished ▼Modified Description
AnalyzedLow (3.7)0.30%—Athroniaeth Fastapi API KEY1/21/20266/17/2026
FastAPI Api Key provides a backend-agnostic library that provides an API key system. Version 1.1.0 has a timing side-channel vulnerability in verify_key(). The method applied a random delay only on verification failures, allowing an attacker to statistically distinguish valid from invalid API keys by measuring…
ModifiedHigh (7.8)0.38%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+57/24/20206/17/2026
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
ModifiedHigh (7.8)0.22%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+57/24/20206/17/2026
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure,…
ModifiedHigh (7.8)0.27%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+57/24/20206/17/2026
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a…