DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-27654: CVE-2026-27654: Heap-based Buffer Overflow in NGINX ngx_http_dav_module via Integer Underflow

CVE-2026-27654: CVE-2026-27654: Heap-based Buffer Overflow in NGINX ngx_http_dav_module via Integer Underflow

Comments
2 min read
CVE-2026-40097: CVE-2026-40097: Index Out-of-Bounds Panic in Step CA TPM Attestation

CVE-2026-40097: CVE-2026-40097: Index Out-of-Bounds Panic in Step CA TPM Attestation

Comments
2 min read
CVE-2026-40109: CVE-2026-40109: Improper Authentication in Flux notification-controller GCR Receiver

CVE-2026-40109: CVE-2026-40109: Improper Authentication in Flux notification-controller GCR Receiver

Comments
2 min read
GHSA-6V7Q-WJVX-W8WG: GHSA-6V7Q-WJVX-W8WG: Arbitrary FTP Command Execution via CRLF Injection in basic-ftp

GHSA-6V7Q-WJVX-W8WG: GHSA-6V7Q-WJVX-W8WG: Arbitrary FTP Command Execution via CRLF Injection in basic-ftp

Comments
2 min read
GHSA-FFQ7-898W-9JC4: GHSA-FFQ7-898W-9JC4: Stored Cross-Site Scripting via SVG Upload in DotNetNuke

GHSA-FFQ7-898W-9JC4: GHSA-FFQ7-898W-9JC4: Stored Cross-Site Scripting via SVG Upload in DotNetNuke

Comments
2 min read
CVE-2026-40194: CVE-2026-40194: Observable Timing Discrepancy in phpseclib SSH2 HMAC Verification

CVE-2026-40194: CVE-2026-40194: Observable Timing Discrepancy in phpseclib SSH2 HMAC Verification

Comments
2 min read
CVE-2026-40242: CVE-2026-40242: Unauthenticated Server-Side Request Forgery in Arcane Template Fetch Mechanism

CVE-2026-40242: CVE-2026-40242: Unauthenticated Server-Side Request Forgery in Arcane Template Fetch Mechanism

Comments
2 min read
GHSA-75HX-XJ24-MQRW: GHSA-75HX-XJ24-MQRW: Unauthenticated Access and Information Exposure in n8n-mcp HTTP Transport

GHSA-75HX-XJ24-MQRW: GHSA-75HX-XJ24-MQRW: Unauthenticated Access and Information Exposure in n8n-mcp HTTP Transport

Comments
2 min read
CVE-2026-5412: CVE-2026-5412: Broken Access Control in Juju API Leads to Cloud Credential Leak

CVE-2026-5412: CVE-2026-5412: Broken Access Control in Juju API Leads to Cloud Credential Leak

Comments
2 min read
CVE-2026-5774: CVE-2026-5774: Race Condition and Denial of Service in Canonical Juju API Server

CVE-2026-5774: CVE-2026-5774: Race Condition and Denial of Service in Canonical Juju API Server

Comments
2 min read
GHSA-8F24-V5VV-GM5J: GHSA-8f24-v5vv-gm5j: Open Redirect in next-intl Middleware via URL Parsing Discrepancy

GHSA-8F24-V5VV-GM5J: GHSA-8f24-v5vv-gm5j: Open Redirect in next-intl Middleware via URL Parsing Discrepancy

Comments
2 min read
GHSA-FPJ4-9QHX-5M6M: GHSA-FPJ4-9QHX-5M6M: Improper Authorization in DNN Platform Friend Request Flow

GHSA-FPJ4-9QHX-5M6M: GHSA-FPJ4-9QHX-5M6M: Improper Authorization in DNN Platform Friend Request Flow

Comments
2 min read
GHSA-2RHW-GW3F-477J: GHSA-2RHW-GW3F-477J: Predictable HostGUID Assignment in DNN Platform New Installations

GHSA-2RHW-GW3F-477J: GHSA-2RHW-GW3F-477J: Predictable HostGUID Assignment in DNN Platform New Installations

Comments
2 min read
GHSA-93VF-569F-22CQ: GHSA-93VF-569F-22CQ: CSS Injection in PHP rhukster/dom-sanitizer via SVG Style Tags

GHSA-93VF-569F-22CQ: GHSA-93VF-569F-22CQ: CSS Injection in PHP rhukster/dom-sanitizer via SVG Style Tags

Comments
2 min read
GHSA-68QG-G8MG-6PR7: GHSA-68QG-G8MG-6PR7: Unauthenticated Remote Code Execution in Paperclip via Authorization Bypass Chain

GHSA-68QG-G8MG-6PR7: GHSA-68QG-G8MG-6PR7: Unauthenticated Remote Code Execution in Paperclip via Authorization Bypass Chain

Comments
2 min read
GHSA-55V6-G8PM-PW4C: GHSA-55V6-G8PM-PW4C: Server-Side Request Forgery and CORS Misconfiguration in rembg API

GHSA-55V6-G8PM-PW4C: GHSA-55V6-G8PM-PW4C: Server-Side Request Forgery and CORS Misconfiguration in rembg API

Comments
2 min read
GHSA-X7MM-9VVV-64W8: GHSA-X7MM-9VVV-64W8: Reflected Cross-Site Scripting in unhead Streaming SSR

GHSA-X7MM-9VVV-64W8: GHSA-X7MM-9VVV-64W8: Reflected Cross-Site Scripting in unhead Streaming SSR

Comments
2 min read
GHSA-JVFF-X2QM-6286: GHSA-jvff-x2qm-6286: Arbitrary JavaScript Execution via Sandbox Bypass in mathjs

GHSA-JVFF-X2QM-6286: GHSA-jvff-x2qm-6286: Arbitrary JavaScript Execution via Sandbox Bypass in mathjs

Comments
2 min read
GHSA-9CP7-J3F8-P5JX: GHSA-9CP7-J3F8-P5JX: Unauthenticated Path Traversal and Zip Slip in Daptin

GHSA-9CP7-J3F8-P5JX: GHSA-9CP7-J3F8-P5JX: Unauthenticated Path Traversal and Zip Slip in Daptin

Comments
2 min read
CVE-2026-40189: CVE-2026-40189: Critical Authorization Bypass in goshs State-Changing Routes

CVE-2026-40189: CVE-2026-40189: Critical Authorization Bypass in goshs State-Changing Routes

Comments
2 min read
CVE-2026-40162: CVE-2026-40162: Authenticated Arbitrary File Write in Bugsink Artifact Assembly

CVE-2026-40162: CVE-2026-40162: Authenticated Arbitrary File Write in Bugsink Artifact Assembly

Comments
2 min read
CVE-2026-39961: CVE-2026-39961: Cross-Namespace Secret Exfiltration via Confused Deputy in Aiven Operator

CVE-2026-39961: CVE-2026-39961: Cross-Namespace Secret Exfiltration via Confused Deputy in Aiven Operator

Comments
2 min read
CVE-2026-40074: CVE-2026-40074: Denial of Service via Unhandled Exceptions in SvelteKit Redirects

CVE-2026-40074: CVE-2026-40074: Denial of Service via Unhandled Exceptions in SvelteKit Redirects

Comments
2 min read
CVE-2026-40077: CVE-2026-40077: Insecure Direct Object Reference in Beszel Hub API

CVE-2026-40077: CVE-2026-40077: Insecure Direct Object Reference in Beszel Hub API

Comments
2 min read
CVE-2026-40073: CVE-2026-40073: Unrestricted Resource Allocation in SvelteKit adapter-node via Chunked Transfer Encoding

CVE-2026-40073: CVE-2026-40073: Unrestricted Resource Allocation in SvelteKit adapter-node via Chunked Transfer Encoding

Comments
2 min read
CVE-2026-40103: CVE-2026-40103: Authorization Bypass via Method Confusion in Vikunja API

CVE-2026-40103: CVE-2026-40103: Authorization Bypass via Method Confusion in Vikunja API

Comments
2 min read
CVE-2024-23653: CVE-2024-23653: Build-Time Container Escape in Moby BuildKit via GRPC API Authorization Bypass

CVE-2024-23653: CVE-2024-23653: Build-Time Container Escape in Moby BuildKit via GRPC API Authorization Bypass

Comments
2 min read
CVE-2026-40046: CVE-2026-40046: Integer Overflow and Protocol Smuggling in Apache ActiveMQ MQTT Decoder

CVE-2026-40046: CVE-2026-40046: Integer Overflow and Protocol Smuggling in Apache ActiveMQ MQTT Decoder

Comments
2 min read
CVE-2026-34941: CVE-2026-34941: Heap Out-of-bounds Read in Wasmtime Component String Transcoding

CVE-2026-34941: CVE-2026-34941: Heap Out-of-bounds Read in Wasmtime Component String Transcoding

Comments
2 min read
CVE-2026-34942: CVE-2026-34942: Denial of Service via Unaligned Memory Allocation in Wasmtime Component Model

CVE-2026-34942: CVE-2026-34942: Denial of Service via Unaligned Memory Allocation in Wasmtime Component Model

Comments
2 min read
CVE-2026-34943: CVE-2026-34943: Host-Side Panic and Denial of Service in Wasmtime Dynamic Lifting

CVE-2026-34943: CVE-2026-34943: Host-Side Panic and Denial of Service in Wasmtime Dynamic Lifting

Comments
2 min read
CVE-2026-34944: CVE-2026-34944: Out-of-bounds Read and Denial of Service in Wasmtime Cranelift Backend

CVE-2026-34944: CVE-2026-34944: Out-of-bounds Read and Denial of Service in Wasmtime Cranelift Backend

Comments
2 min read
CVE-2026-34945: CVE-2026-34945: Host Stack Memory Leak via Type Confusion in Wasmtime Winch Compiler

CVE-2026-34945: CVE-2026-34945: Host Stack Memory Leak via Type Confusion in Wasmtime Winch Compiler

Comments
2 min read
CVE-2026-34946: CVE-2026-34946: Host Panic Denial of Service in Wasmtime Winch Compiler

CVE-2026-34946: CVE-2026-34946: Host Panic Denial of Service in Wasmtime Winch Compiler

Comments
2 min read
CVE-2026-23226: CVE-2026-23226: Use-After-Free in Linux Kernel ksmbd Multi-Channel Sessions

CVE-2026-23226: CVE-2026-23226: Use-After-Free in Linux Kernel ksmbd Multi-Channel Sessions

Comments
2 min read
CVE-2026-34971: CVE-2026-34971: Critical Sandbox Escape via Cranelift Miscompilation on AArch64

CVE-2026-34971: CVE-2026-34971: Critical Sandbox Escape via Cranelift Miscompilation on AArch64

Comments
2 min read
CVE-2026-34983: CVE-2026-34983: Use-After-Free in Wasmtime Linker StringPool

CVE-2026-34983: CVE-2026-34983: Use-After-Free in Wasmtime Linker StringPool

Comments
2 min read
CVE-2026-34988: CVE-2026-34988: Cross-Guest Memory Leak in Wasmtime Pooling Allocator

CVE-2026-34988: CVE-2026-34988: Cross-Guest Memory Leak in Wasmtime Pooling Allocator

Comments
2 min read
CVE-2026-35195: CVE-2026-35195: Out-of-Bounds Write in Wasmtime Component Model Transcoding

CVE-2026-35195: CVE-2026-35195: Out-of-Bounds Write in Wasmtime Component Model Transcoding

Comments
2 min read
CVE-2026-39315: CVE-2026-39315: Cross-Site Scripting Filter Bypass in Unhead useHeadSafe()

CVE-2026-39315: CVE-2026-39315: Cross-Site Scripting Filter Bypass in Unhead useHeadSafe()

Comments
2 min read
CVE-2026-40070: CVE-2026-40070: Improper Verification of Cryptographic Signature in bsv-ruby-sdk

CVE-2026-40070: CVE-2026-40070: Improper Verification of Cryptographic Signature in bsv-ruby-sdk

Comments
2 min read
CVE-2026-40069: CVE-2026-40069: Integrity Verification Failure in BSV Ruby SDK ARC Broadcaster

CVE-2026-40069: CVE-2026-40069: Integrity Verification Failure in BSV Ruby SDK ARC Broadcaster

Comments
2 min read
GHSA-CM8V-2VH9-CXF3: GHSA-cm8v-2vh9-cxf3: Remote Code Execution via Incomplete Environment Variable Denylist in OpenClaw

GHSA-CM8V-2VH9-CXF3: GHSA-cm8v-2vh9-cxf3: Remote Code Execution via Incomplete Environment Variable Denylist in OpenClaw

Comments
2 min read
GHSA-9GJV-JVM7-VV2V: GHSA-9GJV-JVM7-VV2V: Improper Access Control Exposes Private Sub-Object Data in Gramps Web API

GHSA-9GJV-JVM7-VV2V: GHSA-9GJV-JVM7-VV2V: Improper Access Control Exposes Private Sub-Object Data in Gramps Web API

Comments
2 min read
CVE-2026-33439: CVE-2026-33439: Pre-Authentication Remote Code Execution in OpenAM via JATO clientSession Deserialization

CVE-2026-33439: CVE-2026-33439: Pre-Authentication Remote Code Execution in OpenAM via JATO clientSession Deserialization

Comments
2 min read
GHSA-3VVQ-Q2QC-7RMP: GHSA-3VVQ-Q2QC-7RMP: Remote Code Execution via Missing Integrity Check in OpenClaw Package Manager

GHSA-3VVQ-Q2QC-7RMP: GHSA-3VVQ-Q2QC-7RMP: Remote Code Execution via Missing Integrity Check in OpenClaw Package Manager

Comments
2 min read
GHSA-CCX3-FW7Q-RR2R: GHSA-ccx3-fw7q-rr2r: Unbounded Base64 Decoding Leading to Denial of Service in OpenClaw

GHSA-CCX3-FW7Q-RR2R: GHSA-ccx3-fw7q-rr2r: Unbounded Base64 Decoding Leading to Denial of Service in OpenClaw

Comments
2 min read
CVE-2026-35041: CVE-2026-35041: Regular Expression Denial of Service in fast-jwt

CVE-2026-35041: CVE-2026-35041: Regular Expression Denial of Service in fast-jwt

Comments
2 min read
GHSA-JF56-MCCX-5F3F: GHSA-JF56-MCCX-5F3F: Indirect Prompt Injection and Agent Compromise in OpenClaw Webhooks

GHSA-JF56-MCCX-5F3F: GHSA-JF56-MCCX-5F3F: Indirect Prompt Injection and Agent Compromise in OpenClaw Webhooks

Comments
2 min read
GHSA-7437-7HG8-FRRW: GHSA-7437-7HG8-FRRW: Remote Code Execution via Build Tool Environment Injection in OpenClaw

GHSA-7437-7HG8-FRRW: GHSA-7437-7HG8-FRRW: Remote Code Execution via Build Tool Environment Injection in OpenClaw

Comments
2 min read
CVE-2026-21413: CVE-2026-21413: Heap-Based Buffer Overflow in LibRaw Lossless JPEG Decoder

CVE-2026-21413: CVE-2026-21413: Heap-Based Buffer Overflow in LibRaw Lossless JPEG Decoder

Comments
2 min read
CVE-2026-20911: CVE-2026-20911: Remote Code Execution via Heap-Based Buffer Overflow in LibRaw HuffTable::initval

CVE-2026-20911: CVE-2026-20911: Remote Code Execution via Heap-Based Buffer Overflow in LibRaw HuffTable::initval

Comments
2 min read
CVE-2026-20889: CVE-2026-20889: Heap-based Buffer Overflow in LibRaw X3F Thumbnail Parser

CVE-2026-20889: CVE-2026-20889: Heap-based Buffer Overflow in LibRaw X3F Thumbnail Parser

Comments
2 min read
CVE-2026-39882: CVE-2026-39882: Memory Exhaustion Denial of Service in OpenTelemetry-Go OTLP HTTP Exporters

CVE-2026-39882: CVE-2026-39882: Memory Exhaustion Denial of Service in OpenTelemetry-Go OTLP HTTP Exporters

Comments
2 min read
CVE-2026-39883: CVE-2026-39883: PATH Hijacking via Insecure kenv Execution in OpenTelemetry Go SDK

CVE-2026-39883: CVE-2026-39883: PATH Hijacking via Insecure kenv Execution in OpenTelemetry Go SDK

Comments
2 min read
CVE-2026-39885: CVE-2026-39885: Server-Side Request Forgery and Local File Inclusion in FrontMCP mcp-from-openapi

CVE-2026-39885: CVE-2026-39885: Server-Side Request Forgery and Local File Inclusion in FrontMCP mcp-from-openapi

Comments
2 min read
CVE-2026-39901: CVE-2026-39901: Authorization Bypass and Transaction Integrity Flaw in monetr

CVE-2026-39901: CVE-2026-39901: Authorization Bypass and Transaction Integrity Flaw in monetr

Comments
2 min read
CVE-2026-39892: CVE-2026-39892: Out-of-bounds Read in Python Cryptography via Non-Contiguous Buffers

CVE-2026-39892: CVE-2026-39892: Out-of-bounds Read in Python Cryptography via Non-Contiguous Buffers

Comments
2 min read
GHSA-XRW6-GWF8-VVR9: GHSA-XRW6-GWF8-VVR9: Signal Spoofing and Resource Exhaustion in Tmds.DBus

GHSA-XRW6-GWF8-VVR9: GHSA-XRW6-GWF8-VVR9: Signal Spoofing and Resource Exhaustion in Tmds.DBus

Comments
2 min read
GHSA-HWR4-MQ23-WCV5: GHSA-HWR4-MQ23-WCV5: Cache Key Collision and Authorization Bypass in Mercure Hub

GHSA-HWR4-MQ23-WCV5: GHSA-HWR4-MQ23-WCV5: Cache Key Collision and Authorization Bypass in Mercure Hub

Comments
2 min read
loading...