Announcements

CVE-2026-44172 (matched: mariadb)

  • 30th July 2026
A security flaw has been found in MariaDB, the widely used open-source database software many websites rely on to store user data, site content, and other information. The issue impacts MariaDB versions 3.3.18 and 3.4.8.Normally, websites use a standard security tool called mysql_real_escape_string to block SQL injection attacks, which happen when ...
Continue reading

CVE-2026-46634 (matched: php)

  • 30th July 2026
This security notice applies to PHP-powered websites that use the Twig template tool, a popular utility developers use to build consistent page layouts and reusable content components.If your site uses Twig version 3.9.0 up to 3.26.0 and has Twig's sandbox feature enabled (a built-in security tool designed to restrict what templates can do to ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 30th July 2026
A security flaw has been identified in the Arista VeloCloud Orchestrator On-Prem, a tool used to manage VeloCloud networking deployments. This flaw is an OS command injection vulnerability, which means an unauthorized user from a remote location could send and run unapproved commands on the affected system.If this vulnerability is successfully ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 30th July 2026
A security vulnerability has been found in Fortinet FortiOS, a network security platform. This flaw could let an unauthorized remote person access sensitive data stored on the system by sending specially crafted web requests. It also bypasses an existing patch for a known issue related to symbolic link file persistence that has been linked to past ...
Continue reading