DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-12243: CVE-2026-12243: Incomplete Path Traversal Validation and Percent-Encoding Bypass in NLTK

CVE-2026-12243: CVE-2026-12243: Incomplete Path Traversal Validation and Percent-Encoding Bypass in NLTK

Comments
2 min read
CVE-2026-73654: CVE-2026-73654: Prototype Pollution in Trigger.dev leading to Cascading Denial of Service

CVE-2026-73654: CVE-2026-73654: Prototype Pollution in Trigger.dev leading to Cascading Denial of Service

Comments
2 min read
CVE-2026-73559: CVE-2026-73559: Uncontrolled Resource Consumption in vLLM API completions

CVE-2026-73559: CVE-2026-73559: Uncontrolled Resource Consumption in vLLM API completions

Comments
1 min read
CVE-2026-54526: CVE-2026-54526: Strict Template Referencing Bypass and Privilege Escalation in Argo Workflows

CVE-2026-54526: CVE-2026-54526: Strict Template Referencing Bypass and Privilege Escalation in Argo Workflows

Comments
2 min read
CVE-2026-54249: CVE-2026-54249: Server-Side Request Forgery via Confused Deputy in Pydantic AI UI Adapters

CVE-2026-54249: CVE-2026-54249: Server-Side Request Forgery via Confused Deputy in Pydantic AI UI Adapters

Comments
2 min read
GHSA-RM43-82J9-R4MJ: GHSA-RM43-82J9-R4MJ: Path Traversal (Arbitrary File Read) in atomic-agents-stack Dashboard

GHSA-RM43-82J9-R4MJ: GHSA-RM43-82J9-R4MJ: Path Traversal (Arbitrary File Read) in atomic-agents-stack Dashboard

Comments
2 min read
CVE-2026-9318: CVE-2026-9318: Stored Cross-Site Scripting via HTML Export in Jazzband tablib

CVE-2026-9318: CVE-2026-9318: Stored Cross-Site Scripting via HTML Export in Jazzband tablib

Comments
2 min read
CVE-2026-54917: CVE-2026-54917: Cross-Bucket Path Traversal and Authorization Bypass in SeaweedFS S3 and Iceberg Gateways

CVE-2026-54917: CVE-2026-54917: Cross-Bucket Path Traversal and Authorization Bypass in SeaweedFS S3 and Iceberg Gateways

Comments
2 min read
GHSA-JWJP-4649-V8JP: GHSA-jwjp-4649-v8jp: Out-of-Bounds Read in SIPSorcery SCTP SACK Chunk Parsing

GHSA-JWJP-4649-V8JP: GHSA-jwjp-4649-v8jp: Out-of-Bounds Read in SIPSorcery SCTP SACK Chunk Parsing

Comments
2 min read
GHSA-PFVM-W89X-94JW: GHSA-pfvm-w89x-94jw: Uncaught Exception in STUN Parser Causes Complete TurnServer Receive Loop Termination

GHSA-PFVM-W89X-94JW: GHSA-pfvm-w89x-94jw: Uncaught Exception in STUN Parser Causes Complete TurnServer Receive Loop Termination

Comments
2 min read
CVE-2026-62898: CVE-2026-62898: Use After Free Information Disclosure in Microsoft QUIC

CVE-2026-62898: CVE-2026-62898: Use After Free Information Disclosure in Microsoft QUIC

Comments
2 min read
CVE-2026-62899: CVE-2026-62899: .NET Security Feature Bypass Vulnerability (HTTP Request Smuggling)

CVE-2026-62899: CVE-2026-62899: .NET Security Feature Bypass Vulnerability (HTTP Request Smuggling)

Comments
2 min read
CVE-2026-62901: CVE-2026-62901: Remote Denial of Service via Infinite Loop in .NET WebSockets Engine

CVE-2026-62901: CVE-2026-62901: Remote Denial of Service via Infinite Loop in .NET WebSockets Engine

Comments
2 min read
CVE-2026-62909: CVE-2026-62909: .NET Local Elevation of Privilege via Unchecked Diagnostic Socket Permissions

CVE-2026-62909: CVE-2026-62909: .NET Local Elevation of Privilege via Unchecked Diagnostic Socket Permissions

Comments
2 min read
CVE-2026-70354: CVE-2026-70354: Out-of-Bounds Write in .NET Windows Presentation Foundation Subsystem

CVE-2026-70354: CVE-2026-70354: Out-of-Bounds Write in .NET Windows Presentation Foundation Subsystem

Comments
2 min read
CVE-2026-62897: CVE-2026-62897: Integer Overflow and Code Execution in .NET WPF and WinForms

CVE-2026-62897: CVE-2026-62897: Integer Overflow and Code Execution in .NET WPF and WinForms

Comments
2 min read
CVE-2026-62871: CVE-2026-62871: Local Code Execution and Elevation of Privilege in .NET and Visual Studio

CVE-2026-62871: CVE-2026-62871: Local Code Execution and Elevation of Privilege in .NET and Visual Studio

Comments
2 min read
CVE-2026-62902: CVE-2026-62902: .NET and Visual Studio Information Disclosure Vulnerability

CVE-2026-62902: CVE-2026-62902: .NET and Visual Studio Information Disclosure Vulnerability

Comments
2 min read
CVE-2026-62886: CVE-2026-62886: .NET Elevation of Privilege Vulnerability via Native Heap Buffer Overflow

CVE-2026-62886: CVE-2026-62886: .NET Elevation of Privilege Vulnerability via Native Heap Buffer Overflow

Comments
2 min read
CVE-2026-73080: CVE-2026-73080: Unauthenticated Server-Side Request Forgery (SSRF) in SeaweedFS Volume Server

CVE-2026-73080: CVE-2026-73080: Unauthenticated Server-Side Request Forgery (SSRF) in SeaweedFS Volume Server

Comments
2 min read
CVE-2026-71556: CVE-2026-71556: Symbolic Link Directory Traversal in go-git

CVE-2026-71556: CVE-2026-71556: Symbolic Link Directory Traversal in go-git

Comments
2 min read
CVE-2026-71557: CVE-2026-71557: Path Traversal and Configuration Overwrite in go-git Filesystem Storage Engine

CVE-2026-71557: CVE-2026-71557: Path Traversal and Configuration Overwrite in go-git Filesystem Storage Engine

Comments
2 min read
GHSA-7C4V-FWGW-9RF7: GHSA-7c4v-fwgw-9rf7: Nuxt Dev Server Discloses Project Root and Workspace UUID via Chrome DevTools Endpoint

GHSA-7C4V-FWGW-9RF7: GHSA-7c4v-fwgw-9rf7: Nuxt Dev Server Discloses Project Root and Workspace UUID via Chrome DevTools Endpoint

Comments
2 min read
CVE-2026-66062: CVE-2026-66062: Regular Expression Denial of Service (ReDoS) in SvelteKit Content Negotiation

CVE-2026-66062: CVE-2026-66062: Regular Expression Denial of Service (ReDoS) in SvelteKit Content Negotiation

Comments
2 min read
CVE-2026-15895: CVE-2026-15895: OS Command Injection in AWS jsii-diff CLI

CVE-2026-15895: CVE-2026-15895: OS Command Injection in AWS jsii-diff CLI

Comments
2 min read
CVE-2026-63220: CVE-2026-63220: Trust of Untrusted Reverse Proxy Headers in CodeIgniter4

CVE-2026-63220: CVE-2026-63220: Trust of Untrusted Reverse Proxy Headers in CodeIgniter4

Comments
1 min read
CVE-2026-63221: CVE-2026-63221: SQL Injection in CodeIgniter4 Query Builder deleteBatch()

CVE-2026-63221: CVE-2026-63221: SQL Injection in CodeIgniter4 Query Builder deleteBatch()

Comments
3 min read
CVE-2026-63222: CVE-2026-63222: Remote Code Execution via Path Traversal in CodeIgniter4 File Upload Handler

CVE-2026-63222: CVE-2026-63222: Remote Code Execution via Path Traversal in CodeIgniter4 File Upload Handler

Comments
2 min read
CVE-2026-63223: CVE-2026-63223: Unrestricted File Upload leading to Remote Code Execution in CodeIgniter4

CVE-2026-63223: CVE-2026-63223: Unrestricted File Upload leading to Remote Code Execution in CodeIgniter4

Comments
2 min read
CVE-2026-67422: CVE-2026-67422: Regular Expression Denial of Service in pymdown-extensions

CVE-2026-67422: CVE-2026-67422: Regular Expression Denial of Service in pymdown-extensions

Comments
2 min read
CVE-2026-71847: CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser

CVE-2026-71847: CVE-2026-71847: Use-After-Free in Ruby JSON Gem ResumableParser

Comments
2 min read
CVE-2026-71848: CVE-2026-71848: Algorithmic Complexity Denial of Service in Hono languageDetector Middleware

CVE-2026-71848: CVE-2026-71848: Algorithmic Complexity Denial of Service in Hono languageDetector Middleware

Comments
2 min read
CVE-2026-71849: CVE-2026-71849: Information Exposure via Hop-by-Hop Header Leakage in Hono Proxy Helper

CVE-2026-71849: CVE-2026-71849: Information Exposure via Hop-by-Hop Header Leakage in Hono Proxy Helper

Comments
2 min read
CVE-2026-71850: CVE-2026-71850: Server-Side Rendering Data Exposure in Hono JSX Memoization

CVE-2026-71850: CVE-2026-71850: Server-Side Rendering Data Exposure in Hono JSX Memoization

Comments
2 min read
CVE-2026-71851: CVE-2026-71851: Use of Cryptographically Weak PRNG in crypto-js (Ill Bloom)

CVE-2026-71851: CVE-2026-71851: Use of Cryptographically Weak PRNG in crypto-js (Ill Bloom)

Comments
2 min read
CVE-2026-71870: CVE-2026-71870: Uncontrolled Resource Consumption (DoS) in pypdf ToUnicode CMap Parsing

CVE-2026-71870: CVE-2026-71870: Uncontrolled Resource Consumption (DoS) in pypdf ToUnicode CMap Parsing

Comments
2 min read
CVE-2026-71852: CVE-2026-71852: Denial of Service via Excessive Iteration and Memory Exhaustion in pypdf CID Font Parsing

CVE-2026-71852: CVE-2026-71852: Denial of Service via Excessive Iteration and Memory Exhaustion in pypdf CID Font Parsing

Comments
2 min read
CVE-2026-56818: CVE-2026-56818: Denial of Service via Memory Pinning in Netty Redis Array Aggregator

CVE-2026-56818: CVE-2026-56818: Denial of Service via Memory Pinning in Netty Redis Array Aggregator

Comments
2 min read
CVE-2026-54164: CVE-2026-54164: Missing IRI Type Validation in API Platform Core Enables Resource Type Confusion

CVE-2026-54164: CVE-2026-54164: Missing IRI Type Validation in API Platform Core Enables Resource Type Confusion

Comments
2 min read
GHSA-WVPP-8HX9-P66J: GHSA-WVPP-8HX9-P66J: Arbitrary Command Execution via Option Guard Bypass in GitPython

GHSA-WVPP-8HX9-P66J: GHSA-WVPP-8HX9-P66J: Arbitrary Command Execution via Option Guard Bypass in GitPython

Comments
2 min read
GHSA-WG23-69C2-GJC8: GHSA-WG23-69C2-GJC8: Passkey Login Replay Vulnerability in Craft CMS

GHSA-WG23-69C2-GJC8: GHSA-WG23-69C2-GJC8: Passkey Login Replay Vulnerability in Craft CMS

Comments
2 min read
GHSA-MH25-X5HQ-WRQP: GHSA-MH25-X5HQ-WRQP: Algorithmic Complexity Denial of Service in league/commonmark UniqueSlugNormalizer

GHSA-MH25-X5HQ-WRQP: GHSA-MH25-X5HQ-WRQP: Algorithmic Complexity Denial of Service in league/commonmark UniqueSlugNormalizer

Comments
2 min read
GHSA-MJ63-M3RC-8PPR: GHSA-MJ63-M3RC-8PPR: Quadratic-Time Complexity in league/commonmark XML Pretty-Printing

GHSA-MJ63-M3RC-8PPR: GHSA-MJ63-M3RC-8PPR: Quadratic-Time Complexity in league/commonmark XML Pretty-Printing

Comments
2 min read
GHSA-265M-7826-WJQM: GHSA-265m-7826-wjqm: Authenticated Remote Code Execution in Craft CMS via condition.config JSON Cleanse Bypass

GHSA-265M-7826-WJQM: GHSA-265m-7826-wjqm: Authenticated Remote Code Execution in Craft CMS via condition.config JSON Cleanse Bypass

Comments
3 min read
GHSA-F5WM-88JV-G5HX: GHSA-F5WM-88JV-G5HX: Authenticated Remote Code Execution via Twig Sandbox Escape in Craft CMS

GHSA-F5WM-88JV-G5HX: GHSA-F5WM-88JV-G5HX: Authenticated Remote Code Execution via Twig Sandbox Escape in Craft CMS

Comments
2 min read
GHSA-P8X7-9VFW-P7VC: GHSA-P8X7-9VFW-P7VC: Arbitrary User Password Reset via Mass Assignment in Craft CMS

GHSA-P8X7-9VFW-P7VC: GHSA-P8X7-9VFW-P7VC: Arbitrary User Password Reset via Mass Assignment in Craft CMS

Comments
1 min read
CVE-2026-71497: CVE-2026-71497: Parser-Browser Desynchronization leading to XSS in jsoup Sanitizer

CVE-2026-71497: CVE-2026-71497: Parser-Browser Desynchronization leading to XSS in jsoup Sanitizer

Comments
2 min read
GHSA-W9HM-4M3M-FXMM: GHSA-W9HM-4M3M-FXMM: Arbitrary JavaScript Execution via Malicious PDF Parsing in ngx-extended-pdf-viewer

GHSA-W9HM-4M3M-FXMM: GHSA-W9HM-4M3M-FXMM: Arbitrary JavaScript Execution via Malicious PDF Parsing in ngx-extended-pdf-viewer

Comments
2 min read
CVE-2026-71430: CVE-2026-71430: Denial of Service via Native Assertion Failure in node-re2 Replace Operation

CVE-2026-71430: CVE-2026-71430: Denial of Service via Native Assertion Failure in node-re2 Replace Operation

Comments
2 min read
CVE-2026-71498: CVE-2026-71498: Out-of-bounds Heap Read in node-re2 via Truncated Multi-byte UTF-8 Characters

CVE-2026-71498: CVE-2026-71498: Out-of-bounds Heap Read in node-re2 via Truncated Multi-byte UTF-8 Characters

Comments
2 min read
CVE-2026-67434: CVE-2026-67434: OS Command Injection via Malicious Filenames in PHP_CodeSniffer Blame Reports

CVE-2026-67434: CVE-2026-67434: OS Command Injection via Malicious Filenames in PHP_CodeSniffer Blame Reports

Comments
2 min read
GHSA-2RP4-X2J7-QMCC: GHSA-2RP4-X2J7-QMCC: Stored Cross-Site Scripting via Draft Names in Craft CMS Control Panel

GHSA-2RP4-X2J7-QMCC: GHSA-2RP4-X2J7-QMCC: Stored Cross-Site Scripting via Draft Names in Craft CMS Control Panel

Comments
2 min read
GHSA-7HXC-F267-H5Q7: GHSA-7HXC-F267-H5Q7: Path Traversal via Validation-then-Normalization in Craft CMS

GHSA-7HXC-F267-H5Q7: GHSA-7HXC-F267-H5Q7: Path Traversal via Validation-then-Normalization in Craft CMS

Comments
2 min read
GHSA-RVMM-V933-JGXQ: GHSA-rvmm-v933-jgxq: Missing Authorization Check in Craft CMS ChartsController

GHSA-RVMM-V933-JGXQ: GHSA-rvmm-v933-jgxq: Missing Authorization Check in Craft CMS ChartsController

Comments
2 min read
GHSA-596P-6JV8-775V: GHSA-596p-6jv8-775v: Authenticated Leak of Secret Environment Variables in Craft CMS

GHSA-596P-6JV8-775V: GHSA-596p-6jv8-775v: Authenticated Leak of Secret Environment Variables in Craft CMS

Comments
2 min read
CVE-2026-71554: CVE-2026-71554: HTTP Request Smuggling via Duplicate Host Headers in h2 Protocol Stack

CVE-2026-71554: CVE-2026-71554: HTTP Request Smuggling via Duplicate Host Headers in h2 Protocol Stack

Comments
2 min read
GHSA-957R-QF9P-67XW: GHSA-957R-QF9P-67XW: Arbitrary File Read via SplFileObject in Craft CMS Twig Extension

GHSA-957R-QF9P-67XW: GHSA-957R-QF9P-67XW: Arbitrary File Read via SplFileObject in Craft CMS Twig Extension

Comments
2 min read
CVE-2026-14793: CVE-2026-14793: Authorization Bypass in Craft CMS GlobalsController actionReorderSets

CVE-2026-14793: CVE-2026-14793: Authorization Bypass in Craft CMS GlobalsController actionReorderSets

Comments
2 min read
CVE-2026-71438: CVE-2026-71438: Prototype Pollution in Mermaid Configuration APIs

CVE-2026-71438: CVE-2026-71438: Prototype Pollution in Mermaid Configuration APIs

Comments
2 min read
CVE-2026-67309: CVE-2026-67309: Path Traversal and Authentication Bypass in Traefik RewriteTarget Middleware

CVE-2026-67309: CVE-2026-67309: Path Traversal and Authentication Bypass in Traefik RewriteTarget Middleware

Comments
2 min read
loading...