Announcements

CVE-2026-44172 (matched: mariadb)

  • 29th July 2026
A security vulnerability has been identified in specific older versions of MariaDB, a widely used open-source database software that powers many websites to store content, user information, and other site data. The flaw only impacts MariaDB versions 3.3.18 and 3.4.8. For sites running these affected versions with the big5 character set enabled, a ...
Continue reading

CVE-2026-46634 (matched: php)

  • 29th July 2026
Twig is a popular tool used to build dynamic content for PHP websites, such as reusable page layouts, personalized user displays, and consistent site components, without needing to rewrite the same code repeatedly.A security flaw exists in Twig versions 3.9.0 up to 3.26.0 that impacts sites using Twig's sandbox feature, a built-in safeguard ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 29th July 2026
A security vulnerability has been identified in the Arista VeloCloud Orchestrator On-Prem platform. This is an OS command injection flaw, meaning a remote attacker could send specially crafted requests to run unauthorized system commands on the affected system.If successfully exploited, this could let the attacker access restricted internal ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 29th July 2026
A security vulnerability has been identified in Fortinet FortiOS, a widely used network and cybersecurity platform. This flaw could expose sensitive information stored on the system to unauthorized parties, if an attacker sends specially crafted web requests to the platform.This issue cannot be exploited to gain initial access to a system. An ...
Continue reading