Skip to content
Navigation menu
Search
Powered by Algolia
Search
Log in
Create account
DEV Community
Close
#
cve
Follow
Hide
Posts
Left menu
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
Right menu
nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand
Oleg Usoltsev
Oleg Usoltsev
Oleg Usoltsev
Follow
Aug 13
nginx is not the bug. Two lines of your config are. CVE-2026-42945 on a live stand
#
security
#
nginx
#
devops
#
cve
Comments
Add Comment
17 min read
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)
Santosh Kumar Puppala
Santosh Kumar Puppala
Santosh Kumar Puppala
Follow
Aug 7
A text message that runs a command: OS command injection in Gammu SMSD (GHSA-9vjj-v46c-c5qf)
#
security
#
cve
#
linux
#
appsec
Comments
2
 comments
6 min read
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network
Santosh Kumar Puppala
Santosh Kumar Puppala
Santosh Kumar Puppala
Follow
Aug 7
They scoped the customer and forgot the customer's ledger — a High-severity cross-tenant BOLA in Open Food Network
#
security
#
cve
#
ruby
#
appsec
Comments
Add Comment
6 min read
It refused to run a dangerous option. I wrote it one character shorter, and it ran
Oleg Usoltsev
Oleg Usoltsev
Oleg Usoltsev
Follow
Aug 3
It refused to run a dangerous option. I wrote it one character shorter, and it ran
#
security
#
python
#
devops
#
cve
Comments
1
 comment
9 min read
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution
Huynh Kien Minh
Huynh Kien Minh
Huynh Kien Minh
Follow
Aug 1
Deep-Dive Technical Write-up by Huynh Kien Minh: CVE-2026-13157 — Theme Demo Import Arbitrary File Upload to Remote Code Execution
#
cve
#
wordpress
#
security
#
rce
Comments
Add Comment
6 min read
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation
Huynh Kien Minh
Huynh Kien Minh
Huynh Kien Minh
Follow
Aug 1
Huynh Kien Minh: CVE-2026-13152 — Custom Fields Account Registration For WooCommerce Privilege Escalation
#
security
#
wordpress
#
cve
#
bugbounty
Comments
Add Comment
4 min read
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer
CVE Reports
CVE Reports
CVE Reports
Follow
Jul 23
GHSA-GX64-GJ6P-PC4C: GHSA-GX64-GJ6P-PC4C: Stored Cross-Site Scripting in JupyterLab Image Viewer
#
security
#
cve
#
cybersecurity
#
ghsa
Comments
Add Comment
2 min read
30 CVEs filed against MCP servers in 60 days — here's how we're fixing this
Edison Flores
Edison Flores
Edison Flores
Follow
Jul 7
30 CVEs filed against MCP servers in 60 days — here's how we're fixing this
#
mcp
#
security
#
cve
#
vulnerabilities
Comments
Add Comment
2 min read
Aikido buys Root to patch open source in place, without the upgrade dance
Leo
Leo
Leo
Follow
Jul 1
Aikido buys Root to patch open source in place, without the upgrade dance
#
supplychain
#
cve
#
dependencies
#
security
Comments
Add Comment
4 min read
MITRE CVE ID Request and Support Follow-Up: No Confirmation Email Received Despite Anti-Filter Measures
Ksenia Rudneva
Ksenia Rudneva
Ksenia Rudneva
Follow
Jun 26
MITRE CVE ID Request and Support Follow-Up: No Confirmation Email Received Despite Anti-Filter Measures
#
cve
#
cybersecurity
#
mitre
#
communication
1
 reaction
Comments
Add Comment
8 min read
CVE Severity: Risk-Based Prioritization
Nargiz Naghiyeva
Nargiz Naghiyeva
Nargiz Naghiyeva
Follow
Jun 21
CVE Severity: Risk-Based Prioritization
#
cybersecurity
#
cve
Comments
Add Comment
2 min read
How to Actually Protect Yourself From wp2shell (Not Just "Update WordPress")
Aditya Pidurkar
Aditya Pidurkar
Aditya Pidurkar
Follow
Jul 22
How to Actually Protect Yourself From wp2shell (Not Just "Update WordPress")
#
wordpress
#
wp2shell
#
cve
#
cybersecurity
Comments
2
 comments
5 min read
How Attackers Find Vulnerable Applications — And How to Stay One Step Ahead
Vulert
Vulert
Vulert
Follow
Jun 18
How Attackers Find Vulnerable Applications — And How to Stay One Step Ahead
#
vulnerableapplications
#
applicationsecurity
#
cve
#
vulnerabilitymonitoring
Comments
Add Comment
7 min read
The HTTP Header That Could Execute Linux Commands: Understanding Shellshock
Arashad Dodhiya
Arashad Dodhiya
Arashad Dodhiya
Follow
Jun 5
The HTTP Header That Could Execute Linux Commands: Understanding Shellshock
#
devops
#
cybersecurity
#
linux
#
cve
1
 reaction
Comments
Add Comment
4 min read
CVE-2026-48710: CVE-2026-48710: Starlette BadHost HTTP Host-Header Path-Poisoning and Authentication Bypass
CVE Reports
CVE Reports
CVE Reports
Follow
Jun 4
CVE-2026-48710: CVE-2026-48710: Starlette BadHost HTTP Host-Header Path-Poisoning and Authentication Bypass
#
security
#
cve
#
cybersecurity
Comments
Add Comment
3 min read
đź‘‹
Sign in
for the ability to sort posts by
relevant
,
latest
, or
top
.
We're a place where coders share, stay up-to-date and grow their careers.
Log in
Create account