DEV Community

# vulnerability

Discussions about specific security vulnerabilities and CVEs.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
GitHub Breach via VSCode Extension, ZTE Router CVE-2026-34472, & Public Repo Secrets Leaks

GitHub Breach via VSCode Extension, ZTE Router CVE-2026-34472, & Public Repo Secrets Leaks

Comments
3 min read
NGINX CVE-2026-42945: An 18-Year-Old Heap Overflow Now Actively Exploited

NGINX CVE-2026-42945: An 18-Year-Old Heap Overflow Now Actively Exploited

Comments
3 min read
NPM Supply Chain Compromise, cPanel Root RCE, AWS Pathfinding Labs

NPM Supply Chain Compromise, cPanel Root RCE, AWS Pathfinding Labs

Comments
3 min read
Windows MiniPlasma Zero-Day, TanStack Supply Chain Hardening & AudioHijack AI Attacks on LLMs

Windows MiniPlasma Zero-Day, TanStack Supply Chain Hardening & AudioHijack AI Attacks on LLMs

1
Comments
3 min read
macOS ping OOB Write Disclosed, Grafana Mass CVE Scanner, AI Code Security Risks

macOS ping OOB Write Disclosed, Grafana Mass CVE Scanner, AI Code Security Risks

Comments
3 min read
Linux Kernel SSH Key Flaw, CrushFTP Yara Detection, & Vercel Typosquatting Attack

Linux Kernel SSH Key Flaw, CrushFTP Yara Detection, & Vercel Typosquatting Attack

Comments
3 min read
Microsoft Exchange Zero-Day, Linux Kernel LPE, and an Open-Source Docker Scanner

Microsoft Exchange Zero-Day, Linux Kernel LPE, and an Open-Source Docker Scanner

Comments
3 min read
Win11 Zero-Days, npm Supply Chain, & AI Agent Security Threats

Win11 Zero-Days, npm Supply Chain, & AI Agent Security Threats

Comments
3 min read
AI-Powered Zero-Days Bypass 2FA; Passkey & Git Supply Chain Attacks Explored

AI-Powered Zero-Days Bypass 2FA; Passkey & Git Supply Chain Attacks Explored

Comments
4 min read
Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Ollama Out-of-Bounds Read, Docker UFW Bypass, & EagleSpy RAT Analysis

Comments
4 min read
LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

LangChain ChromaDB Metadata Priority Injection — RAG Poisoning Vulnerability

Comments
1 min read
NGINX Heap Overflow (CVE-2026-42945), BitLocker Zero-Day, & Chrome Extension Supply Chain Attack

NGINX Heap Overflow (CVE-2026-42945), BitLocker Zero-Day, & Chrome Extension Supply Chain Attack

1
Comments
3 min read
AI-Driven Kernel LPE Discovery, ChromaDB Memory Poisoning & JDownloader Supply Chain Attack

AI-Driven Kernel LPE Discovery, ChromaDB Memory Poisoning & JDownloader Supply Chain Attack

Comments
3 min read
Linux 'Dirty Frag' Zero-Day, Cilium CI/CD Hardening, and AI-Powered RE with pyghidra-mcp

Linux 'Dirty Frag' Zero-Day, Cilium CI/CD Hardening, and AI-Powered RE with pyghidra-mcp

Comments
3 min read
Bitlocker Bypass, AI Trust Exploits, and FreeBSD RCE Disclosures

Bitlocker Bypass, AI Trust Exploits, and FreeBSD RCE Disclosures

Comments
4 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.