Recent Advisories

Severity ID Title Vendor Product Date Type
MEDIUM 5.3 CVE-2026-12772

BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user session expiration_CVE-2026-12772

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/log...

BerriAI litellm 1.82.0 CVE
MEDIUM 5.3 CVE-2026-12774

BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client server-side request forgery_CVE-2026-12774

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client...

BerriAI litellm 1.82.0 CVE
MEDIUM 6.9 CVE-2026-12773

BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication_CVE-2026-12773

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp...

BerriAI litellm 1.59.0 CVE
MEDIUM 5.3 CVE-2026-12770

BerriAI litellm Admin Key key_management_endpoints.py improper authorization_CVE-2026-12770

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_en...

BerriAI litellm 1.63.0 CVE
MEDIUM 5.3 CVE-2026-56347

AVideo TopMenu Plugin – Stored Cross-Site Scripting via Unescaped Menu Item Fields_CVE-2026-56347

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encodi...

WWBN AVideo CVE
MEDIUM 6.9 CVE-2026-56346

AVideo – Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint_CVE-2026-56346

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated use...

AVideo AVideo CVE
MEDIUM 6.1 CVE-2026-56342

AVideo – Server-Side Request Forgery in Live/test.php via statsURL Parameter_CVE-2026-56342

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators t...

AVideo AVideo CVE
MEDIUM 5.3 CVE-2025-71379

vllm – Regular Expression Denial of Service in Multiple Components_CVE-2025-71379

vLLM versions >= 0.6.3 and < 0.9.0 contain multiple regular expression denial of service (ReDoS) vulnerabilities. Several regex patterns — in vllm/...

vllm vllm 0.6.3 CVE
MEDIUM 5.1 CVE-2026-56332

Capgo – Open Redirect via confirmation_url Parameter_CVE-2026-56332

Capgo before 12.128.2 contains an open redirect vulnerability in the confirm-signup endpoint that allows attackers to redirect users to arbitrary e...

Capgo Capgo CVE
MEDIUM 4.8 CVE-2026-56330

Capgo – Open Redirect via Unvalidated Stripe Billing URLs_CVE-2026-56330

Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, s...

Capgo Capgo CVE