DEV Community

#cve

Posts

đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.
CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now

CVE-2026-94293: AAS Edge Client — CVSS 9.8 IIoT Data Tampering, No Patch, Decommission Now

Comments
1 min read
n8n Published Two CVEs in One Day: Expression Sandbox Escape (CVE-2026-86076) and Argument Injection (CVE-2026-44790)

n8n Published Two CVEs in One Day: Expression Sandbox Escape (CVE-2026-86076) and Argument Injection (CVE-2026-44790)

Comments
6 min read
CVE-2026-96749: CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

CVE-2026-96749: CVE-2026-96749: Heap Out-of-Bounds Write in MongoDB PyMongo BSON Encoder

Comments
2 min read
CVE-2026-103921: CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

CVE-2026-103921: CVE-2026-103921: TLS Certificate Validation Bypass in @graphql-tools/executor-legacy-ws

Comments
2 min read
GitLab Patched a CVSS 9.9 RCE in Its AI Gateway — Patch Guide for Self-Hosted Agent Builders

GitLab Patched a CVSS 9.9 RCE in Its AI Gateway — Patch Guide for Self-Hosted Agent Builders

1
Comments 1
7 min read
CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

CVE-2026-15896: an unauthenticated path traversal in the Super Forms WordPress plugin

Comments
2 min read
CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV

CVE-2026-88779 — Citrix NetScaler SAML Memory Overflow, Actively Exploited, CISA KEV

Comments
1 min read
CVE-2026-29057 — HTTP Request Smuggling via Next.js Rewrites

CVE-2026-29057 — HTTP Request Smuggling via Next.js Rewrites

Comments
5 min read
Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

Pgpool-II 3.5.x through 4.2.x: the branches that will not be patched

Comments
3 min read
CVE-2026-61500: Forging an HFS Admin Session Without Logging In

CVE-2026-61500: Forging an HFS Admin Session Without Logging In

Comments
4 min read
CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

CVE-2026-84411 in MikroTik RouterOS: why a pre-authentication integer underflow reaches root

Comments
2 min read
GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

GHSA-JQMF-MX4F-HFR6: GHSA-JQMF-MX4F-HFR6: Multiple Remote Code Execution and Security Flaws in Vibe-Trading AI-Agent Pipeline

Comments
2 min read
CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

CVE-2026-74904: CVE-2026-74904: Missing Authorization in SiYuan Note-Taking Application API

Comments
2 min read
CVE-2026-19484: CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

CVE-2026-19484: CVE-2026-19484: Remote Denial of Service via Boyer-Moore-Horspool Integer Wrap-around in @fastify/busboy

Comments
2 min read
CVE-2026-92941: CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

CVE-2026-92941: CVE-2026-92941: Sandbox Escape and Process-Wide TLS Trust Store Manipulation in vm2

Comments
3 min read
đź‘‹ Sign in for the ability to sort posts by relevant, latest, or top.