DEV Community

# cve

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2025-68613: n8n RCE: When 'this' Becomes Your Worst Nightmare

CVE-2025-68613: n8n RCE: When 'this' Becomes Your Worst Nightmare

Comments
2 min read
CVE-2026-23950: Scharfes S, Sharp Claws: Breaking Node-Tar with Unicode Ligatures

CVE-2026-23950: Scharfes S, Sharp Claws: Breaking Node-Tar with Unicode Ligatures

Comments
2 min read
CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

CVE-2026-0831 - Arbitrary File Write Vulnerability in WordPress Templately Plugin

Comments
12 min read
CVE-2025-66803: The Undead Session: Explaining the Race Condition in Hotwired Turbo

CVE-2025-66803: The Undead Session: Explaining the Race Condition in Hotwired Turbo

Comments
2 min read
CVE-2026-23829: Mailpit Stop: SMTP Header Injection via Regex Failure

CVE-2026-23829: Mailpit Stop: SMTP Header Injection via Regex Failure

Comments
2 min read
CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

CVE-2026-0594 - Reflected Cross-Site Scripting (XSS) in WordPress

5
Comments
10 min read
CVE-2026-23518: Fleet Fiasco: The Unverified JWT That Opened the Gates

CVE-2026-23518: Fleet Fiasco: The Unverified JWT That Opened the Gates

Comments
2 min read
CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

CVE-2026-0712 - Grafana Open Redirect Leading to Cross-Site Scripting (XSS) Vulnerability

5
Comments
9 min read
CVE-2026-24420: CVE-2026-24420: When `isset()` Becomes a Backdoor in phpMyFAQ

CVE-2026-24420: CVE-2026-24420: When `isset()` Becomes a Backdoor in phpMyFAQ

Comments
2 min read
CVE-2026-0863: Snake in the Sandbox: Breaking n8n with Python 3.10 Internals

CVE-2026-0863: Snake in the Sandbox: Breaking n8n with Python 3.10 Internals

Comments
2 min read
CVE-2026-0994: Recursive Hell: Breaking Python Protobuf with Nested 'Any' Messages

CVE-2026-0994: Recursive Hell: Breaking Python Protobuf with Nested 'Any' Messages

2
Comments
2 min read
GHSA-38CW-85XC-XR9X: Identity Crisis: Dumping Veramo's Digital Wallets via SQL Injection

GHSA-38CW-85XC-XR9X: Identity Crisis: Dumping Veramo's Digital Wallets via SQL Injection

Comments
2 min read
CVE-2026-23735: Singleton Roulette: Racing for Context in GraphQL Modules

CVE-2026-23735: Singleton Roulette: Racing for Context in GraphQL Modules

Comments
2 min read
CVE-2026-22782: RustFS Leak: When Error Logs Become Credentials

CVE-2026-22782: RustFS Leak: When Error Logs Become Credentials

Comments
2 min read
GHSA-GW32-9RMW-QWWW: Svelte SSR XSS: The Textarea Trap

GHSA-GW32-9RMW-QWWW: Svelte SSR XSS: The Textarea Trap

Comments
2 min read
GHSA-5882-5RX9-XGXP: Crawl4AI RCE: Hook, Line, and Sinker into Your Docker Container

GHSA-5882-5RX9-XGXP: Crawl4AI RCE: Hook, Line, and Sinker into Your Docker Container

Comments
2 min read
CVE-2025-8217: Amazon Q's Self-Sabotage: The Backdoor That Couldn't Code

CVE-2025-8217: Amazon Q's Self-Sabotage: The Backdoor That Couldn't Code

Comments
2 min read
CVE-2026-23535: Trust Issues: Arbitrary File Write in Weblate CLI (CVE-2026-23535)

CVE-2026-23535: Trust Issues: Arbitrary File Write in Weblate CLI (CVE-2026-23535)

Comments
2 min read
CVE-2026-23527: Case Sensitivity Kills: HTTP Request Smuggling in H3

CVE-2026-23527: Case Sensitivity Kills: HTTP Request Smuggling in H3

Comments
2 min read
GHSA-58Q2-9X27-H2JM: The Infinite Buffer: Crashing Craft CMS via Axios Data URIs

GHSA-58Q2-9X27-H2JM: The Infinite Buffer: Crashing Craft CMS via Axios Data URIs

Comments
2 min read
CVE-2026-1002: Ghost in the Machine: Vert.x Cache Poisoning DoS

CVE-2026-1002: Ghost in the Machine: Vert.x Cache Poisoning DoS

Comments
2 min read
CVE-2026-22775: Devalue, Indeed: How a Simple Serializer Can Crash Your Svelte App

CVE-2026-22775: Devalue, Indeed: How a Simple Serializer Can Crash Your Svelte App

Comments
2 min read
CVE-2026-23519: Betrayal by Optimization: How LLVM Broke Rust's Constant-Time Promises

CVE-2026-23519: Betrayal by Optimization: How LLVM Broke Rust's Constant-Time Promises

Comments
2 min read
CVE-2025-66292: DPanel's Delete Function Works Too Well: A Tale of Path Traversal

CVE-2025-66292: DPanel's Delete Function Works Too Well: A Tale of Path Traversal

Comments
2 min read
Node.js January 2026 Security Release: 8 CVEs Explained

Node.js January 2026 Security Release: 8 CVEs Explained

Comments
14 min read
loading...