Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 6.9 CVE-2026-12773

BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication_CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp...

BerriAI litellm 1.59.0 CVE
MEDIUM 5.3 CVE-2026-12770

BerriAI litellm Admin Key key_management_endpoints.py improper authorization_CVE-2026-12770

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_en...

BerriAI litellm 1.63.0 CVE
LOW 2.3 CVE-2026-12771

BerriAI litellm M2M JWT user_api_key_auth.py improper authorization_CVE-2026-12771

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.p...

BerriAI litellm 1.82.0 CVE
LOW 3.7 CVE-2026-56355

CVE-2026-56355_CVE-2026-56355

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

GNU Savane 3.14 CVE
MEDIUM 5.3 CVE-2026-56347

AVideo TopMenu Plugin – Stored Cross-Site Scripting via Unescaped Menu Item Fields_CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encodi...

WWBN AVideo CVE
MEDIUM 6.9 CVE-2026-56346

AVideo – Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint_CVE-2026-56346

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated use...

AVideo AVideo CVE
CRITICAL 9.2 CVE-2026-56345

AVideo – Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint_CVE-2026-56345

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the targ...

AVideo AVideo CVE
MEDIUM 6.1 CVE-2026-56342

AVideo – Server-Side Request Forgery in Live/test.php via statsURL Parameter_CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators t...

AVideo AVideo CVE
HIGH 8.7 CVE-2026-56341

AVideo – Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php_CVE-2026-56341

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing Pay...

AVideo AVideo CVE
HIGH 8.7 CVE-2026-56340

vLLM – Denial of Service via Unvalidated Multimodal Embeddings_CVE-2026-56340

vLLM versions >= 0.10.2 and < 0.13.0 are missing sparse tensor validation in multimodal embeddings processing. Because PyTorch disables sparse tens...

vLLM vLLM 0.10.2 CVE