Forem

CVE Reports profile picture

CVE Reports

CVEReports provides daily, automated deep-dives into the latest vulnerabilities, transforming emerging threats into comprehensive technical intelligence.

Joined Joined on  Personal website https://www.cvereports.com
GHSA-H343-GG57-2Q67: CVE-2026-27574: Remote Code Execution in OneUptime Probe via VM Sandbox Escape

GHSA-H343-GG57-2Q67: CVE-2026-27574: Remote Code Execution in OneUptime Probe via VM Sandbox Escape

Comments
2 min read
CVE-2026-30835: CVE-2026-30835: Database Metadata Leak via Malformed Regex in Parse Server

CVE-2026-30835: CVE-2026-30835: Database Metadata Leak via Malformed Regex in Parse Server

Comments
2 min read
CVE-2026-26018: CVE-2026-26018: Remote Denial of Service in CoreDNS Loop Detection Plugin via Predictable PRNG

CVE-2026-26018: CVE-2026-26018: Remote Denial of Service in CoreDNS Loop Detection Plugin via Predictable PRNG

Comments
2 min read
CVE-2026-29064: CVE-2026-29064: Path Traversal via Symlink Extraction in Zarf

CVE-2026-29064: CVE-2026-29064: Path Traversal via Symlink Extraction in Zarf

Comments
2 min read
CVE-2026-30228: CVE-2026-30228: Authorization Bypass in Parse Server Files API via readOnlyMasterKey

CVE-2026-30228: CVE-2026-30228: Authorization Bypass in Parse Server Files API via readOnlyMasterKey

Comments
2 min read
CVE-2026-30241: CVE-2026-30241: Missing Query Depth Validation in Mercurius GraphQL Subscriptions

CVE-2026-30241: CVE-2026-30241: Missing Query Depth Validation in Mercurius GraphQL Subscriptions

Comments
2 min read
CVE-2026-30229: CVE-2026-30229: Privilege Escalation via Read-Only Master Key in Parse Server

CVE-2026-30229: CVE-2026-30229: Privilege Escalation via Read-Only Master Key in Parse Server

Comments
2 min read
GHSA-9R75-G2CR-3H76: GHSA-9r75-g2cr-3h76: Predictable Webhook Tokens in Vercel Workflow

GHSA-9R75-G2CR-3H76: GHSA-9r75-g2cr-3h76: Predictable Webhook Tokens in Vercel Workflow

Comments
2 min read
CVE-2026-26017: CVE-2026-26017: CoreDNS ACL Bypass via TOCTOU in Plugin Chain

CVE-2026-26017: CVE-2026-26017: CoreDNS ACL Bypass via TOCTOU in Plugin Chain

Comments
2 min read
CVE-2026-3419: CVE-2026-3419: Content-Type Validation Bypass in Fastify via Regex Anchor Missing

CVE-2026-3419: CVE-2026-3419: Content-Type Validation Bypass in Fastify via Regex Anchor Missing

Comments
2 min read
CVE-2026-29783: CVE-2026-29783: Command Injection via Bash Parameter Expansion in GitHub Copilot CLI

CVE-2026-29783: CVE-2026-29783: Command Injection via Bash Parameter Expansion in GitHub Copilot CLI

Comments
2 min read
GHSA-FWHJ-785H-43HH: GHSA-FWHJ-785H-43HH: Denial of Service via Null Pointer Dereference in OliveTin

GHSA-FWHJ-785H-43HH: GHSA-FWHJ-785H-43HH: Denial of Service via Null Pointer Dereference in OliveTin

Comments
2 min read
CVE-2026-2833: CVE-2026-2833: HTTP Request Smuggling via Premature Upgrade in Cloudflare Pingora

CVE-2026-2833: CVE-2026-2833: HTTP Request Smuggling via Premature Upgrade in Cloudflare Pingora

Comments
2 min read
CVE-2026-2835: CVE-2026-2835: HTTP Request Smuggling in Cloudflare Pingora

CVE-2026-2835: CVE-2026-2835: HTTP Request Smuggling in Cloudflare Pingora

Comments
2 min read
GHSA-7RHV-H82H-VPJH: CVE-2026-30777: MFA Bypass in EC-CUBE Administrative Interface

GHSA-7RHV-H82H-VPJH: CVE-2026-30777: MFA Bypass in EC-CUBE Administrative Interface

Comments
2 min read
GHSA-MH23-RW7F-V5PQ: GHSA-MH23-RW7F-V5PQ: Malicious 'time-sync' Crate Exfiltrating Environment Secrets

GHSA-MH23-RW7F-V5PQ: GHSA-MH23-RW7F-V5PQ: Malicious 'time-sync' Crate Exfiltrating Environment Secrets

1
Comments
2 min read
CVE-2025-11143: CVE-2025-11143: URI Parsing Differential in Eclipse Jetty

CVE-2025-11143: CVE-2025-11143: URI Parsing Differential in Eclipse Jetty

Comments
2 min read
GHSA-X2G5-FVC2-GQVP: GHSA-X2G5-FVC2-GQVP: Insufficient Bcrypt Salt Rounds in Flowise

GHSA-X2G5-FVC2-GQVP: GHSA-X2G5-FVC2-GQVP: Insufficient Bcrypt Salt Rounds in Flowise

Comments
2 min read
GHSA-JC5M-WRP2-QQ38: GHSA-jc5m-wrp2-qq38: PII Disclosure via Flowise Forgot Password Endpoint

GHSA-JC5M-WRP2-QQ38: GHSA-jc5m-wrp2-qq38: PII Disclosure via Flowise Forgot Password Endpoint

Comments
2 min read
GHSA-5R2P-PJR8-7FH7: Remote Code Execution in AWS SageMaker Python SDK via Unsafe eval()

GHSA-5R2P-PJR8-7FH7: Remote Code Execution in AWS SageMaker Python SDK via Unsafe eval()

Comments
2 min read
CVE-2026-1605: CVE-2026-1605: Native Memory Leak in Eclipse Jetty GzipHandler

CVE-2026-1605: CVE-2026-1605: Native Memory Leak in Eclipse Jetty GzipHandler

Comments
2 min read
CVE-2026-2836: CVE-2026-2836: Host-Blind Cache Poisoning in Cloudflare Pingora

CVE-2026-2836: CVE-2026-2836: Host-Blind Cache Poisoning in Cloudflare Pingora

Comments
2 min read
CVE-2026-26196: CVE-2026-26196: Sensitive API Token Exposure via URL Query Parameters in Gogs

CVE-2026-26196: CVE-2026-26196: Sensitive API Token Exposure via URL Query Parameters in Gogs

Comments
2 min read
CVE-2026-26194: CVE-2026-26194: Command Option Injection in Gogs Release Deletion

CVE-2026-26194: CVE-2026-26194: Command Option Injection in Gogs Release Deletion

1
Comments
2 min read
CVE-2026-25048: CVE-2026-25048: Stack Exhaustion Denial of Service in xgrammar EBNF Parser

CVE-2026-25048: CVE-2026-25048: Stack Exhaustion Denial of Service in xgrammar EBNF Parser

Comments
2 min read
CVE-2026-27944: CVE-2026-27944: Unauthenticated Backup Download and Encryption Key Disclosure in Nginx UI

CVE-2026-27944: CVE-2026-27944: Unauthenticated Backup Download and Encryption Key Disclosure in Nginx UI

Comments
2 min read
CVE-2026-20122: CVE-2026-20122: Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API

CVE-2026-20122: CVE-2026-20122: Arbitrary File Overwrite in Cisco Catalyst SD-WAN Manager API

Comments
2 min read
CVE-2026-20079: CVE-2026-20079: Authentication Bypass & RCE in Cisco Secure FMC

CVE-2026-20079: CVE-2026-20079: Authentication Bypass & RCE in Cisco Secure FMC

Comments
2 min read
CVE-2026-20131: CVE-2026-20131: Unauthenticated RCE in Cisco Secure Firewall Management Center via Java Deserialization

CVE-2026-20131: CVE-2026-20131: Unauthenticated RCE in Cisco Secure Firewall Management Center via Java Deserialization

Comments
2 min read
CVE-2025-15558: CVE-2025-15558: Local Privilege Escalation via Uncontrolled Search Path in Docker CLI for Windows

CVE-2025-15558: CVE-2025-15558: Local Privilege Escalation via Uncontrolled Search Path in Docker CLI for Windows

Comments
2 min read
GHSA-HHJV-JQ77-CMVX: GHSA-HHJV-JQ77-CMVX: Android Shell Blocklist Bypass in Zeptoclaw via Argument Permutation

GHSA-HHJV-JQ77-CMVX: GHSA-HHJV-JQ77-CMVX: Android Shell Blocklist Bypass in Zeptoclaw via Argument Permutation

Comments
2 min read
CVE-2026-22719: CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations

CVE-2026-22719: CVE-2026-22719: Unauthenticated Command Injection in VMware Aria Operations

Comments
2 min read
GHSA-5WP8-Q9MX-8JX8: GHSA-5WP8-Q9MX-8JX8: Critical Shell Security Bypass in Zeptoclaw AI Runtime

GHSA-5WP8-Q9MX-8JX8: GHSA-5WP8-Q9MX-8JX8: Critical Shell Security Bypass in Zeptoclaw AI Runtime

Comments
2 min read
GHSA-9M84-WC28-W895: GHSA-9m84-wc28-w895: Incomplete CSRF Protection and Weak OTC Binding in Ghost

GHSA-9M84-WC28-W895: GHSA-9m84-wc28-w895: Incomplete CSRF Protection and Weak OTC Binding in Ghost

Comments
2 min read
GHSA-XHW7-JHMP-J62J: GHSA-XHW7-JHMP-J62J: Malicious 'dnp3times' Crate Exfiltrates Secrets via Typosquatting

GHSA-XHW7-JHMP-J62J: GHSA-XHW7-JHMP-J62J: Malicious 'dnp3times' Crate Exfiltrates Secrets via Typosquatting

Comments
2 min read
GHSA-QFFP-2RHF-9H96: GHSA-qffp-2rhf-9h96: Hardlink Path Traversal in node-tar via Drive-Relative Paths

GHSA-QFFP-2RHF-9H96: GHSA-qffp-2rhf-9h96: Hardlink Path Traversal in node-tar via Drive-Relative Paths

Comments
2 min read
CVE-2026-3125: CVE-2026-3125: SSRF via Differential Path Normalization in @opennextjs/cloudflare

CVE-2026-3125: CVE-2026-3125: SSRF via Differential Path Normalization in @opennextjs/cloudflare

Comments
2 min read
GHSA-W75W-9QV4-J5XJ: GHSA-W75W-9QV4-J5XJ: Path Traversal in dbt-common Archive Extraction

GHSA-W75W-9QV4-J5XJ: GHSA-W75W-9QV4-J5XJ: Path Traversal in dbt-common Archive Extraction

1
Comments
2 min read
GHSA-V2X6-WWFW-R2RQ: GHSA-v2x6-wwfw-r2rq: Path Traversal and Parameter Injection in Agentgateway

GHSA-V2X6-WWFW-R2RQ: GHSA-v2x6-wwfw-r2rq: Path Traversal and Parameter Injection in Agentgateway

Comments
2 min read
CVE-2026-3520: CVE-2026-3520: Denial of Service via Uncontrolled Recursion in Multer

CVE-2026-3520: CVE-2026-3520: Denial of Service via Uncontrolled Recursion in Multer

Comments
2 min read
GHSA-WF45-3GPW-VRQV: Malicious Rust Crate 'time_calibrators' Exfiltrates Environment Variables

GHSA-WF45-3GPW-VRQV: Malicious Rust Crate 'time_calibrators' Exfiltrates Environment Variables

Comments
2 min read
GHSA-WCCX-J62J-R448: Fickling Security Bypass: Incomplete Monkey-Patching in Safety Hooks

GHSA-WCCX-J62J-R448: Fickling Security Bypass: Incomplete Monkey-Patching in Safety Hooks

Comments
2 min read
GHSA-5HWF-RC88-82XM: CVE-2026-22609: Incomplete Blocklist in Fickling Pickle Analyzer Leads to Arbitrary Code Execution

GHSA-5HWF-RC88-82XM: CVE-2026-22609: Incomplete Blocklist in Fickling Pickle Analyzer Leads to Arbitrary Code Execution

Comments
2 min read
CVE-2026-29069: CVE-2026-29069: Unauthenticated Activation Email Trigger in Craft CMS

CVE-2026-29069: CVE-2026-29069: Unauthenticated Activation Email Trigger in Craft CMS

Comments
2 min read
CVE-2026-3351: CVE-2026-3351: Authorization Bypass in Canonical LXD Certificates API

CVE-2026-3351: CVE-2026-3351: Authorization Bypass in Canonical LXD Certificates API

Comments
2 min read
GHSA-JWF4-8WF4-JF2M: GHSA-JWF4-8WF4-JF2M: Critical Authorization Bypass in OpenClaw BlueBubbles Plugin

GHSA-JWF4-8WF4-JF2M: GHSA-JWF4-8WF4-JF2M: Critical Authorization Bypass in OpenClaw BlueBubbles Plugin

Comments
2 min read
GHSA-F6H3-846H-2R8W: GHSA-f6h3-846h-2r8w: Authorization Bypass in OpenClaw via Improper Recipient Validation

GHSA-F6H3-846H-2R8W: GHSA-f6h3-846h-2r8w: Authorization Bypass in OpenClaw via Improper Recipient Validation

Comments
2 min read
GHSA-W7J5-J98M-W679: GHSA-W7J5-J98M-W679: Excessive Privileges (Root Execution) in OpenClaw Containers

GHSA-W7J5-J98M-W679: GHSA-W7J5-J98M-W679: Excessive Privileges (Root Execution) in OpenClaw Containers

Comments
2 min read
GHSA-25PW-4H6W-QWVM: OpenClaw BlueBubbles Group Allowlist Bypass via DM Pairing Fallback

GHSA-25PW-4H6W-QWVM: OpenClaw BlueBubbles Group Allowlist Bypass via DM Pairing Fallback

Comments
2 min read
GHSA-4GC7-QCVF-38WG: CVE-2026-28363: Remote Code Execution in OpenClaw via Argument Injection

GHSA-4GC7-QCVF-38WG: CVE-2026-28363: Remote Code Execution in OpenClaw via Argument Injection

Comments
2 min read
GHSA-659F-22XC-98F2: GHSA-659F-22XC-98F2: Path Traversal via Symbolic Links in OpenClaw Webhook Transforms

GHSA-659F-22XC-98F2: GHSA-659F-22XC-98F2: Path Traversal via Symbolic Links in OpenClaw Webhook Transforms

Comments
2 min read
GHSA-V6X2-2QVM-6GV8: GHSA-V6X2-2QVM-6GV8: Critical Token Leak via Insecure Hashing Fallback in OpenClaw

GHSA-V6X2-2QVM-6GV8: GHSA-V6X2-2QVM-6GV8: Critical Token Leak via Insecure Hashing Fallback in OpenClaw

Comments
2 min read
GHSA-GW85-XP4Q-5GP9: GHSA-GW85-XP4Q-5GP9: Authorization Bypass in OpenClaw Synology Chat Extension

GHSA-GW85-XP4Q-5GP9: GHSA-GW85-XP4Q-5GP9: Authorization Bypass in OpenClaw Synology Chat Extension

Comments
2 min read
GHSA-8MF7-VV8W-HJR2: GHSA-8MF7-VV8W-HJR2: Remote Code Execution via Insecure SafeBins Fallback in OpenClaw

GHSA-8MF7-VV8W-HJR2: GHSA-8MF7-VV8W-HJR2: Remote Code Execution via Insecure SafeBins Fallback in OpenClaw

Comments
2 min read
GHSA-R9Q5-C7QC-P26W: GHSA-R9Q5-C7QC-P26W: Webhook Replay Vulnerability in OpenClaw Nextcloud Talk Integration

GHSA-R9Q5-C7QC-P26W: GHSA-R9Q5-C7QC-P26W: Webhook Replay Vulnerability in OpenClaw Nextcloud Talk Integration

Comments
2 min read
GHSA-JXRQ-8FM4-9P58: OpenClaw Archive Extraction Path Traversal via Symlinks

GHSA-JXRQ-8FM4-9P58: OpenClaw Archive Extraction Path Traversal via Symlinks

Comments
2 min read
GHSA-M8V2-6WWH-R4GC: GHSA-M8V2-6WWH-R4GC: Sandbox Escape via Symlink Manipulation in OpenClaw

GHSA-M8V2-6WWH-R4GC: GHSA-M8V2-6WWH-R4GC: Sandbox Escape via Symlink Manipulation in OpenClaw

Comments
2 min read
GHSA-792Q-QW95-F446: GHSA-792Q-QW95-F446: Authorization Bypass in OpenClaw Signal Reaction Handling

GHSA-792Q-QW95-F446: GHSA-792Q-QW95-F446: Authorization Bypass in OpenClaw Signal Reaction Handling

Comments
2 min read
GHSA-WPPH-CJGR-7C39: GHSA-WPPH-CJGR-7C39: Identity Collision in OpenClaw Group Policy Resolver

GHSA-WPPH-CJGR-7C39: GHSA-WPPH-CJGR-7C39: Identity Collision in OpenClaw Group Policy Resolver

Comments
2 min read
GHSA-JJ82-76V6-933R: GHSA-JJ82-76V6-933R: Execution Allowlist Bypass via Wrapper Injection in OpenClaw

GHSA-JJ82-76V6-933R: GHSA-JJ82-76V6-933R: Execution Allowlist Bypass via Wrapper Injection in OpenClaw

Comments
2 min read
loading...