DEV Community

#cve

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

A SQL escape is not a shell escape: OS command injection in GOautodial goAPIv2

Comments
5 min read
CVE-2026-24031 Analysis — Dovecot SQL-Based Authentication Bypass (an auth_username_chars Regression)

CVE-2026-24031 Analysis — Dovecot SQL-Based Authentication Bypass (an auth_username_chars Regression)

1
Comments
6 min read
BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

BREAKING: CVE-2026-18500 - @fastify/jwt Key Override Authorization Bypass

Comments
2 min read
CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

CVE-2026-53561: Apache Hive HiveServer2 SAML Bearer Impersonation

Comments
5 min read
CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

CVE-2026-80104: DB-GPT Skill Upload Path Traversal (and Sibling CVE-2026-73034)

Comments
4 min read
CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

CVE-2026-69112: Hugging Face Accelerate Path Traversal Lets Attackers Read Arbitrary Files

Comments
4 min read
CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

CVE-2026-45018: Chainlit MCP stdio unauthenticated RCE (and sibling CVE-2026-45019)

Comments 1
3 min read
CVE-2026-48854: CVE-2026-48854: Unauthenticated Denial of Service via Resource Exhaustion in elixir-grpc Server

CVE-2026-48854: CVE-2026-48854: Unauthenticated Denial of Service via Resource Exhaustion in elixir-grpc Server

Comments
2 min read
Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Comments
4 min read
GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles

GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles

Comments
2 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

Comments 2
6 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

Comments
6 min read
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution

Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution

Comments
6 min read
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation

Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation

Comments
4 min read
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

Comments
2 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.