| CVE ID | Title | Vendor | Product | Severity | CVSS Score | Published At | AI Analysis |
|---|---|---|---|---|---|---|---|
| CVE-2026-75080 🧪 | SourceCodester Class and Exam Timetabling System edit_subject1.php sql injection | SourceCodester | Class and Exam Timetabling System | High | 7.3 | 2026-08-17 23:30:09 | Deep Dive |
| CVE-2026-75079 🧪 | SourceCodester Class and Exam Timetabling System edit_subject2.php sql injection | SourceCodester | Class and Exam Timetabling System | High | 7.3 | 2026-08-17 23:15:11 | Deep Dive |
| CVE-2026-71424 🧪 | Onyx: Cross-user OAuth-token leak via /api/mcp/servers* for per-user MCP servers | onyx-dot-app | onyx | Critical | 9.6 | 2026-08-17 21:28:33 | Deep Dive |
| CVE-2026-45790 🧪 | Dokploy: Invitation Role Escalation Allows Organization Takeover | Dokploy | dokploy | High | 8.0 | 2026-08-17 21:24:22 | Deep Dive |
| CVE-2026-64849 KEV 📌 💣 | MLflow: Unauthenticated full-read SSRF in webhook delivery: _validate_webhook_url bypassed via unvalidated HTTP redirects (and DNS rebinding) EPSS 0.16 | mlflow | mlflow | Critical | 9.3 | 2026-08-17 21:16:11 | Deep Dive |
| CVE-2026-56677 🧪 | 9Router: Authenticated Server-Side Request Forgery (SSRF) via OIDC Provider Test Endpoint | decolua | 9router | High | 8.6 | 2026-08-17 21:14:06 | Deep Dive |
| CVE-2026-71518 🧪 | Typemill < 2.26.0 Authorization Bypass via Media File Download Route | typemill | typemill | High | 7.5 | 2026-08-17 21:05:11 | Deep Dive |
| CVE-2026-75531 🧪 | Stored Cross-Site Scripting in URL Observables via Lookyloo Submission Handler in Pandora | pandora-analysis | pandora | High | 7.0 | 2026-08-17 21:00:13 | Deep Dive |
| CVE-2026-65832 🧪 | Deskflow - Unauthenticated server-controlled out-of-bounds read in ServerProxy::setOptions / translateKey modifier-table indexing | deskflow | deskflow | High | 8.2 | 2026-08-17 20:59:09 | Deep Dive |
| CVE-2026-63409 🧪 | Deskflow: Odd-length DSOP options vector causes out-of-bounds read in Deskflow client | deskflow | deskflow | High | 8.2 | 2026-08-17 20:57:19 | Deep Dive |
| CVE-2026-47683 🧪 | vm2: bufferAllocLimit cap bypassed by Buffer.concat and Buffer.from arrayLike | patriksimek | vm2 | High | 8.7 | 2026-08-17 20:55:32 | Deep Dive |
| CVE-2026-47686 🧪 | vm2: Missing Error.cause Sanitization Enables VM2 Sandbox Escape to RCE | patriksimek | vm2 | Critical | 9.9 | 2026-08-17 20:54:39 | Deep Dive |
| CVE-2026-47698 🧪 | vm2: Sandbox Breakout Using Dangerous Host Proto Mutators | patriksimek | vm2 | Critical | 9.8 | 2026-08-17 20:53:09 | Deep Dive |
| CVE-2026-65822 🧪 | ERPNext: SQL Injection in "Inactive Customers" report via unvalidated `doctype` filter | frappe | erpnext | High | 7.6 | 2026-08-17 20:45:46 | Deep Dive |
| CVE-2026-65974 🧪 | ERPNext: Server-Side Template Injection leading to Remote Code Execution | frappe | erpnext | Critical | 9.9 | 2026-08-17 20:44:21 | Deep Dive |
| CVE-2026-75482 🧪 | SWE-agent Trajectory Inspector Path Traversal File Disclosure | SWE-agent | SWE-agent | High | 7.5 | 2026-08-17 20:36:07 | Deep Dive |
| CVE-2026-75479 🧪 | JimuReport Unauthenticated Report Listing and Share Token Disclosure | jeecgboot | jimureport | High | 7.5 | 2026-08-17 20:36:05 | Deep Dive |
| CVE-2026-75111 🧪 | Evidently UI Path Traversal via Dataset Materialization Filename | evidentlyai | evidently | High | 7.5 | 2026-08-17 20:36:05 | Deep Dive |
| CVE-2026-75110 🧪 | MemOS Authentication Bypass via Unset INTERNAL_SERVICE_SECRET | MemTensor | MemOS | Critical | 9.8 | 2026-08-17 20:36:04 | Deep Dive |
| CVE-2026-75109 🧪 | Determined Missing Authorization Check on Generic Task Endpoints | determined-ai | determined | High | 7.1 | 2026-08-17 20:36:03 | Deep Dive |