Announcements

CVE-2026-78003 (matched: wordpress)

  • 22nd August 2026
A security flaw has been found in the Mailgun for WordPress plugin, a tool used to link WordPress websites to the Mailgun email service. The vulnerability affects all versions of the plugin up to and including version 2.2.0.Unauthenticated attackers can exploit this issue to send requests using your website’s private Mailgun API key. This could ...
Continue reading

MLflow MLflow: MLflow Server-Side Request Forgery Vulnerability

  • 22nd August 2026
A security vulnerability has been identified in MLflow, a popular tool used to manage machine learning workflows that many website and application owners run as part of their hosted services. The flaw is a server-side request forgery issue, which could allow attackers to trick the MLflow tool into sending requests to internal systems or cloud ...
Continue reading

TrueConf Server: TrueConf Server Missing Authentication for Critical Function Vulnerability

  • 22nd August 2026
A security flaw has been found in TrueConf Server, a platform commonly used for video calls and team communication on hosted services. The issue is a missing authentication check for a critical system function, meaning no valid login or permission check is needed to access this feature. This vulnerability lets an unauthorized remote user who can ...
Continue reading

TrueConf Server: TrueConf Server Code Injection Vulnerability

  • 22nd August 2026
A security flaw has been found in TrueConf Server that is a code injection vulnerability, meaning it lets malicious, specially crafted input run unauthorized commands on the affected system.If an unauthorized remote attacker can access your TrueConf Server instance via the 4307/TCP network port, they could use a specially built script to break out ...
Continue reading