DEV Community

# vulnerability

Discussions about specific security vulnerabilities and CVEs.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Trivy Vulnerability Scanner Compromised in Supply Chain Attack: Mitigation Steps and User Guidance

Trivy Vulnerability Scanner Compromised in Supply Chain Attack: Mitigation Steps and User Guidance

1
Comments
8 min read
AI System's Internal Logic Exposed via Creative Querying: Enhanced Access Restrictions Proposed

AI System's Internal Logic Exposed via Creative Querying: Enhanced Access Restrictions Proposed

Comments
13 min read
Claude Code CLI Vulnerability: Malicious Configs Bypass Trust Dialog, Enabling Unauthorized Permission Elevation

Claude Code CLI Vulnerability: Malicious Configs Bypass Trust Dialog, Enabling Unauthorized Permission Elevation

Comments
10 min read
Claude Code CLI Fixed: Configuration Loading Order Defect Resolved to Prevent Unauthorized Permission Elevation

Claude Code CLI Fixed: Configuration Loading Order Defect Resolved to Prevent Unauthorized Permission Elevation

Comments
8 min read
Trivy Scanner Compromised Again: Malicious Code Found in v0.69.4 and GitHub Actions, Raising Security Concerns

Trivy Scanner Compromised Again: Malicious Code Found in v0.69.4 and GitHub Actions, Raising Security Concerns

Comments
8 min read
CVE-2025-9318: SQL Injection in Quiz and Survey Master — Full Audit

CVE-2025-9318: SQL Injection in Quiz and Survey Master — Full Audit

2
Comments
3 min read
Eight Critical Bugs, One Day: Anatomy of an AI Agent Security Audit

Eight Critical Bugs, One Day: Anatomy of an AI Agent Security Audit

Comments
3 min read
MediaTek Audio DSP Vulnerability: How a Nothing Phone Could Have Been Hacked (Except It Wasn't)

MediaTek Audio DSP Vulnerability: How a Nothing Phone Could Have Been Hacked (Except It Wasn't)

Comments
7 min read
Windows Vulnerability CVE-2025-59284: Incomplete Patch Enables NetNTLM Hash Phishing During Archive Extraction

Windows Vulnerability CVE-2025-59284: Incomplete Patch Enables NetNTLM Hash Phishing During Archive Extraction

Comments
14 min read
Glassworm Is Back: The Invisible Unicode Attack Hiding in Your Code

Glassworm Is Back: The Invisible Unicode Attack Hiding in Your Code

Comments
7 min read
Five Chrome Zero-Days in Two Weeks: The Most Aggressive Browser Attack Wave of 2024

Five Chrome Zero-Days in Two Weeks: The Most Aggressive Browser Attack Wave of 2024

1
Comments
6 min read
CVE-2026-20435: How a MediaTek Boot Chain Flaw Exposes Crypto Wallets on 25% of Android Phones

CVE-2026-20435: How a MediaTek Boot Chain Flaw Exposes Crypto Wallets on 25% of Android Phones

1
Comments
5 min read
Zombie ZIP Vulnerability Enables Malware to Bypass 95% of Antivirus Software, Requiring Urgent Security Updates

Zombie ZIP Vulnerability Enables Malware to Bypass 95% of Antivirus Software, Requiring Urgent Security Updates

Comments
8 min read
EPSS Explained: Why Exploit Prediction Scoring Changes Everything for Vulnerability Prioritization

EPSS Explained: Why Exploit Prediction Scoring Changes Everything for Vulnerability Prioritization

Comments
2 min read
Denial of Service in yauzl 3.2.0: One Zip File Crashes the Library Behind VS Code and Electron

Denial of Service in yauzl 3.2.0: One Zip File Crashes the Library Behind VS Code and Electron

Comments
5 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.