Announcements

CVE-2026-60363 (matched: apache http server)

  • 23rd July 2026
There is a critical security vulnerability in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. The affected software versions are 12.2.1.4.0 and 14.1.2.0.0.This flaw is easily exploitable, and does not require an attacker to have any login credentials for the server. Any user with network access to the server ...
Continue reading

CVE-2026-8711 (matched: nginx)

  • 23rd July 2026
A security vulnerability has been identified in the NGINX JavaScript feature, a tool some websites use to add custom, dynamic functionality. This flaw only affects sites that meet two specific conditions: the js_fetch_proxy setting is configured to use at least one value controlled by website visitors (such as data from HTTP request headers, URL ...
Continue reading

CVE-2026-44172 (matched: mariadb)

  • 23rd July 2026
A security flaw has been identified in MariaDB server versions 3.3.18 and 3.4.8. MariaDB is a community-developed fork of MySQL, a common database system many websites use to store content, user information, and other important data. This flaw lets malicious user input slip past a standard built-in security tool that is supposed to block it from ...
Continue reading

CVE-2026-15981 (matched: php)

  • 23rd July 2026
A security vulnerability has been identified in the SAML Single Sign On (SSO Login) plugin for WordPress, impacting all versions up to and including 5.4.4. The flaw is an authentication bypass bug that lets unauthenticated attackers skip the plugin's normal login verification process entirely. This means someone without a valid account for your ...
Continue reading