DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-72808: CVE-2026-72808: Unauthorized PDF Annotation Access in SiYuan Knowledge Management System

CVE-2026-72808: CVE-2026-72808: Unauthorized PDF Annotation Access in SiYuan Knowledge Management System

Comments
2 min read
CVE-2026-72807: CVE-2026-72807: Second-Order SQL Injection via Attribute View Templates in SiYuan

CVE-2026-72807: CVE-2026-72807: Second-Order SQL Injection via Attribute View Templates in SiYuan

Comments
2 min read
CVE-2026-72806: CVE-2026-72806: Missing Authorization in SiYuan Attribute View Rendering Leads to Information Disclosure

CVE-2026-72806: CVE-2026-72806: Missing Authorization in SiYuan Attribute View Rendering Leads to Information Disclosure

Comments
2 min read
CVE-2026-72805: CVE-2026-72805: Missing Authorization in SiYuan Note Block APIs Leads to Information Disclosure

CVE-2026-72805: CVE-2026-72805: Missing Authorization in SiYuan Note Block APIs Leads to Information Disclosure

Comments
2 min read
CVE-2026-72804: CVE-2026-72804: Authentication Bypass and Sensitive Information Exposure in SiYuan Graph Endpoints

CVE-2026-72804: CVE-2026-72804: Authentication Bypass and Sensitive Information Exposure in SiYuan Graph Endpoints

Comments
2 min read
CVE-2026-72802: CVE-2026-72802: Sensitive Information Disclosure via Administrative Asset Resolvers in SiYuan Note

CVE-2026-72802: CVE-2026-72802: Sensitive Information Disclosure via Administrative Asset Resolvers in SiYuan Note

Comments
3 min read
CVE-2026-72801: CVE-2026-72801: Information Disclosure of Cryptographic Key Material in SiYuan

CVE-2026-72801: CVE-2026-72801: Information Disclosure of Cryptographic Key Material in SiYuan

Comments
2 min read
CVE-2026-72800: CVE-2026-72800: Missing Authorization in SiYuan Personal Knowledge Management System

CVE-2026-72800: CVE-2026-72800: Missing Authorization in SiYuan Personal Knowledge Management System

Comments
2 min read
CVE-2026-72803: CVE-2026-72803: Information Disclosure via Missing Authorization in SiYuan API

CVE-2026-72803: CVE-2026-72803: Information Disclosure via Missing Authorization in SiYuan API

Comments
2 min read
GHSA-7J72-F6WG-CXW6: CVE-2026-68584: Authentication Bypass via Auxiliary Content Endpoints in SiYuan

GHSA-7J72-F6WG-CXW6: CVE-2026-68584: Authentication Bypass via Auxiliary Content Endpoints in SiYuan

Comments
3 min read
CVE-2026-77465: CVE-2026-77465: Uncontrolled Recursion in toml-node Deserializer Leads to Denial of Service

CVE-2026-77465: CVE-2026-77465: Uncontrolled Recursion in toml-node Deserializer Leads to Denial of Service

Comments
2 min read
CVE-2026-73295: CVE-2026-73295: DOM-based Cross-Site Scripting (XSS) in Material for MkDocs Search Suggestions

CVE-2026-73295: CVE-2026-73295: DOM-based Cross-Site Scripting (XSS) in Material for MkDocs Search Suggestions

Comments
2 min read
CVE-2026-71869: CVE-2026-71869: Remote Code Execution in Orval via OpenAPI Default Value Template Literal Injection

CVE-2026-71869: CVE-2026-71869: Remote Code Execution in Orval via OpenAPI Default Value Template Literal Injection

Comments
2 min read
CVE-2026-61625: CVE-2026-61625: Arbitrary File Write via Path Traversal in VictoriaMetrics vmrestore

CVE-2026-61625: CVE-2026-61625: Arbitrary File Write via Path Traversal in VictoriaMetrics vmrestore

Comments
2 min read
CVE-2026-73846: CVE-2026-73846: Cache Key Canonicalization Collision in ondata ckan-mcp-server

CVE-2026-73846: CVE-2026-73846: Cache Key Canonicalization Collision in ondata ckan-mcp-server

Comments
2 min read
GHSA-99RQ-75J6-5J9F: GHSA-99rq-75j6-5j9f: Stored and Reflected XSS in SiYuan via SVG Sanitizer Bypass

GHSA-99RQ-75J6-5J9F: GHSA-99rq-75j6-5j9f: Stored and Reflected XSS in SiYuan via SVG Sanitizer Bypass

Comments
2 min read
GHSA-GW25-M53R-QH88: GHSA-gw25-m53r-qh88: Path Traversal Bypass in SiYuan Notebook via /export/temp/ Short-Circuit Branch

GHSA-GW25-M53R-QH88: GHSA-gw25-m53r-qh88: Path Traversal Bypass in SiYuan Notebook via /export/temp/ Short-Circuit Branch

Comments
2 min read
CVE-2026-62669: CVE-2026-62669: Critical Two-Factor Authentication Bypass in Grav CMS Login Plugin

CVE-2026-62669: CVE-2026-62669: Critical Two-Factor Authentication Bypass in Grav CMS Login Plugin

Comments
2 min read
CVE-2026-63435: CVE-2026-63435: Parser Interpretation Conflict in Ruby Mail Gem RFC 2047 Decoders

CVE-2026-63435: CVE-2026-63435: Parser Interpretation Conflict in Ruby Mail Gem RFC 2047 Decoders

Comments
2 min read
CVE-2026-63481: CVE-2026-63481: Sensitive Information Exposure in Hurl [Cookies] Redirection

CVE-2026-63481: CVE-2026-63481: Sensitive Information Exposure in Hurl [Cookies] Redirection

Comments
2 min read
CVE-2026-63490: CVE-2026-63490: Path Traversal and Arbitrary File Disclosure in Handlebars.java

CVE-2026-63490: CVE-2026-63490: Path Traversal and Arbitrary File Disclosure in Handlebars.java

Comments
2 min read
CVE-2026-4692: CVE-2026-4692: Sandbox Escape via Responsive Design Mode in Mozilla Firefox and Thunderbird

CVE-2026-4692: CVE-2026-4692: Sandbox Escape via Responsive Design Mode in Mozilla Firefox and Thunderbird

Comments
3 min read
CVE-2026-65842: CVE-2026-65842: Server-Side Request Forgery with Response Disclosure in @platejs/docx-io

CVE-2026-65842: CVE-2026-65842: Server-Side Request Forgery with Response Disclosure in @platejs/docx-io

Comments
2 min read
CVE-2026-2763: CVE-2026-2763: Use-After-Free in SpiderMonkey Generator for-in Loops

CVE-2026-2763: CVE-2026-2763: Use-After-Free in SpiderMonkey Generator for-in Loops

Comments
2 min read
CVE-2026-60206: CVE-2026-60206: Unauthenticated SAML Authentication Bypass in Oracle WebLogic Server

CVE-2026-60206: CVE-2026-60206: Unauthenticated SAML Authentication Bypass in Oracle WebLogic Server

Comments
2 min read
CVE-2026-62676: CVE-2026-62676: Security Guardrail Policy Bypass via Shell-Command Parser Flaws in Omnigent AI Agent Framework

CVE-2026-62676: CVE-2026-62676: Security Guardrail Policy Bypass via Shell-Command Parser Flaws in Omnigent AI Agent Framework

Comments
2 min read
CVE-2026-68921: CVE-2026-68921: Cross-Site Scripting via SVG Attribute Injection in DiceBear

CVE-2026-68921: CVE-2026-68921: Cross-Site Scripting via SVG Attribute Injection in DiceBear

Comments
2 min read
CVE-2026-67446: CVE-2026-67446: Unbounded Image Dimension Decoding in Mailpit Thumbnail Generation

CVE-2026-67446: CVE-2026-67446: Unbounded Image Dimension Decoding in Mailpit Thumbnail Generation

Comments
2 min read
CVE-2026-72921: CVE-2026-72921: Incorrect Authorization in SeaweedFS Filer JWT Prefix Match

CVE-2026-72921: CVE-2026-72921: Incorrect Authorization in SeaweedFS Filer JWT Prefix Match

Comments
2 min read
CVE-2026-67445: CVE-2026-67445: Uncontrolled Memory Resource Consumption in Mailpit SMTP and POP3 Services

CVE-2026-67445: CVE-2026-67445: Uncontrolled Memory Resource Consumption in Mailpit SMTP and POP3 Services

Comments
2 min read
CVE-2026-73843: CVE-2026-73843: Critical Missing Authentication and Privilege Escalation in OpenChoreo Cluster Gateway

CVE-2026-73843: CVE-2026-73843: Critical Missing Authentication and Privilege Escalation in OpenChoreo Cluster Gateway

Comments
2 min read
CVE-2026-73841: CVE-2026-73841: Broken Object Level Authorization (BOLA) in OpenChoreo Container Exec and Wirelogs Endpoints

CVE-2026-73841: CVE-2026-73841: Broken Object Level Authorization (BOLA) in OpenChoreo Container Exec and Wirelogs Endpoints

Comments
2 min read
CVE-2026-73840: CVE-2026-73840: Unauthenticated Webhook Signature Bypass and Git-Provider Confusion in OpenChoreo

CVE-2026-73840: CVE-2026-73840: Unauthenticated Webhook Signature Bypass and Git-Provider Confusion in OpenChoreo

Comments
2 min read
CVE-2026-73667: CVE-2026-73667: Remote Code Execution via OS Command Injection in OpenChoreo Workflow Plane

CVE-2026-73667: CVE-2026-73667: Remote Code Execution via OS Command Injection in OpenChoreo Workflow Plane

Comments
2 min read
CVE-2026-84366: CVE-2026-84366: Plaintext AWS Credential Exposure in Scrapy S3DownloadHandler

CVE-2026-84366: CVE-2026-84366: Plaintext AWS Credential Exposure in Scrapy S3DownloadHandler

Comments
2 min read
CVE-2026-62674: CVE-2026-62674: Shared Agent Bundle Overwrite Leads to Authenticated Runner Remote Code Execution in omnigent

CVE-2026-62674: CVE-2026-62674: Shared Agent Bundle Overwrite Leads to Authenticated Runner Remote Code Execution in omnigent

1
Comments
2 min read
CVE-2026-63311: CVE-2026-63311: Server-Side Request Forgery and DNS Rebinding in Natural Language Toolkit (NLTK)

CVE-2026-63311: CVE-2026-63311: Server-Side Request Forgery and DNS Rebinding in Natural Language Toolkit (NLTK)

Comments
2 min read
CVE-2026-62388: CVE-2026-62388: Insecure Default Security Enforcement in Natural Language Toolkit (NLTK) Path Security Module

CVE-2026-62388: CVE-2026-62388: Insecure Default Security Enforcement in Natural Language Toolkit (NLTK) Path Security Module

Comments
2 min read
CVE-2026-76172: CVE-2026-76172: Parser Differential and Host Confusion in fast-uri

CVE-2026-76172: CVE-2026-76172: Parser Differential and Host Confusion in fast-uri

Comments
2 min read
CVE-2026-75899: CVE-2026-75899: Double-Decoding Host Bypass and SSRF in fast-uri

CVE-2026-75899: CVE-2026-75899: Double-Decoding Host Bypass and SSRF in fast-uri

Comments
3 min read
CVE-2026-75975: CVE-2026-75975: Server-Side Request Forgery (SSRF) and Address-Policy Bypass via Malformed IPv6 Parser in fast-uri

CVE-2026-75975: CVE-2026-75975: Server-Side Request Forgery (SSRF) and Address-Policy Bypass via Malformed IPv6 Parser in fast-uri

Comments
2 min read
CVE-2026-75931: CVE-2026-75931: Host Confusion and SSRF Bypass via Scheme-Relative URIs in fast-uri

CVE-2026-75931: CVE-2026-75931: Host Confusion and SSRF Bypass via Scheme-Relative URIs in fast-uri

Comments
2 min read
CVE-2026-82395: CVE-2026-82395: Insecure Direct Object Reference (IDOR) in Sulu CMS Media Move Authorization

CVE-2026-82395: CVE-2026-82395: Insecure Direct Object Reference (IDOR) in Sulu CMS Media Move Authorization

Comments
2 min read
GHSA-WWV5-G3V4-889X: GHSA-wwv5-g3v4-889x: Cookie Attribute Injection in Tornado via Legacy Case-Insensitive kwargs

GHSA-WWV5-G3V4-889X: GHSA-wwv5-g3v4-889x: Cookie Attribute Injection in Tornado via Legacy Case-Insensitive kwargs

Comments
2 min read
GHSA-8423-8FGW-73VQ: GHSA-8423-8FGW-73VQ: Memory Amplification Denial of Service in Tornado Multipart Form Parser

GHSA-8423-8FGW-73VQ: GHSA-8423-8FGW-73VQ: Memory Amplification Denial of Service in Tornado Multipart Form Parser

Comments
2 min read
GHSA-J8PM-GJ4C-RQ4X: GHSA-J8PM-GJ4C-RQ4X: Algorithmic Complexity Denial of Service in league/commonmark

GHSA-J8PM-GJ4C-RQ4X: GHSA-J8PM-GJ4C-RQ4X: Algorithmic Complexity Denial of Service in league/commonmark

Comments
2 min read
GHSA-F8FG-PG57-V4J8: GHSA-f8fg-pg57-v4j8: Sanitizer Filter Bypass via Control Character Injection in league/commonmark

GHSA-F8FG-PG57-V4J8: GHSA-f8fg-pg57-v4j8: Sanitizer Filter Bypass via Control Character Injection in league/commonmark

Comments
2 min read
GHSA-JJV6-8J6V-6J52: GHSA-JJV6-8J6V-6J52: Algorithmic Complexity Denial of Service in league/commonmark

GHSA-JJV6-8J6V-6J52: GHSA-JJV6-8J6V-6J52: Algorithmic Complexity Denial of Service in league/commonmark

Comments
2 min read
CVE-2026-78680: CVE-2026-78680: Arbitrary Code Execution in NLTK via Untrusted Graphviz Path Resolution

CVE-2026-78680: CVE-2026-78680: Arbitrary Code Execution in NLTK via Untrusted Graphviz Path Resolution

Comments
2 min read
GHSA-8RR7-CVQ3-GMFH: GHSA-8RR7-CVQ3-GMFH: Algorithmic Complexity Denial of Service in league/commonmark AttributesExtension

GHSA-8RR7-CVQ3-GMFH: GHSA-8RR7-CVQ3-GMFH: Algorithmic Complexity Denial of Service in league/commonmark AttributesExtension

Comments
2 min read
CVE-2026-84371: CVE-2026-84371: Stored XSS via SVG SMIL URI-list Scheme-Policy Bypass in sanitize-html

CVE-2026-84371: CVE-2026-84371: Stored XSS via SVG SMIL URI-list Scheme-Policy Bypass in sanitize-html

Comments
2 min read
CVE-2026-84305: CVE-2026-84305: Algorithmic Complexity Vulnerability (ReindentFilter CPU Exhaustion) in sqlparse

CVE-2026-84305: CVE-2026-84305: Algorithmic Complexity Vulnerability (ReindentFilter CPU Exhaustion) in sqlparse

Comments
2 min read
CVE-2026-84309: CVE-2026-84309: Infinite Loop and CPU Exhaustion in pypdf TreeObject.insert_child

CVE-2026-84309: CVE-2026-84309: Infinite Loop and CPU Exhaustion in pypdf TreeObject.insert_child

Comments
2 min read
CVE-2026-84311: CVE-2026-84311: Algorithmic Complexity Denial of Service in pypdf

CVE-2026-84311: CVE-2026-84311: Algorithmic Complexity Denial of Service in pypdf

Comments
2 min read
CVE-2026-84310: CVE-2026-84310: Algorithmic Complexity Exhaustion in pypdf

CVE-2026-84310: CVE-2026-84310: Algorithmic Complexity Exhaustion in pypdf

Comments
2 min read
CVE-2026-77567: CVE-2026-77567: Multi-Factor Authentication Bypass in Filament App-Based MFA

CVE-2026-77567: CVE-2026-77567: Multi-Factor Authentication Bypass in Filament App-Based MFA

Comments
2 min read
CVE-2026-84307: CVE-2026-84307: Authentication Oracle and Multi-Factor Authentication Challenge Leak in Filament

CVE-2026-84307: CVE-2026-84307: Authentication Oracle and Multi-Factor Authentication Challenge Leak in Filament

Comments
2 min read
CVE-2026-84306: CVE-2026-84306: Multi-Factor Authentication Bypass via Replay Attack in Filament

CVE-2026-84306: CVE-2026-84306: Multi-Factor Authentication Bypass via Replay Attack in Filament

Comments
2 min read
CVE-2026-19418: CVE-2026-19418: Broken Access Control and Cross-Site Request Forgery in TYPO3 CMS Core

CVE-2026-19418: CVE-2026-19418: Broken Access Control and Cross-Site Request Forgery in TYPO3 CMS Core

Comments
2 min read
CVE-2026-84304: CVE-2026-84304: Uncontrolled Resource Consumption in gRPC-Go HTTP/2 Frame Processing

CVE-2026-84304: CVE-2026-84304: Uncontrolled Resource Consumption in gRPC-Go HTTP/2 Frame Processing

Comments
2 min read
loading...