Skip to content

Menu
  • Home
Menu

CVE-2026-9816 – Insufficient server-side validation of board member role fields permits privilege escalation

Posted on August 18, 2026

CVE ID :CVE-2026-9816 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Mattermost versions 11.7.x Severity: 8.3 | HIGH Visit the link for more details, such as CVSS details,…

CVE-2026-71424 – Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers

Posted on August 18, 2026

CVE ID :CVE-2026-71424 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Onyx is an open-source AI platform. Prior to 3.1.10, 3.2.14, and 4.0.0, Onyx’s GET /api/mcp/servers and GET…

CVE-2026-64849 – MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding)

Posted on August 18, 2026

CVE ID :CVE-2026-64849 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :MLflow is an open source AI engineering platform for agents, large language models, and machine learning models….

CVE-2026-56677 – 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint

Posted on August 18, 2026

CVE ID :CVE-2026-56677 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :9Router is an AI router & token saver. In 0.5.4 and earlier, the POST /api/auth/oidc/test endpoint in…

CVE-2026-45790 – Dokploy: Invitation Role Escalation Allows Organization Takeover

Posted on August 18, 2026

CVE ID :CVE-2026-45790 Published : Aug. 17, 2026, 10:17 p.m. | 1 hour, 56 minutes ago Description :Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.6, Dokploy’s organization.inviteMember tRPC procedure…

CVE-2026-19961 – Edimax EW-7478APC formWlSiteSurvey buffer overflow

Posted on August 17, 2026

CVE ID :CVE-2026-19961 Published : Aug. 16, 2026, 11:16 p.m. | 56 minutes ago Description :A vulnerability was detected in Edimax EW-7478APC 1.04. Affected is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey. Performing…

CVE-2026-19959 – Edimax EW-7478APC formWanTcpipSetup stack-based overflow

Posted on August 17, 2026

CVE ID :CVE-2026-19959 Published : Aug. 16, 2026, 11:16 p.m. | 56 minutes ago Description :A weakness has been identified in Edimax EW-7478APC 1.04. This affects the function formWanTcpipSetup of the file /goform/formWanTcpipSetup….

CVE-2026-74791 – Scriban before 7.0.0 Authorization Bypass via Stale Include Cache

Posted on August 17, 2026

CVE ID :CVE-2026-74791 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.0.0 fails to clear the CachedTemplates dictionary when TemplateContext.Reset() is called, allowing cached templates to…

CVE-2026-74790 – Scriban before 7.0.0 MemberFilter Bypass via TemplateContext Cache

Posted on August 17, 2026

CVE ID :CVE-2026-74790 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.0.0 caches TypedObjectAccessor by Type only without considering MemberFilter changes, allowing reused TemplateContext instances to…

CVE-2026-74784 – Scriban before 7.2.0 Denial of Service via array.insert_at

Posted on August 17, 2026

CVE ID :CVE-2026-74784 Published : Aug. 16, 2026, 2:16 p.m. | 9 hours, 56 minutes ago Description :Scriban before 7.2.0 contains a denial of service vulnerability in the array.insert_at function that allocates unbounded null…

Posts pagination

1 2 … 130 Next

Site map

  • About Us
  • Privacy Policy
  • Terms & Conditions of Use
©2026 | Design: Newspaperly WordPress Theme