Announcements

CVE-2025-40690 (matched: php)

  • 2nd October 2026

SQL Injection in Online Fire Reporting System v1.2 by PHPGurukul. This vulnerability allows an attacker to retrieve, create, update and delete database via 'teamid' parameter in the endpoint '/ofrs/admin/edit-team.php'.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2025-40690

Continue reading

CVE-2025-10079 (matched: php)

  • 2nd October 2026
A flaw has been found in PHPGurukul Small CRM 4.0. Affected by this vulnerability is an unknown functionality of the file /get-quote.php. Executing manipulation of the argument Contact can lead to sql injection. The attack can be executed remotely. The exploit has been published and may be used.Source: NVD (National Vulnerability Database) — ...
Continue reading

Apple Multiple Products: Apple Multiple Products Out-of-Bounds Write Vulnerability

  • 2nd October 2026

Apple iOS, macOS, and iPadOS contain an out-of-bounds write vulnerability in CoreGraphics that may lead to arbitrary code execution.

Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-86950

Continue reading

Cisco Catalyst SD-WAN Manager: Cisco Catalyst SD-WAN Manager Hex Encoding Vulnerability

  • 2nd October 2026
Cisco Catalyst SD-WAN Manager contains a hex encoding vulnerability that could allow an unauthenticated, remote attacker to access an affected system with privileges of the admin user due to improper handling of URI encoding in an HTTP request.Source: CISA Known Exploited Vulnerabilities Catalog — https://nvd.nist.gov/vuln/detail/CVE-2026-76504
Continue reading