DEV Community

#cve

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Deep-Dive Write-up by Huynh Kien Minh: CVE-2026-13736 — NewPath WildApricotPress Member Directory PII Disclosure

Comments
4 min read
GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles

GHSA-5CWR-5JXG-PCF6: GHSA-5CWR-5JXG-PCF6: Stored Cross-Site Scripting via Improper Cache Sanitization in Winter CMS Custom Styles

Comments
2 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)

Comments 2
6 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network

Comments
6 min read
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution

Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution

Comments
6 min read
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation

Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation

Comments
4 min read
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer

Comments
2 min read
nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand

nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand

1
Comments
17 min read
Aikido buys Root to patch open source in place, without the upgrade dance

Aikido buys Root to patch open source in place, without the upgrade dance

Comments
4 min read
It refused to run a dangerous option. I wrote it one character shorter, and it ran

It refused to run a dangerous option. I wrote it one character shorter, and it ran

Comments 2
9 min read
MITRE CVE ID Request and Support Follow-Up: No Confirmation Email Received Despite Anti-Filter Measures

MITRE CVE ID Request and Support Follow-Up: No Confirmation Email Received Despite Anti-Filter Measures

1
Comments
8 min read
CVE Severity: Risk-Based Prioritization

CVE Severity: Risk-Based Prioritization

Comments
2 min read
How to Actually Protect Yourself From wp2shell (Not Just "Update WordPress")

How to Actually Protect Yourself From wp2shell (Not Just "Update WordPress")

Comments 2
5 min read
How Attackers Find Vulnerable Applications — And How to Stay One Step Ahead

How Attackers Find Vulnerable Applications — And How to Stay One Step Ahead

Comments
7 min read
The HTTP Header That Could Execute Linux Commands: Understanding Shellshock

The HTTP Header That Could Execute Linux Commands: Understanding Shellshock

1
Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.