DEV Community

# vulnerability

Posts

👋 Sign in for the ability to sort posts by relevant, latest, or top.
Unveiling the XZ Backdoor: A Deep Dive into the Shocking Supply Chain Attack

Unveiling the XZ Backdoor: A Deep Dive into the Shocking Supply Chain Attack

6
Comments 1
3 min read
Understanding Cross-Site Scripting (XSS)

Understanding Cross-Site Scripting (XSS)

5
Comments
4 min read
Death to the invincible engineer

Death to the invincible engineer

Comments
7 min read
Death to the invincible engineer

Death to the invincible engineer

61
Comments 6
7 min read
Docker Scout

Docker Scout

Comments
1 min read
What is path travelsal vulnerability?

What is path travelsal vulnerability?

Comments
2 min read
Insecure Direct Object Reference (IDOR) vulnerability types

Insecure Direct Object Reference (IDOR) vulnerability types

Comments
3 min read
Rational Shift-Left Security for Developers

Rational Shift-Left Security for Developers

2
Comments 1
7 min read
Mastering Node.js Security: Top Strategies for Resolving Vulnerabilities

Mastering Node.js Security: Top Strategies for Resolving Vulnerabilities

1
Comments
4 min read
10 Best Vulnerability Scanner Tools For Penetration Testing

10 Best Vulnerability Scanner Tools For Penetration Testing

2
Comments 1
4 min read
Comprised Mac Studio — Hacked Developer Server - Remote Access Technology

Comprised Mac Studio — Hacked Developer Server - Remote Access Technology

1
Comments
18 min read
Un Dependabot más inteligente y silencioso

Un Dependabot más inteligente y silencioso

2
Comments
1 min read
sudoedit (`sudo -e`) に係る脆弱性 (CVE-2023-22809)

sudoedit (`sudo -e`) に係る脆弱性 (CVE-2023-22809)

2
Comments
1 min read
sudoedit (`sudo -e`) security flaw (CVE-2023-22809)

sudoedit (`sudo -e`) security flaw (CVE-2023-22809)

4
Comments 7
1 min read
Google Chrome の CVE 脆弱性: 2022 年 12 月頃のリリースバージョンまで

Google Chrome の CVE 脆弱性: 2022 年 12 月頃のリリースバージョンまで

1
Comments
1 min read
CVE vulnerabilities on Google Chrome prior to releases around on Dec. 2022

CVE vulnerabilities on Google Chrome prior to releases around on Dec. 2022

1
Comments
1 min read
Spring Framework 6.0.0 compatibility with Java 11

Spring Framework 6.0.0 compatibility with Java 11

3
Comments
1 min read
Top websites for website vulnerability checks online

Top websites for website vulnerability checks online

3
Comments
2 min read
Apache Commons Text RCE Vulnerability Analysis - CVE-2022-42889

Apache Commons Text RCE Vulnerability Analysis - CVE-2022-42889

5
Comments
3 min read
P1 Bug Bounties: What is an IDOR, and how does IDOR == $$$?

P1 Bug Bounties: What is an IDOR, and how does IDOR == $$$?

1
Comments
1 min read
Sekurak MSHP CTF Summary - Part 1

Sekurak MSHP CTF Summary - Part 1

2
Comments
3 min read
How I found an S3 vulnerability in a $85 million funded startup and reported it ethically

How I found an S3 vulnerability in a $85 million funded startup and reported it ethically

1
Comments
4 min read
CycloneDX SBom (Software Bill of material) Maven Demo

CycloneDX SBom (Software Bill of material) Maven Demo

Comments
6 min read
Forging GraphQL Bombs, the 2022 version of Zip Bombs

Forging GraphQL Bombs, the 2022 version of Zip Bombs

47
Comments 2
4 min read
Understanding Auto-Merge in Dependency Management Tools

Understanding Auto-Merge in Dependency Management Tools

Comments
4 min read
Reconmap 1.1.0 release notes

Reconmap 1.1.0 release notes

5
Comments
2 min read
Finding a Stack Buffer Overflow

Finding a Stack Buffer Overflow

5
Comments
7 min read
CVE-2022-0185 - How to mitigate - Linux Kernel - cap_sys_admin - K8s vulnerability

CVE-2022-0185 - How to mitigate - Linux Kernel - cap_sys_admin - K8s vulnerability

1
Comments
2 min read
What a Jar of Buttons Is Teaching Me About Trust

What a Jar of Buttons Is Teaching Me About Trust

10
Comments 2
5 min read
Log4j 2.17.0 に関わる新たな RCE 脆弱性 (CVE-2021-4483)

Log4j 2.17.0 に関わる新たな RCE 脆弱性 (CVE-2021-4483)

3
Comments
1 min read
A new RCE vulnerability on Log4j 2.17.0 (CVE-2021-4483)

A new RCE vulnerability on Log4j 2.17.0 (CVE-2021-4483)

3
Comments
1 min read
What is Log4j Vulnerability and how dangerous is it

What is Log4j Vulnerability and how dangerous is it

2
Comments
3 min read
Log4j 2: DoS に関わる新たな脆弱性 (2.16.0 とそれ以前のバージョン)

Log4j 2: DoS に関わる新たな脆弱性 (2.16.0 とそれ以前のバージョン)

3
Comments
1 min read
Log4j 2: New vulnerability on DoS in 2.16.0 and below

Log4j 2: New vulnerability on DoS in 2.16.0 and below

9
Comments 3
1 min read
log4shell の JAR 検査ツール

log4shell の JAR 検査ツール

3
Comments
1 min read
Log4j2 vulnerability

Log4j2 vulnerability

1
Comments
1 min read
Log4j Vulnerability

Log4j Vulnerability

1
Comments
1 min read
New Log4j vulnerability was found in 2.15.0 which is less dangerous

New Log4j vulnerability was found in 2.15.0 which is less dangerous

4
Comments
2 min read
About Apache Log4j RCE vulnerability (CVE-2021-44228)

About Apache Log4j RCE vulnerability (CVE-2021-44228)

6
Comments 1
1 min read
Apache Log4j RCE 脆弱性 (CVE-2021-44228) に関して

Apache Log4j RCE 脆弱性 (CVE-2021-44228) に関して

3
Comments
1 min read
Apache Log4j RCE 脆弱性 (CVE-2021-44228): 攻撃試行を検出

Apache Log4j RCE 脆弱性 (CVE-2021-44228): 攻撃試行を検出

3
Comments
1 min read
Apache Log4j RCE vulnerability (CVE-2021-44228): Attack trials detected

Apache Log4j RCE vulnerability (CVE-2021-44228): Attack trials detected

3
Comments
1 min read
Log4Shell : JNDI Injection via Attackable Log4J

Log4Shell : JNDI Injection via Attackable Log4J

Comments
6 min read
Evolving Threat series — Infiltrating NPM’s Supply Chain (UA-Parser-js)

Evolving Threat series — Infiltrating NPM’s Supply Chain (UA-Parser-js)

3
Comments
4 min read
Mitigating the 0-day Apache path traversal vulnerability

Mitigating the 0-day Apache path traversal vulnerability

6
Comments
4 min read
Why Is Penetration Testing Important For Your Website?

Why Is Penetration Testing Important For Your Website?

1
Comments 1
4 min read
Connecting RaaS, REvil, Kaseya and your security posture

Connecting RaaS, REvil, Kaseya and your security posture

Comments
7 min read
Web Threats

Web Threats

Comments
2 min read
NGINX ประกาศ CVE-2021-23017 เกิดจากการใช้ resolver บน NGINX และ NGINX Ingress Controller

NGINX ประกาศ CVE-2021-23017 เกิดจากการใช้ resolver บน NGINX และ NGINX Ingress Controller

1
Comments
2 min read
Blind XPath Injections: The Path Less Travelled

Blind XPath Injections: The Path Less Travelled

22
Comments
5 min read
Be Openly Confused

Be Openly Confused

4
Comments
1 min read
14 Software Security Terms You Should Know

14 Software Security Terms You Should Know

7
Comments
3 min read
Security Benchmarking at 1300 °C

Security Benchmarking at 1300 °C

5
Comments
5 min read
Generating pentest reports with Reconmap

Generating pentest reports with Reconmap

6
Comments
3 min read
To improve good security practices

To improve good security practices

7
Comments
1 min read
Hacking the antivirus: BitDefender remote code execution vulnerability

Hacking the antivirus: BitDefender remote code execution vulnerability

4
Comments 2
4 min read
National Vulnerability Database in Dolt

National Vulnerability Database in Dolt

1
Comments
1 min read
Attention! New .NET Vulnerabilities

Attention! New .NET Vulnerabilities

6
Comments
5 min read
Vulnerability Focus: PHP

Vulnerability Focus: PHP

10
Comments
5 min read
Cross-site scripting Attack Tutorial

Cross-site scripting Attack Tutorial

41
Comments 1
1 min read
loading...