DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
GHSA-8M29-FPQ5-89JJ: GHSA-8M29-FPQ5-89JJ: Consensus Divergence in Zebra via Improper Sighash Hash-Type Handling

GHSA-8M29-FPQ5-89JJ: GHSA-8M29-FPQ5-89JJ: Consensus Divergence in Zebra via Improper Sighash Hash-Type Handling

Comments
2 min read
CVE-2026-35402: CVE-2026-35402: Improper Access Control in mcp-neo4j-cypher via Stored Procedure Bypass

CVE-2026-35402: CVE-2026-35402: Improper Access Control in mcp-neo4j-cypher via Stored Procedure Bypass

Comments
2 min read
GHSA-JP74-MFRX-3QVH: GHSA-jp74-mfrx-3qvh: Authenticated SQL Injection in Saltcorn Mobile Sync Endpoints

GHSA-JP74-MFRX-3QVH: GHSA-jp74-mfrx-3qvh: Authenticated SQL Injection in Saltcorn Mobile Sync Endpoints

Comments
2 min read
GHSA-92JP-89MQ-4374: GHSA-92JP-89MQ-4374: Unauthenticated Sandbox Access and Context Leakage in OpenClaw

GHSA-92JP-89MQ-4374: GHSA-92JP-89MQ-4374: Unauthenticated Sandbox Access and Context Leakage in OpenClaw

Comments
2 min read
GHSA-3G92-F9CH-QJCM: GHSA-3G92-F9CH-QJCM: Cryptographic Hash Collision in Plonky3 p3-symmetric Sponge Construction

GHSA-3G92-F9CH-QJCM: GHSA-3G92-F9CH-QJCM: Cryptographic Hash Collision in Plonky3 p3-symmetric Sponge Construction

Comments
2 min read
GHSA-FV5P-P927-QMXR: GHSA-FV5P-P927-QMXR: SSRF via Redirect Bypass in LangChain HTMLHeaderTextSplitter

GHSA-FV5P-P927-QMXR: GHSA-FV5P-P927-QMXR: SSRF via Redirect Bypass in LangChain HTMLHeaderTextSplitter

Comments
2 min read
CVE-2026-26171: CVE-2026-26171: Denial of Service in .NET System.Security.Cryptography.Xml

CVE-2026-26171: CVE-2026-26171: Denial of Service in .NET System.Security.Cryptography.Xml

Comments
2 min read
CVE-2026-32178: CVE-2026-32178: SMTP Header Injection and Protocol Smuggling in .NET System.Net.Mail

CVE-2026-32178: CVE-2026-32178: SMTP Header Injection and Protocol Smuggling in .NET System.Net.Mail

Comments
2 min read
CVE-2026-32203: CVE-2026-32203: Stack-based Buffer Overflow in .NET Cryptography XML Processing

CVE-2026-32203: CVE-2026-32203: Stack-based Buffer Overflow in .NET Cryptography XML Processing

Comments
2 min read
CVE-2026-33116: CVE-2026-33116: Denial of Service via XML Encryption Circular References in .NET

CVE-2026-33116: CVE-2026-33116: Denial of Service via XML Encryption Circular References in .NET

Comments
2 min read
GHSA-R7W7-9XR2-QQ2R: GHSA-R7W7-9XR2-QQ2R: Server-Side Request Forgery via DNS Rebinding in langchain-openai

GHSA-R7W7-9XR2-QQ2R: GHSA-R7W7-9XR2-QQ2R: Server-Side Request Forgery via DNS Rebinding in langchain-openai

Comments
2 min read
GHSA-F3G8-9XV5-77GV: GHSA-f3g8-9xv5-77gv: Open Redirect in Saltcorn via Incomplete URL Validation

GHSA-F3G8-9XV5-77GV: GHSA-f3g8-9xv5-77gv: Open Redirect in Saltcorn via Incomplete URL Validation

Comments
2 min read
CVE-2026-6270: CVE-2026-6270: Authentication Bypass via Middleware Interpretation Conflict in Fastify Middie

CVE-2026-6270: CVE-2026-6270: Authentication Bypass via Middleware Interpretation Conflict in Fastify Middie

Comments
2 min read
CVE-2026-39857: CVE-2026-39857: Information Disclosure via Authorization Bypass in ApostropheCMS REST API

CVE-2026-39857: CVE-2026-39857: Information Disclosure via Authorization Bypass in ApostropheCMS REST API

Comments
2 min read
CVE-2026-33824: CVE-2026-33824: Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

CVE-2026-33824: CVE-2026-33824: Windows Internet Key Exchange (IKE) Service Extensions Remote Code Execution Vulnerability

Comments
2 min read
GHSA-33R3-4WHC-44C2: GHSA-33R3-4WHC-44C2: Path Traversal and Arbitrary File Write in vite-plus/binding

GHSA-33R3-4WHC-44C2: GHSA-33R3-4WHC-44C2: Path Traversal and Arbitrary File Write in vite-plus/binding

Comments
2 min read
CVE-2026-33805: CVE-2026-33805: Connection Header Abuse in @fastify/reply-from and @fastify/http-proxy

CVE-2026-33805: CVE-2026-33805: Connection Header Abuse in @fastify/reply-from and @fastify/http-proxy

Comments
2 min read
CVE-2026-33807: CVE-2026-33807: Middleware Bypass via Path Interpretation Conflict in @fastify/express

CVE-2026-33807: CVE-2026-33807: Middleware Bypass via Path Interpretation Conflict in @fastify/express

Comments
2 min read
CVE-2026-40175: CVE-2026-40175: Header Injection in Axios via Prototype Pollution Gadget

CVE-2026-40175: CVE-2026-40175: Header Injection in Axios via Prototype Pollution Gadget

Comments
2 min read
CVE-2026-33808: CVE-2026-33808: Authentication Bypass via Path Normalization Drift in @fastify/express

CVE-2026-33808: CVE-2026-33808: Authentication Bypass via Path Normalization Drift in @fastify/express

Comments
2 min read
GHSA-VP22-38M5-R39R: CVE-2026-33139: Arbitrary Code Execution via Sandbox Bypass in PySpector Plugin Validation

GHSA-VP22-38M5-R39R: CVE-2026-33139: Arbitrary Code Execution via Sandbox Bypass in PySpector Plugin Validation

Comments
2 min read
CVE-2026-33825: CVE-2026-33825: Local Privilege Escalation via TOCTOU in Microsoft Defender Signature Updates (BlueHammer)

CVE-2026-33825: CVE-2026-33825: Local Privilege Escalation via TOCTOU in Microsoft Defender Signature Updates (BlueHammer)

Comments
2 min read
GHSA-RR7J-V2Q5-CHGV: GHSA-RR7J-V2Q5-CHGV: Streaming Token Redaction Bypass in LangSmith SDK

GHSA-RR7J-V2Q5-CHGV: GHSA-RR7J-V2Q5-CHGV: Streaming Token Redaction Bypass in LangSmith SDK

Comments
2 min read
CVE-2026-20147: CVE-2026-20147: Authenticated Remote Code Execution in Cisco Identity Services Engine (ISE)

CVE-2026-20147: CVE-2026-20147: Authenticated Remote Code Execution in Cisco Identity Services Engine (ISE)

Comments
2 min read
CVE-2026-32176: CVE-2026-32176: Elevation of Privilege via SQL Injection in Microsoft SQL Server

CVE-2026-32176: CVE-2026-32176: Elevation of Privilege via SQL Injection in Microsoft SQL Server

Comments
2 min read
CVE-2026-32167: CVE-2026-32167: Microsoft SQL Server Elevation of Privilege via Internal SQL Injection

CVE-2026-32167: CVE-2026-32167: Microsoft SQL Server Elevation of Privilege via Internal SQL Injection

Comments
2 min read
CVE-2026-33120: CVE-2026-33120: Remote Code Execution via Untrusted Pointer Dereference in Microsoft SQL Server

CVE-2026-33120: CVE-2026-33120: Remote Code Execution via Untrusted Pointer Dereference in Microsoft SQL Server

Comments
2 min read
GHSA-2689-5P89-6J3J: GHSA-2689-5P89-6J3J: Stack-Based Out-of-Bounds Write in UEFI Firmware Parser Tiano Decompressor

GHSA-2689-5P89-6J3J: GHSA-2689-5P89-6J3J: Stack-Based Out-of-Bounds Write in UEFI Firmware Parser Tiano Decompressor

Comments
2 min read
GHSA-5VJQ-5JMG-39XQ: GHSA-5VJQ-5JMG-39XQ: Remote Code Execution in Renovate via Bazel Lockfile Maintenance

GHSA-5VJQ-5JMG-39XQ: GHSA-5VJQ-5JMG-39XQ: Remote Code Execution in Renovate via Bazel Lockfile Maintenance

Comments
2 min read
GHSA-HM2W-VR2P-HQ7W: GHSA-HM2W-VR2P-HQ7W: Heap Out-of-Bounds Write in uefi-firmware-parser Tiano Decompressor

GHSA-HM2W-VR2P-HQ7W: GHSA-HM2W-VR2P-HQ7W: Heap Out-of-Bounds Write in uefi-firmware-parser Tiano Decompressor

Comments
2 min read
GHSA-JJ6C-8H6C-HPPX: GHSA-JJ6C-8H6C-HPPX: Uncontrolled Resource Consumption in pypdf via Malformed PDF Streams

GHSA-JJ6C-8H6C-HPPX: GHSA-JJ6C-8H6C-HPPX: Uncontrolled Resource Consumption in pypdf via Malformed PDF Streams

Comments
2 min read
GHSA-XP4F-G2CM-RHG7: GHSA-XP4F-G2CM-RHG7: Log Denial of Service via LoginPacket Resource Exhaustion in PocketMine-MP

GHSA-XP4F-G2CM-RHG7: GHSA-XP4F-G2CM-RHG7: Log Denial of Service via LoginPacket Resource Exhaustion in PocketMine-MP

Comments
2 min read
CVE-2026-2332: CVE-2026-2332: HTTP Request Smuggling in Eclipse Jetty via Chunked Extension Quoted-String Parsing

CVE-2026-2332: CVE-2026-2332: HTTP Request Smuggling in Eclipse Jetty via Chunked Extension Quoted-String Parsing

Comments
2 min read
GHSA-2X79-GWQ3-VXXM: GHSA-2x79-gwq3-vxxm: Infinite Loop Denial of Service in facil.io and iodine JSON Parser

GHSA-2X79-GWQ3-VXXM: GHSA-2x79-gwq3-vxxm: Infinite Loop Denial of Service in facil.io and iodine JSON Parser

Comments
2 min read
CVE-2023-2640: CVE-2023-2640: Local Privilege Escalation in Ubuntu Kernel OverlayFS (GameOver(lay))

CVE-2023-2640: CVE-2023-2640: Local Privilege Escalation in Ubuntu Kernel OverlayFS (GameOver(lay))

Comments
2 min read
GHSA-G4VJ-CJJJ-V7HG: GHSA-G4VJ-CJJJ-V7HG: Defense in Depth Update for NuGet Client Handling Resource Consumption and Log Disclosure

GHSA-G4VJ-CJJJ-V7HG: GHSA-G4VJ-CJJJ-V7HG: Defense in Depth Update for NuGet Client Handling Resource Consumption and Log Disclosure

Comments
2 min read
CVE-2026-34621: CVE-2026-34621: Prototype Pollution to Arbitrary Code Execution in Adobe Acrobat EScript Engine

CVE-2026-34621: CVE-2026-34621: Prototype Pollution to Arbitrary Code Execution in Adobe Acrobat EScript Engine

Comments
2 min read
CVE-2026-34457: CVE-2026-34457: Authentication Bypass via User-Agent Spoofing in OAuth2 Proxy

CVE-2026-34457: CVE-2026-34457: Authentication Bypass via User-Agent Spoofing in OAuth2 Proxy

Comments
2 min read
CVE-2026-40310: CVE-2026-40310: Heap-Based Out-of-Bounds Write in ImageMagick JP2 Encoder

CVE-2026-40310: CVE-2026-40310: Heap-Based Out-of-Bounds Write in ImageMagick JP2 Encoder

Comments
2 min read
CVE-2026-40312: CVE-2026-40312: Off-by-One Heap Memory Corruption in ImageMagick MSL Decoder

CVE-2026-40312: CVE-2026-40312: Off-by-One Heap Memory Corruption in ImageMagick MSL Decoder

Comments
2 min read
CVE-2026-40311: CVE-2026-40311: Heap Use-After-Free in ImageMagick XMP Profile Parsing

CVE-2026-40311: CVE-2026-40311: Heap Use-After-Free in ImageMagick XMP Profile Parsing

Comments
2 min read
CVE-2023-36424: CVE-2023-36424: Windows Common Log File System (CLFS) Driver Elevation of Privilege

CVE-2023-36424: CVE-2023-36424: Windows Common Log File System (CLFS) Driver Elevation of Privilege

Comments
2 min read
CVE-2025-0520: CVE-2025-0520: Unauthenticated Remote Code Execution via Unrestricted File Upload in ShowDoc

CVE-2025-0520: CVE-2025-0520: Unauthenticated Remote Code Execution via Unrestricted File Upload in ShowDoc

Comments
2 min read
GHSA-CMXV-58FP-FM3G: GHSA-cmxv-58fp-fm3g: Cross-Domain Credential Leakage in AsyncHttpClient

GHSA-CMXV-58FP-FM3G: GHSA-cmxv-58fp-fm3g: Cross-Domain Credential Leakage in AsyncHttpClient

Comments
2 min read
GHSA-527G-3W9M-29HV: GHSA-527g-3w9m-29hv: LDAP Injection in mitmproxy proxyauth Addon

GHSA-527G-3W9M-29HV: GHSA-527g-3w9m-29hv: LDAP Injection in mitmproxy proxyauth Addon

Comments
2 min read
GHSA-R4Q5-VMMM-2653: GHSA-R4Q5-VMMM-2653: Information Exposure via Sensitive Header Leak in follow-redirects

GHSA-R4Q5-VMMM-2653: GHSA-R4Q5-VMMM-2653: Information Exposure via Sensitive Header Leak in follow-redirects

Comments
2 min read
GHSA-76HW-P97H-883F: GHSA-76hw-p97h-883f: Arbitrary File Write via Path Traversal in gdown Archive Extraction

GHSA-76HW-P97H-883F: GHSA-76hw-p97h-883f: Arbitrary File Write via Path Traversal in gdown Archive Extraction

Comments
2 min read
CVE-2026-32270: CVE-2026-32270: Information Disclosure in Craft Commerce Payments Controller

CVE-2026-32270: CVE-2026-32270: Information Disclosure in Craft Commerce Payments Controller

Comments
2 min read
CVE-2026-34069: CVE-2026-34069: Remote Denial of Service via Reachable Assertion in Nimiq Albatross Consensus

CVE-2026-34069: CVE-2026-34069: Remote Denial of Service via Reachable Assertion in Nimiq Albatross Consensus

Comments
2 min read
CVE-2026-5724: CVE-2026-5724: Missing Authentication in Temporal gRPC Streaming Endpoint

CVE-2026-5724: CVE-2026-5724: Missing Authentication in Temporal gRPC Streaming Endpoint

Comments
2 min read
CVE-2026-33900: CVE-2026-33900: Heap-Based Buffer Overflow via Integer Truncation in ImageMagick VIFF Encoder

CVE-2026-33900: CVE-2026-33900: Heap-Based Buffer Overflow via Integer Truncation in ImageMagick VIFF Encoder

Comments
2 min read
CVE-2026-34238: CVE-2026-34238: Heap Buffer Overflow in ImageMagick Despeckle Operation

CVE-2026-34238: CVE-2026-34238: Heap Buffer Overflow in ImageMagick Despeckle Operation

Comments
2 min read
CVE-2026-33899: CVE-2026-33899: Heap-Based Buffer Overflow via Integer Underflow in ImageMagick XML Parser

CVE-2026-33899: CVE-2026-33899: Heap-Based Buffer Overflow via Integer Underflow in ImageMagick XML Parser

Comments
2 min read
CVE-2026-28291: CVE-2026-28291: Command Execution via Option-Parsing Bypass in simple-git

CVE-2026-28291: CVE-2026-28291: Command Execution via Option-Parsing Bypass in simple-git

Comments
2 min read
CVE-2026-23891: CVE-2026-23891: Critical Stored Cross-Site Scripting (XSS) in Decidim User Profiles

CVE-2026-23891: CVE-2026-23891: Critical Stored Cross-Site Scripting (XSS) in Decidim User Profiles

Comments
2 min read
CVE-2026-27654: CVE-2026-27654: Heap-based Buffer Overflow in NGINX ngx_http_dav_module via Integer Underflow

CVE-2026-27654: CVE-2026-27654: Heap-based Buffer Overflow in NGINX ngx_http_dav_module via Integer Underflow

Comments
2 min read
CVE-2026-40097: CVE-2026-40097: Index Out-of-Bounds Panic in Step CA TPM Attestation

CVE-2026-40097: CVE-2026-40097: Index Out-of-Bounds Panic in Step CA TPM Attestation

Comments
2 min read
CVE-2026-40109: CVE-2026-40109: Improper Authentication in Flux notification-controller GCR Receiver

CVE-2026-40109: CVE-2026-40109: Improper Authentication in Flux notification-controller GCR Receiver

Comments
2 min read
GHSA-6V7Q-WJVX-W8WG: GHSA-6V7Q-WJVX-W8WG: Arbitrary FTP Command Execution via CRLF Injection in basic-ftp

GHSA-6V7Q-WJVX-W8WG: GHSA-6V7Q-WJVX-W8WG: Arbitrary FTP Command Execution via CRLF Injection in basic-ftp

Comments
2 min read
GHSA-FFQ7-898W-9JC4: GHSA-FFQ7-898W-9JC4: Stored Cross-Site Scripting via SVG Upload in DotNetNuke

GHSA-FFQ7-898W-9JC4: GHSA-FFQ7-898W-9JC4: Stored Cross-Site Scripting via SVG Upload in DotNetNuke

Comments
2 min read
loading...