Announcements

CVE-2026-15981 (matched: wordpress)

  • 23rd July 2026
A security flaw has been identified in the SAML Single Sign On – SSO Login plugin for WordPress, a tool used to let users log in to websites with a single shared set of credentials. The issue affects all versions of the plugin up to and including 5.4.4.The vulnerability lets attackers completely bypass the plugin’s login verification process. ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 23rd July 2026
We’re reaching out to share details about a confirmed security vulnerability found in DD-WRT, a popular open-source firmware used for many routers that website and small business owners often use to manage their hosting and office network connections. The flaw is a type of coding error called a stack-based buffer overflow, which impacts the ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 23rd July 2026

Langflow contains an inclusion of functionality from untrusted control sphere vulnerability that allows remote attackers to execute arbitrary code on affected installations.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-0770

Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 23rd July 2026
A security flaw has been found in the core WordPress software used to run millions of websites. This flaw, called an interpretation conflict, could let bad actors perform SQL injection attacks on your site, and in some cases gain the ability to run unauthorized code on your WordPress installation.This vulnerability can be chained with a separate ...
Continue reading