Predictive Vulnerability Intelligence.

Product

  • Product
  • Pricing
  • Documentation

Company

  • About
  • Partnerships
  • Blog
  • Support

Legal

  • Terms
  • Privacy
  • Data Licensing

© 2026 FAUCET Technologies LLC. All rights reserved.

Newapi

First CVE: Aug 22, 2025Active for: 1 yearTotal CVEs: 9

Newapi provides a focused API product that has disclosed a modest set of vulnerabilities centered on authentication and authorization mechanisms. The recurring weakness classes—including improper input neutralization in web contexts, authorization bypass through user-controlled keys, authentication defects, and SQL injection—reflect common challenges in API design where access control and input handling boundaries are critical. Live severity, exploitation activity, and exposure counts are shown alongside this summary.

FAUCET AI Generated
9
Total CVEs
More Total CVEs than 91% of tracked vendors
4.5
Avg CVEs / Product / Year
More Avg CVEs / Product / Year than 97% of tracked vendors
6.7
Avg CVSS Score
Higher Avg CVSS Score than 44% of tracked vendors
0.0%
In CISA KEV
Bottom 1%

Trends Over Time

The number and severity of CVEs published that impact products developed by Newapi over time

Volume of CVEsAvg CVSS Base Score
First CVE
Aug 22, 2025
11 months ago
Most Recent CVE
Jul 9, 2026
15 days ago

Products(1 total)

Top CVEs

Signals from CVEs in this vendor scope (9 CVEs).

9 CVEs · Highest risk first

CVEPublishedCVSSRiskKEVExploit
CVE-2026-33655HIGH
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the default SSRF protection configuration did not
Jul 9, 20267.735NONO
CVE-2026-41432HIGH
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.12.10, a vulnerability exists in the Stripe webhook hand
May 8, 20268.230NONO
CVE-2025-55573HIGH
QuantumNous new-api v.0.8.5.2 is vulnerable to Cross Site Scripting (XSS).
Aug 22, 20258.828NONO
CVE-2026-44342MEDIUM
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to 0.12.0-alpha.1, the email and WeChat account binding endpoints GET
Jul 9, 20265.327NONO
CVE-2026-42339HIGH
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.
May 8, 20267.127NONO
CVE-2026-25591MEDIUM
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.10, a SQL LIKE wildcard injection vulnerabili
Feb 24, 20266.524NONO
CVE-2026-30886MEDIUM
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.11.4-alpha.2, an Insecure Direct Object Reference (IDOR)
Mar 23, 20266.522NONO
CVE-2026-25802MEDIUM
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Prior to version 0.10.8-alpha.9, a potential unsafe operation occurs in com
Feb 24, 20265.420NONO
CVE-2026-32879MEDIUM
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. Starting in version 0.10.0, a logic flaw in the universal secure verificati
Mar 23, 20264.918NONO
View all 9 CVEs →

CVE Severity & Scoring

Severity distribution of CVEs that affect this vendor's products9 CVEs
56%
44%
Severity distribution among all CVEs352,231 CVEs
45%
40%
11%
MediumHigh
Attack Vector
Local0 (0.0%)
Network9 (100.0%)
Unknown0 (0.0%)
Physical0 (0.0%)
Adjacent Network0 (0.0%)
Attack Complexity
Low8 (88.9%)
High1 (11.1%)
Unknown0 (0.0%)
User Interaction
None6 (66.7%)
Unknown0 (0.0%)
Required3 (33.3%)
Privileges Required
Low5 (55.6%)
High1 (11.1%)
None3 (33.3%)
Unknown0 (0.0%)

Exploit Exposure

Signals from CVEs in this vendor scope (9 CVEs).

CISA KEV
0 CVEs
0.0% of CVEs· Bottom 1%
Metasploit
0 CVEs
0.0% of CVEs· Bottom 1%
Nuclei
0 CVEs
0.0% of CVEs· Bottom 1%
ExploitDB
0 CVEs
0.0% of CVEs· Bottom 1%

Social Chatter

An overview of all social media posts that mention a CVE ID that affects a product developed by Newapi.

Media Mentions

Media articles that mention a CVE ID that affects a product developed by Newapi — matched by CVE ID, not by vendor name.

Top CNAs Publishing CVEs For Newapi's Products

View all 2 CNAs →

Top CWEs