DEV Community

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
CVE-2026-15603: CVE-2026-15603: Log Forging via Unescaped Unicode Line Separators in morgan Middleware

CVE-2026-15603: CVE-2026-15603: Log Forging via Unescaped Unicode Line Separators in morgan Middleware

Comments
2 min read
CVE-2026-82333: CVE-2026-82333: Remote Denial of Service via Sparse Array Manipulation in Multer

CVE-2026-82333: CVE-2026-82333: Remote Denial of Service via Sparse Array Manipulation in Multer

Comments
2 min read
CVE-2026-77063: CVE-2026-77063: File Size Limit Bypass via Asynchronous Race Condition in Multer

CVE-2026-77063: CVE-2026-77063: File Size Limit Bypass via Asynchronous Race Condition in Multer

Comments
2 min read
CVE-2026-77037: CVE-2026-77037: File Descriptor Leak and Denial of Service in Multer Disk Storage

CVE-2026-77037: CVE-2026-77037: File Descriptor Leak and Denial of Service in Multer Disk Storage

Comments
2 min read
CVE-2026-77078: CVE-2026-77078: Remote Denial of Service in Multer Middleware via Array Suffix Handling

CVE-2026-77078: CVE-2026-77078: Remote Denial of Service in Multer Middleware via Array Suffix Handling

Comments
2 min read
GHSA-2Q42-4Q24-7RGV: Path Traversal Vulnerability in Microsoft TypeSpec Core and Emitter Packages

GHSA-2Q42-4Q24-7RGV: Path Traversal Vulnerability in Microsoft TypeSpec Core and Emitter Packages

Comments
2 min read
GHSA-CC9R-2J5M-2M83: GHSA-CC9R-2J5M-2M83: Parser Differential and Domain Validation Bypass in Nodemailer

GHSA-CC9R-2J5M-2M83: GHSA-CC9R-2J5M-2M83: Parser Differential and Domain Validation Bypass in Nodemailer

Comments
2 min read
GHSA-2X7J-588G-CCC2: GHSA-2x7j-588g-ccc2: Algorithmic Complexity Denial of Service in Nodemailer

GHSA-2X7J-588G-CCC2: GHSA-2x7j-588g-ccc2: Algorithmic Complexity Denial of Service in Nodemailer

Comments
2 min read
GHSA-WMMP-3585-3RMP: GHSA-WMMP-3585-3RMP: IDN/Punycode Domain Allow-list Bypass in Nodemailer

GHSA-WMMP-3585-3RMP: GHSA-WMMP-3585-3RMP: IDN/Punycode Domain Allow-list Bypass in Nodemailer

Comments
1 min read
CVE-2026-86996: CVE-2026-86996: Missing Authorization in n8n AI Agent Workflow Tool Execution

CVE-2026-86996: CVE-2026-86996: Missing Authorization in n8n AI Agent Workflow Tool Execution

Comments
2 min read
CVE-2026-83612: CVE-2026-83612: Algorithmic Complexity and Denial of Service via Output Amplification in xmldom

CVE-2026-83612: CVE-2026-83612: Algorithmic Complexity and Denial of Service via Output Amplification in xmldom

Comments
2 min read
CVE-2026-78679: CVE-2026-78679: Arbitrary File Read via Command-Line Option Injection in GitPython

CVE-2026-78679: CVE-2026-78679: Arbitrary File Read via Command-Line Option Injection in GitPython

Comments
2 min read
CVE-2026-78677: CVE-2026-78677: Path Traversal and Arbitrary File Write in GitPython

CVE-2026-78677: CVE-2026-78677: Path Traversal and Arbitrary File Write in GitPython

Comments
2 min read
CVE-2026-72925: CVE-2026-72925: Cross-Site Scripting via Improper JSON Escaping in SWC HTML Minifier

CVE-2026-72925: CVE-2026-72925: Cross-Site Scripting via Improper JSON Escaping in SWC HTML Minifier

Comments
2 min read
CVE-2026-79674: CVE-2026-79674: Path Sandbox Bypass in NLTK CorpusReader Constructors

CVE-2026-79674: CVE-2026-79674: Path Sandbox Bypass in NLTK CorpusReader Constructors

Comments
2 min read
CVE-2026-12259: CVE-2026-12259: Improper Integrity Verification (Extract-Before-Verify) in NLTK Downloader

CVE-2026-12259: CVE-2026-12259: Improper Integrity Verification (Extract-Before-Verify) in NLTK Downloader

Comments
2 min read
CVE-2026-75856: CVE-2026-75856: Server-Side Request Forgery (SSRF) Bypass via DNS Resolution TOCTOU in CodeWhale

CVE-2026-75856: CVE-2026-75856: Server-Side Request Forgery (SSRF) Bypass via DNS Resolution TOCTOU in CodeWhale

Comments
2 min read
CVE-2026-75912: CVE-2026-75912: Argument Injection and Arbitrary File Disclosure in CodeWhale Git Tools

CVE-2026-75912: CVE-2026-75912: Argument Injection and Arbitrary File Disclosure in CodeWhale Git Tools

Comments
2 min read
CVE-2026-63735: CVE-2026-63735: Cross-Tenant Authorization Bypass in SurrealDB Custom API Routing Handler

CVE-2026-63735: CVE-2026-63735: Cross-Tenant Authorization Bypass in SurrealDB Custom API Routing Handler

Comments
2 min read
CVE-2026-63733: CVE-2026-63733: Incorrect Authorization in SurrealDB Permissions Clause

CVE-2026-63733: CVE-2026-63733: Incorrect Authorization in SurrealDB Permissions Clause

Comments
2 min read
CVE-2026-72799: CVE-2026-72799: Missing Authorization in SiYuan Filetree Path-Resolution API

CVE-2026-72799: CVE-2026-72799: Missing Authorization in SiYuan Filetree Path-Resolution API

Comments
2 min read
CVE-2026-72798: CVE-2026-72798: Missing Authorization and Information Disclosure in SiYuan renderAttributeView

CVE-2026-72798: CVE-2026-72798: Missing Authorization and Information Disclosure in SiYuan renderAttributeView

Comments
2 min read
CVE-2026-72797: CVE-2026-72797: Missing Authorization in SiYuan Notebook Metadata Endpoint

CVE-2026-72797: CVE-2026-72797: Missing Authorization in SiYuan Notebook Metadata Endpoint

Comments
2 min read
CVE-2026-72794: CVE-2026-72794: Cryptographic Key Leakage and Session Forgery in SiYuan

CVE-2026-72794: CVE-2026-72794: Cryptographic Key Leakage and Session Forgery in SiYuan

Comments
2 min read
CVE-2026-72795: CVE-2026-72795: Missing Authorization in SiYuan Block DOM Rendering

CVE-2026-72795: CVE-2026-72795: Missing Authorization in SiYuan Block DOM Rendering

Comments
2 min read
CVE-2026-72793: CVE-2026-72793: Information Disclosure and Session Forgery in SiYuan Note-Taking Application

CVE-2026-72793: CVE-2026-72793: Information Disclosure and Session Forgery in SiYuan Note-Taking Application

Comments
2 min read
CVE-2026-72792: CVE-2026-72792: Information Disclosure via Tag API Endpoint in SiYuan

CVE-2026-72792: CVE-2026-72792: Information Disclosure via Tag API Endpoint in SiYuan

Comments
2 min read
CVE-2026-71486: CVE-2026-71486: Uncontrolled Resource Consumption in vLLM Derender Endpoints

CVE-2026-71486: CVE-2026-71486: Uncontrolled Resource Consumption in vLLM Derender Endpoints

Comments
2 min read
CVE-2026-73555: CVE-2026-73555: Environment and Information Disclosure via Exception Handling in vLLM

CVE-2026-73555: CVE-2026-73555: Environment and Information Disclosure via Exception Handling in vLLM

Comments
2 min read
CVE-2026-73556: CVE-2026-73556: Regular Expression Denial of Service (ReDoS) in vLLM lm-format-enforcer Backend

CVE-2026-73556: CVE-2026-73556: Regular Expression Denial of Service (ReDoS) in vLLM lm-format-enforcer Backend

Comments
2 min read
CVE-2026-73557: CVE-2026-73557: Race Condition in PyTorch Tensor Invariant Checks within vLLM Engine

CVE-2026-73557: CVE-2026-73557: Race Condition in PyTorch Tensor Invariant Checks within vLLM Engine

Comments
2 min read
CVE-2026-73842: CVE-2026-73842: Missing Authentication and Authorization on Internal Management Listener in OpenChoreo cluster-gateway

CVE-2026-73842: CVE-2026-73842: Missing Authentication and Authorization on Internal Management Listener in OpenChoreo cluster-gateway

Comments
2 min read
GHSA-7Q9C-HPX7-9CWM: GHSA-7Q9C-HPX7-9CWM: Unauthenticated Remote Shutdown in @typespec/spector Mock Server

GHSA-7Q9C-HPX7-9CWM: GHSA-7Q9C-HPX7-9CWM: Unauthenticated Remote Shutdown in @typespec/spector Mock Server

Comments
2 min read
CVE-2026-72796: CVE-2026-72796: Access Control Bypass via Static Routes in SiYuan

CVE-2026-72796: CVE-2026-72796: Access Control Bypass via Static Routes in SiYuan

Comments
2 min read
CVE-2026-75858: CVE-2026-75858: Silent Remote Code Execution via Approval Bypass in CodeWhale Interactive Tools

CVE-2026-75858: CVE-2026-75858: Silent Remote Code Execution via Approval Bypass in CodeWhale Interactive Tools

Comments
2 min read
CVE-2026-75911: CVE-2026-75911: Remote Code Execution via Configuration Override in CodeWhale

CVE-2026-75911: CVE-2026-75911: Remote Code Execution via Configuration Override in CodeWhale

Comments
2 min read
CVE-2026-75914: CVE-2026-75914: Improper Link Resolution and Path Traversal in CodeWhale image_analyze Tool

CVE-2026-75914: CVE-2026-75914: Improper Link Resolution and Path Traversal in CodeWhale image_analyze Tool

Comments
2 min read
CVE-2026-63376: CVE-2026-63376: Prototype Pollution via Path Desynchronization in toml-node

CVE-2026-63376: CVE-2026-63376: Prototype Pollution via Path Desynchronization in toml-node

Comments
2 min read
CVE-2026-69083: CVE-2026-69083: Unauthenticated SQL Injection and SQL Command Execution in SiYuan Full-Text Search API

CVE-2026-69083: CVE-2026-69083: Unauthenticated SQL Injection and SQL Command Execution in SiYuan Full-Text Search API

Comments
2 min read
CVE-2026-68587: CVE-2026-68587: Broken Access Control in SiYuan Note Transaction Endpoints

CVE-2026-68587: CVE-2026-68587: Broken Access Control in SiYuan Note Transaction Endpoints

Comments
2 min read
CVE-2026-68586: CVE-2026-68586: Missing Authorization in SiYuan Backlink Content Endpoints Allows Information Disclosure

CVE-2026-68586: CVE-2026-68586: Missing Authorization in SiYuan Backlink Content Endpoints Allows Information Disclosure

Comments
2 min read
CVE-2026-68585: CVE-2026-68585: Metadata Disclosure via Missing Authorization in SiYuan API

CVE-2026-68585: CVE-2026-68585: Metadata Disclosure via Missing Authorization in SiYuan API

Comments
2 min read
CVE-2026-72812: CVE-2026-72812: Broken Access Control and SQL Injection in SiYuan

CVE-2026-72812: CVE-2026-72812: Broken Access Control and SQL Injection in SiYuan

Comments
2 min read
CVE-2026-72811: CVE-2026-72811: Remote SQL Injection in SiYuan Backlink and Mention Search Engine

CVE-2026-72811: CVE-2026-72811: Remote SQL Injection in SiYuan Backlink and Mention Search Engine

Comments
2 min read
CVE-2026-72810: CVE-2026-72810: Publish-Boundary Bypass and Real-Time Data Leakage via WebSocket Session Pollution in SiYuan

CVE-2026-72810: CVE-2026-72810: Publish-Boundary Bypass and Real-Time Data Leakage via WebSocket Session Pollution in SiYuan

Comments
2 min read
CVE-2026-72809: CVE-2026-72809: Authentication Bypass in SiYuan via Localhost Trust Spoofing

CVE-2026-72809: CVE-2026-72809: Authentication Bypass in SiYuan via Localhost Trust Spoofing

Comments
2 min read
CVE-2026-72808: CVE-2026-72808: Unauthorized PDF Annotation Access in SiYuan Knowledge Management System

CVE-2026-72808: CVE-2026-72808: Unauthorized PDF Annotation Access in SiYuan Knowledge Management System

Comments
2 min read
CVE-2026-72807: CVE-2026-72807: Second-Order SQL Injection via Attribute View Templates in SiYuan

CVE-2026-72807: CVE-2026-72807: Second-Order SQL Injection via Attribute View Templates in SiYuan

Comments
2 min read
CVE-2026-72806: CVE-2026-72806: Missing Authorization in SiYuan Attribute View Rendering Leads to Information Disclosure

CVE-2026-72806: CVE-2026-72806: Missing Authorization in SiYuan Attribute View Rendering Leads to Information Disclosure

Comments
2 min read
CVE-2026-72805: CVE-2026-72805: Missing Authorization in SiYuan Note Block APIs Leads to Information Disclosure

CVE-2026-72805: CVE-2026-72805: Missing Authorization in SiYuan Note Block APIs Leads to Information Disclosure

Comments
2 min read
CVE-2026-72804: CVE-2026-72804: Authentication Bypass and Sensitive Information Exposure in SiYuan Graph Endpoints

CVE-2026-72804: CVE-2026-72804: Authentication Bypass and Sensitive Information Exposure in SiYuan Graph Endpoints

Comments
2 min read
CVE-2026-72802: CVE-2026-72802: Sensitive Information Disclosure via Administrative Asset Resolvers in SiYuan Note

CVE-2026-72802: CVE-2026-72802: Sensitive Information Disclosure via Administrative Asset Resolvers in SiYuan Note

Comments
3 min read
CVE-2026-72801: CVE-2026-72801: Information Disclosure of Cryptographic Key Material in SiYuan

CVE-2026-72801: CVE-2026-72801: Information Disclosure of Cryptographic Key Material in SiYuan

Comments
2 min read
CVE-2026-72800: CVE-2026-72800: Missing Authorization in SiYuan Personal Knowledge Management System

CVE-2026-72800: CVE-2026-72800: Missing Authorization in SiYuan Personal Knowledge Management System

Comments
2 min read
CVE-2026-72803: CVE-2026-72803: Information Disclosure via Missing Authorization in SiYuan API

CVE-2026-72803: CVE-2026-72803: Information Disclosure via Missing Authorization in SiYuan API

Comments
2 min read
GHSA-7J72-F6WG-CXW6: CVE-2026-68584: Authentication Bypass via Auxiliary Content Endpoints in SiYuan

GHSA-7J72-F6WG-CXW6: CVE-2026-68584: Authentication Bypass via Auxiliary Content Endpoints in SiYuan

Comments
3 min read
CVE-2026-77465: CVE-2026-77465: Uncontrolled Recursion in toml-node Deserializer Leads to Denial of Service

CVE-2026-77465: CVE-2026-77465: Uncontrolled Recursion in toml-node Deserializer Leads to Denial of Service

Comments
2 min read
CVE-2026-73295: CVE-2026-73295: DOM-based Cross-Site Scripting (XSS) in Material for MkDocs Search Suggestions

CVE-2026-73295: CVE-2026-73295: DOM-based Cross-Site Scripting (XSS) in Material for MkDocs Search Suggestions

Comments
2 min read
CVE-2026-71869: CVE-2026-71869: Remote Code Execution in Orval via OpenAPI Default Value Template Literal Injection

CVE-2026-71869: CVE-2026-71869: Remote Code Execution in Orval via OpenAPI Default Value Template Literal Injection

Comments
2 min read
CVE-2026-61625: CVE-2026-61625: Arbitrary File Write via Path Traversal in VictoriaMetrics vmrestore

CVE-2026-61625: CVE-2026-61625: Arbitrary File Write via Path Traversal in VictoriaMetrics vmrestore

Comments
2 min read
loading...