CVE ID :CVE-2026-9816 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Mattermost versions 11.7.x Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details,…
CVE-2026-71424 – Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers
CVE ID :CVE-2026-71424 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx’s GET /api/mcp/servers and GET…
CVE-2026-64849 – MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)
CVE ID :CVE-2026-64849 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :MLflow is an open source AI engineering platform for agents, large language models, and machine learning models….
CVE-2026-56677 – 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint
CVE ID :CVE-2026-56677 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in…
CVE-2026-45790 – Dokploy: Invitation Role Escalation Allows Organization Takeover
CVE ID :CVE-2026-45790 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy’s organization.inviteMember tRPC procedure…
CVE-2026-19961 – Edimax EW-7478APC formWlSiteSurvey buffer overflow
CVE ID :CVE-2026-19961 Published : Aug. 16, 2026, 11:16 p.m. | 56 minutes ago Description :A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing…
CVE-2026-19959 – Edimax EW-7478APC formWanTcpipSetup stack-based overflow
CVE ID :CVE-2026-19959 Published : Aug. 16, 2026, 11:16 p.m. | 56 minutes ago Description :A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup….
CVE-2026-74791 – Scriban before 7.0.0 Authorization Bypass via Stale Include Cache
CVE ID :CVE-2026-74791 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to…
CVE-2026-74790 – Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache
CVE ID :CVE-2026-74790 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to…
CVE-2026-74784 – Scriban before 7.2.0 Denial of Service via array.insert_at
CVE ID :CVE-2026-74784 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null…