Announcements

CVE-2019-11049 (matched: php)

  • 20th August 2026
In PHP versions 7.3.x below 7.3.13 and 7.4.0 on Windows, when supplying custom headers to mail() function, due to mistake introduced in commit 78f4b4a2dcf92ddbccea1bb95f8390a18ac3342e, if the header is supplied in lowercase, this can result in double-freeing certain memory locations.Source: NVD (National Vulnerability Database) — ...
Continue reading

CVE-2026-18315 (matched: wordpress)

  • 20th August 2026
A security vulnerability has been found in the TrueBooker – Appointment Booking and Scheduler System plugin for WordPress, affecting all versions up to and including 1.2.6. The issue is an authorization bypass caused by a specific plugin tool not requiring any login or permission verification before processing user-supplied input.This gap allows ...
Continue reading

Ray-Project Ray: Ray-Project Ray Code Injection Vulnerability

  • 20th August 2026
A security vulnerability has been discovered in Ray-Project Ray, a popular development tool used by teams to build and test applications. This is a code injection flaw, which means an attacker could potentially run unauthorized, malicious code on any system that has this tool installed. Developers who use Ray as part of their development workflow ...
Continue reading

Apple macOS: Apple macOS Improper Authentication Vulnerability

  • 20th August 2026
A security vulnerability has been identified in Apple’s macOS operating system. The flaw impacts the built-in Screen Sharing feature, a tool that lets users remotely access and control a Mac from another device. Due to this issue, an attacker who is connected to the same local network as a Mac running macOS could access Screen Sharing without ...
Continue reading