A critical security vulnerability tracked as CVE-2026-60363 has been identified in the Apache Plugin component of Oracle HTTP Server, part of Oracle Fusion Middleware. Only versions 12.2.1.4.0 and 14.1.2.0.0 of this software are affected by the flaw, which carries a severity rating of 9.8 out of 10.
The vulnerability is very easy to exploit: an ...
Continue reading
MariaDB server is a community developed fork of MySQL server. In versions 3.3.18 and 3.4.8, an application that was taking non-validated user input, escaping it with mysql_real_escape_string() and sending it to the database using text protocol and big5 character set was vulnerable to SQL injections, even though mysql_real_escape_string() was ...
Continue reading
A security vulnerability has been identified in the JCE editor extension, a tool many site owners use to edit content on Joomla websites. This flaw allows people who do not have valid login credentials for your site to create new custom profiles for the JCE editor.
These unauthorized profiles can be used to upload and run harmful code on your ...
Continue reading
A security flaw tracked as CVE-2026-48687 has been found in FastNetMon Community Edition, affecting all versions up to 1.2.9. The issue exists in the tool’s Juniper router integration plugin, and could allow unauthorized commands to run on servers where FastNetMon is installed.
The problem occurs because the plugin builds log-related shell ...
Continue reading