Announcements

CVE-2026-34184 (matched: php)

  • 14th August 2026
A security flaw has been found in AlanWeb SCADA software that does not restrict access to certain system directories. This means unauthorized people can view and interact with files in these folders without needing permission.If you use this software for your website or connected systems, attackers could exploit this flaw to read all files in the ...
Continue reading

CVE-2026-12949 (matched: wordpress)

  • 14th August 2026
A security flaw has been found in the Wishlist Member plugin for WordPress, affecting all versions up to and including 3.34.1. This issue lets unauthenticated attackers take over any existing account on a site running the plugin, including administrator accounts, without needing to know the account’s login credentials.The vulnerability works by ...
Continue reading

Metabase Metabase: Metabase SQL Injection Vulnerability

  • 14th August 2026
A popular data analysis tool called Metabase has a critical security vulnerability. This flaw, known as a SQL injection issue, can be exploited by remote attackers who do not need any existing login credentials to access your Metabase instance.If you run Metabase on your hosting account, a successful attack would give the attacker full ...
Continue reading

Microsoft Windows Ancillary Function Driver for WinSock : Microsoft Windows Ancillary Function Driver for WinSock Use-After-Free Vulnerability

  • 14th August 2026
A security vulnerability has been identified in a core Windows system component called the Ancillary Function Driver for WinSock, which handles network and internet connectivity for Windows devices and servers. The flaw is a type of coding error called a use-after-free vulnerability, which occurs when a system mistakenly tries to access memory ...
Continue reading