Home
Trends
Vulnerabilities
News
Researchers
Why dbugs?

Eric-E

#22226of 53,624
10.2Total CVSS
Vulnerabilities · 2
Low
1
Medium
1
PT-2026-42885
6.5
2026-05-23
Quantumnous · New Api · CVE-2026-9305
**Name of the Vulnerable Software and Affected Versions** QuantumNous new-api versions prior to 0.12.2 **Description** A SQL injection flaw exists in the 'self' Endpoint within the `model/topup.go` file. The issue is located in the `SearchUserTopUps()` and `SearchAllTopUps()` functions, allowing a remote attacker to manipulate queries via SQL injection, which is a technique where malicious SQL statements are inserted into entry fields for execution. **Recommendations** At the moment, there is no information about a newer version that contains a fix for this vulnerability.
PT-2026-42886
3.7
2026-05-23
Quantumnous · New Api · CVE-2026-9306
**Name of the Vulnerable Software and Affected Versions** QuantumNous new-api versions prior to 0.12.2 **Description** An issue in the Midjourney Image Relay Endpoint component, specifically within the `RelayMidjourneyImage/GetByOnlyMJId()` function located in the `router/relay-router.go` file, allows for a remote authorization bypass. This bypass occurs through manipulation of the function, although the attack is characterized by high complexity and difficult exploitability. **Recommendations** Update to a version later than 0.12.1. As a temporary workaround, restrict access to the `RelayMidjourneyImage/GetByOnlyMJId()` function to minimize the risk of exploitation.