DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-25611: CVE-2026-25611: Pre-Authentication Denial of Service via Asymmetric Memory Exhaustion in MongoDB Server

CVE-2026-25611: CVE-2026-25611: Pre-Authentication Denial of Service via Asymmetric Memory Exhaustion in MongoDB Server

Comments
2 min read
CVE-2026-30852: CVE-2026-30852: Double-Expansion Information Disclosure in Caddy vars_regexp

CVE-2026-30852: CVE-2026-30852: Double-Expansion Information Disclosure in Caddy vars_regexp

Comments
2 min read
CVE-2026-30855: CVE-2026-30855: Broken Object Level Authorization in Tencent WeKnora

CVE-2026-30855: CVE-2026-30855: Broken Object Level Authorization in Tencent WeKnora

Comments
2 min read
CVE-2026-30856: CVE-2026-30856: Tool Execution Hijacking and Indirect Prompt Injection in Tencent WeKnora

CVE-2026-30856: CVE-2026-30856: Tool Execution Hijacking and Indirect Prompt Injection in Tencent WeKnora

Comments
2 min read
CVE-2026-30857: CVE-2026-30857: Unauthorized Cross-Tenant Knowledge Base Cloning in WeKnora

CVE-2026-30857: CVE-2026-30857: Unauthorized Cross-Tenant Knowledge Base Cloning in WeKnora

Comments
2 min read
CVE-2026-30858: CVE-2026-30858: Server-Side Request Forgery via DNS Rebinding in Tencent WeKnora

CVE-2026-30858: CVE-2026-30858: Server-Side Request Forgery via DNS Rebinding in Tencent WeKnora

Comments
2 min read
CVE-2026-30859: CVE-2026-30859: Cross-Tenant Data Exfiltration via Broken Access Control in Tencent WeKnora

CVE-2026-30859: CVE-2026-30859: Cross-Tenant Data Exfiltration via Broken Access Control in Tencent WeKnora

Comments
2 min read
CVE-2026-30860: CVE-2026-30860: Remote Code Execution via SQL Injection Bypass in Tencent WeKnora

CVE-2026-30860: CVE-2026-30860: Remote Code Execution via SQL Injection Bypass in Tencent WeKnora

Comments
2 min read
CVE-2026-30861: CVE-2026-30861: Remote Code Execution via Incomplete Command Blacklist in Tencent WeKnora

CVE-2026-30861: CVE-2026-30861: Remote Code Execution via Incomplete Command Blacklist in Tencent WeKnora

Comments
2 min read
GHSA-5Q8V-J673-M5V4: GHSA-5Q8V-J673-M5V4: Insecure Direct Object Reference and Authorization Bypass in Firefly III API

GHSA-5Q8V-J673-M5V4: GHSA-5Q8V-J673-M5V4: Insecure Direct Object Reference and Authorization Bypass in Firefly III API

Comments
2 min read
GHSA-G9RG-8VQ5-MPWM: GHSA-G9RG-8VQ5-MPWM: Cross-Origin Memory Theft and Information Disclosure in mcp-memory-service

GHSA-G9RG-8VQ5-MPWM: GHSA-G9RG-8VQ5-MPWM: Cross-Origin Memory Theft and Information Disclosure in mcp-memory-service

Comments
2 min read
GHSA-2H2P-MVFX-868W: GHSA-2H2P-MVFX-868W: Critical Path Traversal and Authentication Bypass in SiYuan

GHSA-2H2P-MVFX-868W: GHSA-2H2P-MVFX-868W: Critical Path Traversal and Authentication Bypass in SiYuan

Comments
2 min read
GHSA-Q6WC-XX4M-92FJ: GHSA-q6wc-xx4m-92fj: Improper Authorization in PowerSync Service Sync Streams

GHSA-Q6WC-XX4M-92FJ: GHSA-q6wc-xx4m-92fj: Improper Authorization in PowerSync Service Sync Streams

Comments
2 min read
GHSA-6W2R-CFPC-23R5: GHSA-6w2r-cfpc-23r5: Unauthenticated IDOR in AVideo Playlist Endpoints

GHSA-6W2R-CFPC-23R5: GHSA-6w2r-cfpc-23r5: Unauthenticated IDOR in AVideo Playlist Endpoints

Comments
2 min read
GHSA-C8M8-3JCR-6RJ5: GHSA-c8m8-3jcr-6rj5: Hardcoded JWT Signing Secret in FUXA

GHSA-C8M8-3JCR-6RJ5: GHSA-c8m8-3jcr-6rj5: Hardcoded JWT Signing Secret in FUXA

Comments
2 min read
GHSA-6F6W-6J58-RQ76: GHSA-6f6w-6j58-rq76: Shell Injection in shescape via Symlink Chain Misidentification

GHSA-6F6W-6J58-RQ76: GHSA-6f6w-6j58-rq76: Shell Injection in shescape via Symlink Chain Misidentification

Comments
2 min read
GHSA-V53H-F6M7-XCGM: GHSA-V53H-F6M7-XCGM: Remote Code Execution in psf/black GitHub Action via pyproject.toml

GHSA-V53H-F6M7-XCGM: GHSA-V53H-F6M7-XCGM: Remote Code Execution in psf/black GitHub Action via pyproject.toml

Comments
2 min read
GHSA-QR2G-P6Q7-W82M: GHSA-qr2g-p6q7-w82m: Critical Payment Verification Bypass in Coinbase x402 SDK (Solana)

GHSA-QR2G-P6Q7-W82M: GHSA-qr2g-p6q7-w82m: Critical Payment Verification Bypass in Coinbase x402 SDK (Solana)

1
Comments
2 min read
GHSA-4J36-39GM-8VQ8: OneUptime Synthetic Monitor RCE via Sandbox Escape

GHSA-4J36-39GM-8VQ8: OneUptime Synthetic Monitor RCE via Sandbox Escape

Comments
2 min read
GHSA-PM4J-7R4Q-CCG8: GHSA-PM4J-7R4Q-CCG8: State Inconsistency in Soroban Host Storage Key Conversion

GHSA-PM4J-7R4Q-CCG8: GHSA-PM4J-7R4Q-CCG8: State Inconsistency in Soroban Host Storage Key Conversion

Comments
2 min read
GHSA-H343-GG57-2Q67: CVE-2026-27574: Remote Code Execution in OneUptime Probe via VM Sandbox Escape

GHSA-H343-GG57-2Q67: CVE-2026-27574: Remote Code Execution in OneUptime Probe via VM Sandbox Escape

Comments
2 min read
CVE-2026-30835: CVE-2026-30835: Database Metadata Leak via Malformed Regex in Parse Server

CVE-2026-30835: CVE-2026-30835: Database Metadata Leak via Malformed Regex in Parse Server

Comments
2 min read
CVE-2026-26018: CVE-2026-26018: Remote Denial of Service in CoreDNS Loop Detection Plugin via Predictable PRNG

CVE-2026-26018: CVE-2026-26018: Remote Denial of Service in CoreDNS Loop Detection Plugin via Predictable PRNG

Comments
2 min read
CVE-2026-29064: CVE-2026-29064: Path Traversal via Symlink Extraction in Zarf

CVE-2026-29064: CVE-2026-29064: Path Traversal via Symlink Extraction in Zarf

Comments
2 min read
CVE-2026-30228: CVE-2026-30228: Authorization Bypass in Parse Server Files API via readOnlyMasterKey

CVE-2026-30228: CVE-2026-30228: Authorization Bypass in Parse Server Files API via readOnlyMasterKey

Comments
2 min read
CVE-2026-30241: CVE-2026-30241: Missing Query Depth Validation in Mercurius GraphQL Subscriptions

CVE-2026-30241: CVE-2026-30241: Missing Query Depth Validation in Mercurius GraphQL Subscriptions

1
Comments
2 min read
CVE-2026-30229: CVE-2026-30229: Privilege Escalation via Read-Only Master Key in Parse Server

CVE-2026-30229: CVE-2026-30229: Privilege Escalation via Read-Only Master Key in Parse Server

Comments
2 min read
GHSA-9R75-G2CR-3H76: GHSA-9r75-g2cr-3h76: Predictable Webhook Tokens in Vercel Workflow

GHSA-9R75-G2CR-3H76: GHSA-9r75-g2cr-3h76: Predictable Webhook Tokens in Vercel Workflow

Comments
2 min read
CVE-2026-26017: CVE-2026-26017: CoreDNS ACL Bypass via TOCTOU in Plugin Chain

CVE-2026-26017: CVE-2026-26017: CoreDNS ACL Bypass via TOCTOU in Plugin Chain

Comments
2 min read
CVE-2026-3419: CVE-2026-3419: Content-Type Validation Bypass in Fastify via Regex Anchor Missing

CVE-2026-3419: CVE-2026-3419: Content-Type Validation Bypass in Fastify via Regex Anchor Missing

Comments
2 min read
CVE-2026-29783: CVE-2026-29783: Command Injection via Bash Parameter Expansion in GitHub Copilot CLI

CVE-2026-29783: CVE-2026-29783: Command Injection via Bash Parameter Expansion in GitHub Copilot CLI

Comments
2 min read
GHSA-FWHJ-785H-43HH: GHSA-FWHJ-785H-43HH: Denial of Service via Null Pointer Dereference in OliveTin

GHSA-FWHJ-785H-43HH: GHSA-FWHJ-785H-43HH: Denial of Service via Null Pointer Dereference in OliveTin

Comments
2 min read
CVE-2026-2833: CVE-2026-2833: HTTP Request Smuggling via Premature Upgrade in Cloudflare Pingora

CVE-2026-2833: CVE-2026-2833: HTTP Request Smuggling via Premature Upgrade in Cloudflare Pingora

Comments
2 min read
CVE-2026-2835: CVE-2026-2835: HTTP Request Smuggling in Cloudflare Pingora

CVE-2026-2835: CVE-2026-2835: HTTP Request Smuggling in Cloudflare Pingora

Comments
2 min read
GHSA-7RHV-H82H-VPJH: CVE-2026-30777: MFA Bypass in EC-CUBE Administrative Interface

GHSA-7RHV-H82H-VPJH: CVE-2026-30777: MFA Bypass in EC-CUBE Administrative Interface

Comments
2 min read
GHSA-MH23-RW7F-V5PQ: GHSA-MH23-RW7F-V5PQ: Malicious 'time-sync' Crate Exfiltrating Environment Secrets

GHSA-MH23-RW7F-V5PQ: GHSA-MH23-RW7F-V5PQ: Malicious 'time-sync' Crate Exfiltrating Environment Secrets

1
Comments
2 min read
CVE-2025-11143: CVE-2025-11143: URI Parsing Differential in Eclipse Jetty

CVE-2025-11143: CVE-2025-11143: URI Parsing Differential in Eclipse Jetty

Comments
2 min read
GHSA-X2G5-FVC2-GQVP: GHSA-X2G5-FVC2-GQVP: Insufficient Bcrypt Salt Rounds in Flowise

GHSA-X2G5-FVC2-GQVP: GHSA-X2G5-FVC2-GQVP: Insufficient Bcrypt Salt Rounds in Flowise

Comments
2 min read
GHSA-JC5M-WRP2-QQ38: GHSA-jc5m-wrp2-qq38: PII Disclosure via Flowise Forgot Password Endpoint

GHSA-JC5M-WRP2-QQ38: GHSA-jc5m-wrp2-qq38: PII Disclosure via Flowise Forgot Password Endpoint

Comments
2 min read
GHSA-5R2P-PJR8-7FH7: Remote Code Execution in AWS SageMaker Python SDK via Unsafe eval()

GHSA-5R2P-PJR8-7FH7: Remote Code Execution in AWS SageMaker Python SDK via Unsafe eval()

Comments
2 min read
CVE-2026-1605: CVE-2026-1605: Native Memory Leak in Eclipse Jetty GzipHandler

CVE-2026-1605: CVE-2026-1605: Native Memory Leak in Eclipse Jetty GzipHandler

Comments
2 min read
CVE-2026-2836: CVE-2026-2836: Host-Blind Cache Poisoning in Cloudflare Pingora

CVE-2026-2836: CVE-2026-2836: Host-Blind Cache Poisoning in Cloudflare Pingora

Comments
2 min read
CVE-2026-26196: CVE-2026-26196: Sensitive API Token Exposure via URL Query Parameters in Gogs

CVE-2026-26196: CVE-2026-26196: Sensitive API Token Exposure via URL Query Parameters in Gogs

Comments
2 min read
CVE-2026-26194: CVE-2026-26194: Command Option Injection in Gogs Release Deletion

CVE-2026-26194: CVE-2026-26194: Command Option Injection in Gogs Release Deletion

1
Comments
2 min read
CVE-2026-25048: CVE-2026-25048: Stack Exhaustion Denial of Service in xgrammar EBNF Parser

CVE-2026-25048: CVE-2026-25048: Stack Exhaustion Denial of Service in xgrammar EBNF Parser

Comments
2 min read
CVE-2026-27944: CVE-2026-27944: Unauthenticated Backup Download and Encryption Key Disclosure in Nginx UI

CVE-2026-27944: CVE-2026-27944: Unauthenticated Backup Download and Encryption Key Disclosure in Nginx UI

Comments
2 min read
CVE-2026-20122: CVE-2026-20122: Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API

CVE-2026-20122: CVE-2026-20122: Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API

Comments
2 min read
CVE-2026-20079: CVE-2026-20079: Authentication Bypass & RCE in Cisco Secure FMC

CVE-2026-20079: CVE-2026-20079: Authentication Bypass & RCE in Cisco Secure FMC

Comments
2 min read
CVE-2026-20131: CVE-2026-20131: Unauthenticated RCE in Cisco Secure Firewall Management Center via Java Deserialization

CVE-2026-20131: CVE-2026-20131: Unauthenticated RCE in Cisco Secure Firewall Management Center via Java Deserialization

Comments
2 min read
CVE-2025-15558: CVE-2025-15558: Local Privilege Escalation via Uncontrolled Search Path in Docker CLI for Windows

CVE-2025-15558: CVE-2025-15558: Local Privilege Escalation via Uncontrolled Search Path in Docker CLI for Windows

Comments
2 min read
GHSA-HHJV-JQ77-CMVX: GHSA-HHJV-JQ77-CMVX: Android Shell Blocklist Bypass in Zeptoclaw via Argument Permutation

GHSA-HHJV-JQ77-CMVX: GHSA-HHJV-JQ77-CMVX: Android Shell Blocklist Bypass in Zeptoclaw via Argument Permutation

Comments
2 min read
CVE-2026-22719: CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations

CVE-2026-22719: CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations

Comments
2 min read
GHSA-5WP8-Q9MX-8JX8: GHSA-5WP8-Q9MX-8JX8: Critical Shell Security Bypass in Zeptoclaw AI Runtime

GHSA-5WP8-Q9MX-8JX8: GHSA-5WP8-Q9MX-8JX8: Critical Shell Security Bypass in Zeptoclaw AI Runtime

Comments
2 min read
GHSA-9M84-WC28-W895: GHSA-9m84-wc28-w895: Incomplete CSRF Protection and Weak OTC Binding in Ghost

GHSA-9M84-WC28-W895: GHSA-9m84-wc28-w895: Incomplete CSRF Protection and Weak OTC Binding in Ghost

Comments
2 min read
GHSA-XHW7-JHMP-J62J: GHSA-XHW7-JHMP-J62J: Malicious 'dnp3times' Crate Exfiltrates Secrets via Typosquatting

GHSA-XHW7-JHMP-J62J: GHSA-XHW7-JHMP-J62J: Malicious 'dnp3times' Crate Exfiltrates Secrets via Typosquatting

Comments
2 min read
GHSA-QFFP-2RHF-9H96: GHSA-qffp-2rhf-9h96: Hardlink Path Traversal in node-tar via Drive-Relative Paths

GHSA-QFFP-2RHF-9H96: GHSA-qffp-2rhf-9h96: Hardlink Path Traversal in node-tar via Drive-Relative Paths

Comments
2 min read
CVE-2026-3125: CVE-2026-3125: SSRF via Differential Path Normalization in @opennextjs/cloudflare

CVE-2026-3125: CVE-2026-3125: SSRF via Differential Path Normalization in @opennextjs/cloudflare

Comments
2 min read
GHSA-W75W-9QV4-J5XJ: GHSA-W75W-9QV4-J5XJ: Path Traversal in dbt-common Archive Extraction

GHSA-W75W-9QV4-J5XJ: GHSA-W75W-9QV4-J5XJ: Path Traversal in dbt-common Archive Extraction

1
Comments
2 min read
GHSA-V2X6-WWFW-R2RQ: GHSA-v2x6-wwfw-r2rq: Path Traversal and Parameter Injection in Agentgateway

GHSA-V2X6-WWFW-R2RQ: GHSA-v2x6-wwfw-r2rq: Path Traversal and Parameter Injection in Agentgateway

Comments
2 min read
CVE-2026-3520: CVE-2026-3520: Denial of Service via Uncontrolled Recursion in Multer

CVE-2026-3520: CVE-2026-3520: Denial of Service via Uncontrolled Recursion in Multer

Comments
2 min read
loading...