CVE ID :CVE-2026-75976 Published : Aug. 19, 2026, 12:16 a.m. | 1 hour, 32 minutes ago Description :A weakness has been identified in TRENDnet TEW-823DRU 1.1.02b01. Impacted is the function strcpy of the file…
CVE-2026-66602 – WordPress HashBar – WordPress Notification Bar plugin <= 2.0.0 – Cross Site Request Forgery (CSRF) vulnerability
CVE ID :CVE-2026-66602 Published : 18 août 2026 22:17 | 1 heure, 31 minutes ago Description :Cross-Site Request Forgery (CSRF) vulnerability in DevItems HashBar – WordPress Notification Bar allows Cross Site Request Forgery. This…
CVE-2026-62292 – libheif: Out-of-bounds read in uncompressed unci tile range slicing
CVE ID :CVE-2026-62292 Published : 18 août 2026 22:17 | 1 heure, 32 minutes ago Description :libheif is a HEIF and AVIF file format decoder and encoder. From 1.19.0 until 1.23.1, a crafted uncompressed…
CVE-2026-52877 – Streambert : Insecure Protocol Execution in open-external IPC Handler
CVE ID :CVE-2026-52877 Published : 18 août 2026 22:16 | 1 heure, 32 minutes ago Description :Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the…
CVE-2026-52876 – Streambert: Arbitrary File Execution via VLC/mpv Launcher Fallback
CVE ID :CVE-2026-52876 Published : 18 août 2026 22:16 | 1 heure, 32 minutes ago Description :Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to version 2.6.0, the…
CVE-2026-52875 – Streambert: Arbitrary Directory Creation and File Manipulation via Backup Handler
CVE ID :CVE-2026-52875 Published : 18 août 2026 22:16 | 1 heure, 32 minutes ago Description :Streambert is a cross-platform Electron Desktop App to stream and download video content. Prior to 2.6.0, the perform-scheduled-backup…
CVE-2026-9816 – Insufficient server-side validation of board member role fields permits privilege escalation
CVE ID :CVE-2026-9816 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Mattermost versions 11.7.x Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details,…
CVE-2026-71424 – Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers
CVE ID :CVE-2026-71424 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx’s GET /api/mcp/servers and GET…
CVE-2026-64849 – MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVE ID :CVE-2026-64849 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :MLflow is an open source AI engineering platform for agents, large language models, and machine learning models….
CVE-2026-56677 – 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
CVE ID :CVE-2026-56677 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in…