newapi records
9 published records for vendor newapi.
Researcher profile
- Entered KEV
- 0 · 0%
- Weaponized
- 0 · 0%
- Pre-auth RCE
- 0
- With a fix record
- 66.7%
- Median publish → KEV
- No record has entered KEV
Recurring classes
- CWE-918 Server-Side Request Forgery (SSRF)2
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')2
- CWE-352 Cross-Site Request Forgery (CSRF)1
- CWE-287 Improper Authentication1
- CWE-943 Improper Neutralization of Special Elements in Data Query Logic1
- CWE-639 Authorization Bypass Through User-Controlled Key1
The weakness classes this vendor ships most often: where to look.
CWEAll records
9 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
35Monitor | CVE-2025-55573No exploit | QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).newapi · new api · CWE-79 | High8.8 | — | 0.4% | Aug 22, 2025 |
32Monitor | CVE-2026-41432Proof of concept | New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraudnewapi · new api · CWE-345 | High8.2 | — | 0.8% | May 8, 2026 |
30Monitor | CVE-2026-33655No exploit | New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLsnewapi · new api · CWE-918 | High7.7 | — | 0.4% | Jul 9, 2026 |
28Monitor | CVE-2026-25591No exploit | New API has an SQL LIKE Wildcard Injection DoS via Token Searchnewapi · new api · CWE-943 | High7.1 | — | 0.6% | Feb 23, 2026 |
28Monitor | CVE-2026-42339No exploit | New API: SSRF Filter Bypass via 0.0.0.0newapi · new api · CWE-918 | High7.1 | — | 0.3% | May 8, 2026 |
26Monitor | CVE-2026-30886No exploit | New API: IDOR in VideoProxy allows cross-user video content access via missing ownership checknewapi · new api · CWE-639 | Medium6.5 | — | 0.4% | Mar 23, 2026 |
21Monitor | CVE-2026-25802No exploit | New API has Potential XSS in its MarkdownRenderer componentnewapi · new api · CWE-79 | Medium5.4 | — | 0.3% | Feb 23, 2026 |
21Monitor | CVE-2026-44342No exploit | New API CSRF in email and WeChat account binding endpointsnewapi · new api · CWE-352 | Medium5.3 | — | 0.2% | Jul 9, 2026 |
19Monitor | CVE-2026-32879No exploit | New API has passkey-based secure step-up verification bypass for root-only channel secret disclosurenewapi · new api · CWE-287 | Medium4.9 | — | 0.5% | Mar 23, 2026 |
- CVE-2025-5557335Monitor
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
HighCVSS 8.8No exploitEPSS 0%newapi · new apiAug 22, 2025
- CVE-2026-4143232Monitor
New API: Stripe Webhook Signature Bypass via Empty Secret Enables Unlimited Quota Fraud
HighCVSS 8.2Proof of conceptEPSS 1%newapi · new apiMay 8, 2026
- CVE-2026-3365530Monitor
New API: SSRF Protection Bypass via Unresolved Hostname in Notification URLs
HighCVSS 7.7No exploitEPSS 0%newapi · new apiJul 9, 2026
- CVE-2026-2559128Monitor
New API has an SQL LIKE Wildcard Injection DoS via Token Search
HighCVSS 7.1No exploitEPSS 1%newapi · new apiFeb 23, 2026
- CVE-2026-4233928Monitor
New API: SSRF Filter Bypass via 0.0.0.0
HighCVSS 7.1No exploitEPSS 0%newapi · new apiMay 8, 2026
- CVE-2026-3088626Monitor
New API: IDOR in VideoProxy allows cross-user video content access via missing ownership check
MediumCVSS 6.5No exploitEPSS 0%newapi · new apiMar 23, 2026
- CVE-2026-2580221Monitor
New API has Potential XSS in its MarkdownRenderer component
MediumCVSS 5.4No exploitEPSS 0%newapi · new apiFeb 23, 2026
- CVE-2026-4434221Monitor
New API CSRF in email and WeChat account binding endpoints
MediumCVSS 5.3No exploitEPSS 0%newapi · new apiJul 9, 2026
- CVE-2026-3287919Monitor
New API has passkey-based secure step-up verification bypass for root-only channel secret disclosure
MediumCVSS 4.9No exploitEPSS 0%newapi · new apiMar 23, 2026