DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-8467: CVE-2026-8467: Unauthenticated Remote Code Execution in phoenix_storybook

CVE-2026-8467: CVE-2026-8467: Unauthenticated Remote Code Execution in phoenix_storybook

Comments
2 min read
CVE-2026-8469: CVE-2026-8469: Denial of Service via BEAM Atom Table Exhaustion in phoenix_storybook

CVE-2026-8469: CVE-2026-8469: Denial of Service via BEAM Atom Table Exhaustion in phoenix_storybook

Comments
2 min read
CVE-2026-47068: CVE-2026-47068: Authorization Bypass via Cross-Session PubSub Topic Injection in phoenix_storybook

CVE-2026-47068: CVE-2026-47068: Authorization Bypass via Cross-Session PubSub Topic Injection in phoenix_storybook

Comments
2 min read
GHSA-7QJX-GP9H-65QJ: GHSA-7QJX-GP9H-65QJ: Improper Authorization in Dex Token Exchange

GHSA-7QJX-GP9H-65QJ: GHSA-7QJX-GP9H-65QJ: Improper Authorization in Dex Token Exchange

Comments
2 min read
CVE-2024-29203: CVE-2024-29203: Client-Side Cross-Site Scripting via Unsandboxed Iframes and Legacy Embed Elements in TinyMCE

CVE-2024-29203: CVE-2024-29203: Client-Side Cross-Site Scripting via Unsandboxed Iframes and Legacy Embed Elements in TinyMCE

Comments
2 min read
CVE-2026-9277: CVE-2026-9277: OS Command Injection in shell-quote via Object-Token Line Terminator Parsing Defect

CVE-2026-9277: CVE-2026-9277: OS Command Injection in shell-quote via Object-Token Line Terminator Parsing Defect

Comments
2 min read
CVE-2026-11645: CVE-2026-11645: Out-of-Bounds Memory Access in Google Chrome V8 Engine

CVE-2026-11645: CVE-2026-11645: Out-of-Bounds Memory Access in Google Chrome V8 Engine

Comments
1 min read
CVE-2026-50751: CVE-2026-50751: Authentication Bypass in Check Point Security Gateway IKEv1 Legacy Validation

CVE-2026-50751: CVE-2026-50751: Authentication Bypass in Check Point Security Gateway IKEv1 Legacy Validation

Comments
2 min read
CVE-2026-39922: CVE-2026-39922: Server-Side Request Forgery in GeoNode Service Registration Endpoint

CVE-2026-39922: CVE-2026-39922: Server-Side Request Forgery in GeoNode Service Registration Endpoint

Comments
2 min read
CVE-2022-0492: CVE-2022-0492: Privilege Escalation and Container Escape via cgroups v1 release_agent

CVE-2022-0492: CVE-2022-0492: Privilege Escalation and Container Escape via cgroups v1 release_agent

Comments
3 min read
GHSA-G72G-R7M4-9X4G: GHSA-G72G-R7M4-9X4G: Insufficient Session Expiration of OAuth Tokens in NocoDB

GHSA-G72G-R7M4-9X4G: GHSA-G72G-R7M4-9X4G: Insufficient Session Expiration of OAuth Tokens in NocoDB

Comments
2 min read
GHSA-FGMC-2HQJ-86V4: GHSA-FGMC-2HQJ-86V4: Default Administrative Credentials in vantage6-server

GHSA-FGMC-2HQJ-86V4: GHSA-FGMC-2HQJ-86V4: Default Administrative Credentials in vantage6-server

Comments
2 min read
GHSA-X9F6-9RVM-MMRG: GHSA-X9F6-9RVM-MMRG: Improper Access Control and Volume Mount Isolation Bypass in vantage6 Node

GHSA-X9F6-9RVM-MMRG: GHSA-X9F6-9RVM-MMRG: Improper Access Control and Volume Mount Isolation Bypass in vantage6 Node

Comments
2 min read
CVE-2026-47760: CVE-2026-47760: Cross-Site Scripting (XSS) via SVG Namespace Sanitizer Bypass in TinyMCE

CVE-2026-47760: CVE-2026-47760: Cross-Site Scripting (XSS) via SVG Namespace Sanitizer Bypass in TinyMCE

Comments
2 min read
CVE-2026-47759: CVE-2026-47759: Stored Cross-Site Scripting (XSS) via Unsanitized data-mce-* Serialization Bypass in TinyMCE

CVE-2026-47759: CVE-2026-47759: Stored Cross-Site Scripting (XSS) via Unsanitized data-mce-* Serialization Bypass in TinyMCE

Comments
2 min read
CVE-2026-47762: CVE-2026-47762: Stored Cross-Site Scripting (XSS) in TinyMCE Protect Pattern Restoration

CVE-2026-47762: CVE-2026-47762: Stored Cross-Site Scripting (XSS) in TinyMCE Protect Pattern Restoration

Comments
2 min read
CVE-2026-47742: CVE-2026-47742: Missing Authorization and Client-Side Property Tampering in Shopper E-commerce Panel

CVE-2026-47742: CVE-2026-47742: Missing Authorization and Client-Side Property Tampering in Shopper E-commerce Panel

Comments
2 min read
CVE-2026-47745: CVE-2026-47745: Missing Authorization in Shopper Admin Panel Settings

CVE-2026-47745: CVE-2026-47745: Missing Authorization in Shopper Admin Panel Settings

Comments
2 min read
CVE-2026-47715: CVE-2026-47715: Insecure Direct Object Reference (IDOR) / Cross-Project Authorization Bypass in Bugsink

CVE-2026-47715: CVE-2026-47715: Insecure Direct Object Reference (IDOR) / Cross-Project Authorization Bypass in Bugsink

Comments
2 min read
CVE-2026-47716: CVE-2026-47716: Broken Object Level Authorization in Bugsink Bulk Issue Actions

CVE-2026-47716: CVE-2026-47716: Broken Object Level Authorization in Bugsink Bulk Issue Actions

Comments
2 min read
CVE-2026-47728: CVE-2026-47728: Multi-Tenant Isolation Bypass via Unscoped Debug ID Resolution in Bugsink

CVE-2026-47728: CVE-2026-47728: Multi-Tenant Isolation Bypass via Unscoped Debug ID Resolution in Bugsink

Comments
2 min read
GHSA-5X67-J5XG-C5GJ: GHSA-5X67-J5XG-C5GJ: Denial of Service via Uncontrolled Resource Consumption in Bugsink Ingestion Pipeline

GHSA-5X67-J5XG-C5GJ: GHSA-5X67-J5XG-C5GJ: Denial of Service via Uncontrolled Resource Consumption in Bugsink Ingestion Pipeline

Comments
2 min read
CVE-2026-47744: CVE-2026-47744: Improper Privilege Management and State Tampering in Shopper E-commerce Administration Panel

CVE-2026-47744: CVE-2026-47744: Improper Privilege Management and State Tampering in Shopper E-commerce Administration Panel

Comments
2 min read
CVE-2026-24425: CVE-2026-24425: Remote Code Execution via Sandbox Bypass in Twig Template Engine

CVE-2026-24425: CVE-2026-24425: Remote Code Execution via Sandbox Bypass in Twig Template Engine

Comments
2 min read
CVE-2026-47761: CVE-2026-47761: Stored Cross-Site Scripting in TinyMCE Media Plugin

CVE-2026-47761: CVE-2026-47761: Stored Cross-Site Scripting in TinyMCE Media Plugin

Comments
2 min read
GHSA-WX3M-WHQV-XV47: GHSA-WX3M-WHQV-XV47: Multiple Path Traversal and Symlink-Following Vulnerabilities in skillctl

GHSA-WX3M-WHQV-XV47: GHSA-WX3M-WHQV-XV47: Multiple Path Traversal and Symlink-Following Vulnerabilities in skillctl

Comments
2 min read
GHSA-XF4V-W5X5-PV79: GHSA-XF4V-W5X5-PV79: CSV Formula Injection in Spree Customer Export

GHSA-XF4V-W5X5-PV79: GHSA-XF4V-W5X5-PV79: CSV Formula Injection in Spree Customer Export

1
Comments
2 min read
CVE-2026-47694: CVE-2026-47694: Stored Cross-Site Scripting in WWBN AVideo Category Descriptions

CVE-2026-47694: CVE-2026-47694: Stored Cross-Site Scripting in WWBN AVideo Category Descriptions

1
Comments
2 min read
GHSA-JPVJ-WPMJ-H7RV: GHSA-JPVJ-WPMJ-H7RV: Supply Chain Compromise and Malicious Code Injection in @cap-js/openapi

GHSA-JPVJ-WPMJ-H7RV: GHSA-JPVJ-WPMJ-H7RV: Supply Chain Compromise and Malicious Code Injection in @cap-js/openapi

1
Comments
2 min read
CVE-2026-47696: CVE-2026-47696: Authenticated Wallet Credit Bypass in WWBN AVideo AuthorizeNet Plugin

CVE-2026-47696: CVE-2026-47696: Authenticated Wallet Credit Bypass in WWBN AVideo AuthorizeNet Plugin

Comments
2 min read
GHSA-8WHC-2WMV-WW35: GHSA-8whc-2wmv-ww35: Unauthenticated Stored DOM-based Cross-Site Scripting in WWBN AVideo YPTSocket Plugin

GHSA-8WHC-2WMV-WW35: GHSA-8whc-2wmv-ww35: Unauthenticated Stored DOM-based Cross-Site Scripting in WWBN AVideo YPTSocket Plugin

1
Comments
2 min read
CVE-2026-47676: CVE-2026-47676: Inconsistent Path Parsing and Slicing in Hono Framework Sub-Application Mounting

CVE-2026-47676: CVE-2026-47676: Inconsistent Path Parsing and Slicing in Hono Framework Sub-Application Mounting

Comments
2 min read
CVE-2026-47706: CVE-2026-47706: Application-Level Denial of Service via Uncontrolled Recursion in Strawberry GraphQL

CVE-2026-47706: CVE-2026-47706: Application-Level Denial of Service via Uncontrolled Recursion in Strawberry GraphQL

Comments
2 min read
CVE-2026-34077: CVE-2026-34077: Denial of Service and Unsafe Deserialization in React Router Single Fetch

CVE-2026-34077: CVE-2026-34077: Denial of Service and Unsafe Deserialization in React Router Single Fetch

Comments
2 min read
CVE-2026-47707: CVE-2026-47707: GraphQL Alias Amplification Bypass in Strawberry GraphQL MaxAliasesLimiter

CVE-2026-47707: CVE-2026-47707: GraphQL Alias Amplification Bypass in Strawberry GraphQL MaxAliasesLimiter

Comments
2 min read
CVE-2026-48710: CVE-2026-48710: Starlette BadHost HTTP Host-Header Path-Poisoning and Authentication Bypass

CVE-2026-48710: CVE-2026-48710: Starlette BadHost HTTP Host-Header Path-Poisoning and Authentication Bypass

Comments
3 min read
CVE-2026-20230: CVE-2026-20230: Server-Side Request Forgery in Cisco Unified Communications Manager WebDialer Service

CVE-2026-20230: CVE-2026-20230: Server-Side Request Forgery in Cisco Unified Communications Manager WebDialer Service

Comments
2 min read
CVE-2026-48526: CVE-2026-48526: Algorithm Confusion Vulnerability in PyJWT

CVE-2026-48526: CVE-2026-48526: Algorithm Confusion Vulnerability in PyJWT

Comments
2 min read
CVE-2026-23479: CVE-2026-23479: Use-After-Free Vulnerability in Redis Blocking-Client Command Re-Execution

CVE-2026-23479: CVE-2026-23479: Use-After-Free Vulnerability in Redis Blocking-Client Command Re-Execution

Comments
3 min read
CVE-2026-42211: CVE-2026-42211: Remote Code Execution via Insecure Deserialization in React Router Framework Mode

CVE-2026-42211: CVE-2026-42211: Remote Code Execution via Insecure Deserialization in React Router Framework Mode

Comments
2 min read
CVE-2026-47265: CVE-2026-47265: Cross-Origin Cookie Leakage in AIOHTTP Client Redirects

CVE-2026-47265: CVE-2026-47265: Cross-Origin Cookie Leakage in AIOHTTP Client Redirects

Comments
2 min read
CVE-2026-49144: CVE-2026-49144: Unauthenticated Arbitrary File Read via Path Traversal in BrowserStack Runner

CVE-2026-49144: CVE-2026-49144: Unauthenticated Arbitrary File Read via Path Traversal in BrowserStack Runner

Comments
2 min read
CVE-2026-49143: CVE-2026-49143: Unauthenticated Remote Code Execution in browserstack-runner

CVE-2026-49143: CVE-2026-49143: Unauthenticated Remote Code Execution in browserstack-runner

Comments
2 min read
GHSA-F9RX-7WF7-JR36: GHSA-F9RX-7WF7-JR36: Two-Factor Authentication Bypass and Passwordless API Key Creation in Froxlor

GHSA-F9RX-7WF7-JR36: GHSA-F9RX-7WF7-JR36: Two-Factor Authentication Bypass and Passwordless API Key Creation in Froxlor

Comments
2 min read
CVE-2026-42342: CVE-2026-42342: Uncontrolled Resource Consumption and Denial of Service in React Router and Remix

CVE-2026-42342: CVE-2026-42342: Uncontrolled Resource Consumption and Denial of Service in React Router and Remix

Comments
2 min read
CVE-2026-40181: CVE-2026-40181: Open Redirect Vulnerability in React Router

CVE-2026-40181: CVE-2026-40181: Open Redirect Vulnerability in React Router

Comments
2 min read
CVE-2022-31114: CVE-2022-31114: Reflected Cross-Site Scripting in Laravel Backpack Error Views

CVE-2022-31114: CVE-2022-31114: Reflected Cross-Site Scripting in Laravel Backpack Error Views

Comments
2 min read
CVE-2024-52011: CVE-2024-52011: Remote Command Injection in ViteJS launch-editor

CVE-2024-52011: CVE-2024-52011: Remote Command Injection in ViteJS launch-editor

Comments
2 min read
CVE-2025-10230: CVE-2025-10230: Samba Active Directory Domain Controller WINS Server Hook Command Injection

CVE-2025-10230: CVE-2025-10230: Samba Active Directory Domain Controller WINS Server Hook Command Injection

Comments
2 min read
GHSA-XQ3M-2V4X-88GG: CVE-2026-41242: Remote Code Execution via Dynamic Code Generation in protobufjs

GHSA-XQ3M-2V4X-88GG: CVE-2026-41242: Remote Code Execution via Dynamic Code Generation in protobufjs

Comments
2 min read
GHSA-63GR-G7JC-V8RG: GHSA-63GR-G7JC-V8RG: Missing Authentication in AgenticMail MCP HTTP Transport Layer

GHSA-63GR-G7JC-V8RG: GHSA-63GR-G7JC-V8RG: Missing Authentication in AgenticMail MCP HTTP Transport Layer

Comments
2 min read
CVE-2026-9354: CVE-2026-9354: Arbitrary Mass Mention Bypass in NousResearch hermes-agent Slack and Mattermost Adapters

CVE-2026-9354: CVE-2026-9354: Arbitrary Mass Mention Bypass in NousResearch hermes-agent Slack and Mattermost Adapters

Comments
2 min read
CVE-2026-9306: CVE-2026-9306: Unauthenticated Insecure Direct Object Reference (IDOR) in QuantumNous new-api Midjourney Relay

CVE-2026-9306: CVE-2026-9306: Unauthenticated Insecure Direct Object Reference (IDOR) in QuantumNous new-api Midjourney Relay

Comments
2 min read
GHSA-GGXF-37HM-9WQF: GHSA-GGXF-37HM-9WQF: Session Leakage via Unsafe Challenge Path Parsing in instagrapi

GHSA-GGXF-37HM-9WQF: GHSA-GGXF-37HM-9WQF: Session Leakage via Unsafe Challenge Path Parsing in instagrapi

Comments
2 min read
GHSA-QQQM-5547-774X: GHSA-QQQM-5547-774X: Unauthenticated Path Traversal in FileBrowser Quantum PATCH Handler

GHSA-QQQM-5547-774X: GHSA-QQQM-5547-774X: Unauthenticated Path Traversal in FileBrowser Quantum PATCH Handler

Comments
2 min read
CVE-2026-8723: CVE-2026-8723: Synchronous Denial of Service in qs npm Package via TypeError

CVE-2026-8723: CVE-2026-8723: Synchronous Denial of Service in qs npm Package via TypeError

Comments
2 min read
GHSA-7M8F-HGJQ-8GC9: GHSA-7M8F-HGJQ-8GC9: Pre-Authentication Denial of Service via Insecure Deserialization Order in aiosend

GHSA-7M8F-HGJQ-8GC9: GHSA-7M8F-HGJQ-8GC9: Pre-Authentication Denial of Service via Insecure Deserialization Order in aiosend

Comments
2 min read
GHSA-JQQ5-8PX3-9M6M: GHSA-JQQ5-8PX3-9M6M: Single-Byte Heap Overflow Bypass in ImageMagick JSON and YAML Encoders

GHSA-JQQ5-8PX3-9M6M: GHSA-JQQ5-8PX3-9M6M: Single-Byte Heap Overflow Bypass in ImageMagick JSON and YAML Encoders

Comments
2 min read
GHSA-VF33-6R7X-66XX: GHSA-VF33-6R7X-66XX: Division by Zero and Integer Overflow in ImageMagick Morphology

GHSA-VF33-6R7X-66XX: GHSA-VF33-6R7X-66XX: Division by Zero and Integer Overflow in ImageMagick Morphology

Comments
2 min read
GHSA-QV2Q-C278-PCH5: GHSA-qv2q-c278-pch5: Cryptographic Nonce Reuse and Information Disclosure in ImageMagick

GHSA-QV2Q-C278-PCH5: GHSA-qv2q-c278-pch5: Cryptographic Nonce Reuse and Information Disclosure in ImageMagick

Comments
2 min read
loading...