Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
cve
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2
Santosh Kumar Puppala
Santosh Kumar Puppala
Santosh Kumar Puppala
Follow
Sep 2
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2
#
security
#
cve
#
php
#
appsec
Comments
Add Comment
5 min read
CVE-2026-24031 Analysis — Dovecot SQL-Based Authentication Bypass (an auth_username_chars Regression)
GUIDANCE WHITE
GUIDANCE WHITE
GUIDANCE WHITE
Follow
Sep 2
CVE-2026-24031 Analysis — Dovecot SQL-Based Authentication Bypass (an auth_username_chars Regression)
#
database
#
vulnerabilities
#
cve
#
sql
1
 reaction
Comments
Add Comment
6 min read
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
Michael Kantor
Michael Kantor
Michael Kantor
Follow
for
HOL (Hashgraph Online)
Aug 31
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass
#
cve
#
security
#
vulnerability
#
fastifyjwt
Comments
Add Comment
2 min read
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
Michael Kantor
Michael Kantor
Michael Kantor
Follow
for
HOL (Hashgraph Online)
Aug 31
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation
#
cve
#
apachehive
#
authn
#
ssrf
Comments
Add Comment
5 min read
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
Michael Kantor
Michael Kantor
Michael Kantor
Follow
for
HOL (Hashgraph Online)
Aug 31
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)
#
cve
#
dbgpt
#
pathtraversal
#
ai
Comments
Add Comment
4 min read
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
Michael Kantor
Michael Kantor
Michael Kantor
Follow
for
HOL (Hashgraph Online)
Aug 31
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files
#
cve
#
security
#
vulnerability
#
accelerate
Comments
Add Comment
4 min read
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
Michael Kantor
Michael Kantor
Michael Kantor
Follow
for
HOL (Hashgraph Online)
Aug 31
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)
#
cve
#
chainlit
#
mcp
#
rce
Comments
1
 comment
3 min read
CVE-2026-48854: CVE-2026-48854: Unauthenticated Denial of Service via Resource Exhaustion in elixir-grpc Server
CVE Reports
CVE Reports
CVE Reports
Follow
Aug 26
CVE-2026-48854: CVE-2026-48854: Unauthenticated Denial of Service via Resource Exhaustion in elixir-grpc Server
#
security
#
cve
#
cybersecurity
Comments
Add Comment
2 min read
Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure
Huynh Kien Minh
Huynh Kien Minh
Huynh Kien Minh
Follow
Aug 22
Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure
#
security
#
wordpress
#
cve
#
infosec
Comments
Add Comment
4 min read
GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles
CVE Reports
CVE Reports
CVE Reports
Follow
Aug 21
GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles
#
security
#
cve
#
cybersecurity
#
ghsa
Comments
Add Comment
2 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)
Santosh Kumar Puppala
Santosh Kumar Puppala
Santosh Kumar Puppala
Follow
Aug 7
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)
#
security
#
cve
#
linux
#
appsec
Comments
2
 comments
6 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network
Santosh Kumar Puppala
Santosh Kumar Puppala
Santosh Kumar Puppala
Follow
Aug 7
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network
#
security
#
cve
#
ruby
#
appsec
Comments
Add Comment
6 min read
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution
Huynh Kien Minh
Huynh Kien Minh
Huynh Kien Minh
Follow
Aug 1
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution
#
cve
#
wordpress
#
security
#
rce
Comments
Add Comment
6 min read
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation
Huynh Kien Minh
Huynh Kien Minh
Huynh Kien Minh
Follow
Aug 1
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation
#
security
#
wordpress
#
cve
#
bugbounty
Comments
Add Comment
4 min read
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer
CVE Reports
CVE Reports
CVE Reports
Follow
Jul 23
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer
#
security
#
cve
#
cybersecurity
#
ghsa
Comments
Add Comment
2 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account