Announcements

CVE-2021-40438 (matched: apache http server)

  • 8th August 2026
A security flaw has been found in older versions of the Apache HTTP Server, a widely used tool that routes visitor requests to websites. The issue affects Apache HTTP Server 2.4.48 and all earlier versions. The flaw is triggered by a specially crafted web request sent to a site running the affected software. When triggered, it tricks the server's ...
Continue reading

CVE-2026-17544 (matched: php)

  • 8th August 2026
A security flaw has been found in specific recent versions of PHP, the software that powers most websites. The issue exists in the bccomp() function, a built-in PHP tool used to compare decimal numbers for tasks like handling pricing, financial calculations, or user-submitted numeric input. When an attacker sends specially crafted input to this ...
Continue reading

CVE-2026-17543 (matched: php)

  • 8th August 2026
A security flaw has been identified in specific versions of PHP, the software that powers most interactive, database-driven websites. The issue is caused by incorrect handling of backslash characters in inputs submitted by visitors to your site. This flaw lets bad actors slip unauthorized commands into your website’s database queries, a common ...
Continue reading

CVE-2026-65883 (matched: php)

  • 8th August 2026
A security vulnerability has been identified in the Aimy Captcha-Less Form Guard extension for Joomla, developed by aimy-extensions.com. The flaw impacts versions 18.0 through 20.0 of the tool.This issue exploits PHP object injection, a technique that lets unauthorized users run harmful code on your website's hosting server. Attackers can trigger ...
Continue reading