DEV Community

# vulnerability

Discussions about specific security vulnerabilities and CVEs.

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-20435: How a MediaTek Boot Chain Flaw Exposes Crypto Wallets on 25% of Android Phones

CVE-2026-20435: How a MediaTek Boot Chain Flaw Exposes Crypto Wallets on 25% of Android Phones

1
Comments
5 min read
Zombie ZIP Vulnerability Enables Malware to Bypass 95% of Antivirus Software, Requiring Urgent Security Updates

Zombie ZIP Vulnerability Enables Malware to Bypass 95% of Antivirus Software, Requiring Urgent Security Updates

Comments
8 min read
EPSS Explained: Why Exploit Prediction Scoring Changes Everything for Vulnerability Prioritization

EPSS Explained: Why Exploit Prediction Scoring Changes Everything for Vulnerability Prioritization

Comments
2 min read
Denial of Service in yauzl 3.2.0: One Zip File Crashes the Library Behind VS Code and Electron

Denial of Service in yauzl 3.2.0: One Zip File Crashes the Library Behind VS Code and Electron

Comments
5 min read
MediaTek's Security Nightmare: How a Nothing Phone Was Hacked in 45 Seconds (Except It Wasn't)

MediaTek's Security Nightmare: How a Nothing Phone Was Hacked in 45 Seconds (Except It Wasn't)

1
Comments
6 min read
CVE-2026-28292: How a Simple Case-Sensitivity Bug Turns simple-git Into a Remote Code Execution Weapon (CVSS 9.8)

CVE-2026-28292: How a Simple Case-Sensitivity Bug Turns simple-git Into a Remote Code Execution Weapon (CVSS 9.8)

Comments
4 min read
Your Server's Public Key Is All I Need to Become Admin, CVE-2026-29000

Your Server's Public Key Is All I Need to Become Admin, CVE-2026-29000

1
Comments
5 min read
Breaking: New "PleaseFix" Vulnerabilities Turn AI Agents Against Their Users

Breaking: New "PleaseFix" Vulnerabilities Turn AI Agents Against Their Users

Comments
3 min read
Pac4j-JWT Authentication Bypass Vulnerability Undetected for Six Years Despite Advanced Security Tools

Pac4j-JWT Authentication Bypass Vulnerability Undetected for Six Years Despite Advanced Security Tools

Comments
9 min read
ClawJacked: How Malicious Websites Hijack Local AI Agents via WebSocket

ClawJacked: How Malicious Websites Hijack Local AI Agents via WebSocket

1
Comments
3 min read
Qualcomm Integer Overflow Zero-Day (CVE-2026-21385) Under Active Exploitation: What You Need to Know

Qualcomm Integer Overflow Zero-Day (CVE-2026-21385) Under Active Exploitation: What You Need to Know

Comments
5 min read
CVE-2026-22719: Why Your VMware Upgrade Is Actually A Breach Waiting To Happen

CVE-2026-22719: Why Your VMware Upgrade Is Actually A Breach Waiting To Happen

Comments
7 min read
Context Pivoting: A New Attack Vector in Multi-Server MCP Deployments

Context Pivoting: A New Attack Vector in Multi-Server MCP Deployments

Comments
4 min read
CVE-2026-25253: How 42,000+ OpenClaw Instances Got Pwned (And Why Your AI Assistant Is a Security Disaster)

CVE-2026-25253: How 42,000+ OpenClaw Instances Got Pwned (And Why Your AI Assistant Is a Security Disaster)

Comments
7 min read
CVE-2025-12758: Unicode Variation Selectors Bypass in 'validator' library (isLength)

CVE-2025-12758: Unicode Variation Selectors Bypass in 'validator' library (isLength)

Comments
1 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.