Announcements

CVE-2026-73533 (matched: php)

  • 14th August 2026
Ninja Tables Pro 5.2.11 contains an embedded malicious code vulnerability introduced via a tampered plugin build served through a decommissioned update server. The tampered build introduced a rogue PHP file (app/Library/updater/NinjaTableDataSync.php) that established a backdoor REST API endpoint, dropped persistent PHP files in mu-plugins and ...
Continue reading

CVE-2026-34184 (matched: php)

  • 14th August 2026
A security flaw has been found in AlanWeb SCADA software. The software fails to require proper authorization to access certain folders on systems where it is installed. This means unauthorized users could read every file stored in those folders, and even run some of the files, including PHP scripts linked to the system's connected database.This ...
Continue reading

Metabase Metabase: Metabase SQL Injection Vulnerability

  • 14th August 2026
A security vulnerability has been identified in Metabase, a common tool used for website data reporting and analysis. This flaw is a type of code injection that allows an unauthenticated (no account required) remote attacker to send unauthorized commands directly to the Metabase application’s database.If exploited, the attacker will gain full ...
Continue reading

Microsoft Windows Ancillary Function Driver for WinSock : Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

  • 14th August 2026
A security vulnerability has been identified in a core Windows system component called the Ancillary Function Driver for WinSock, which handles networking functions for Windows servers. This is a "use-after-free" type flaw, a weakness that occurs when a system attempts to access a section of memory that has already been marked for reuse by other ...
Continue reading