Announcements

CVE-2026-17543 (matched: php)

  • 7th August 2026
A security vulnerability has been found in specific versions of PHP, the common programming language that powers many dynamic websites. The flaw is caused by improper handling of backslashes in data submitted by site visitors, such as form entries or information passed in page URLs.This issue can be exploited to carry out SQL injection attacks, ...
Continue reading

CVE-2026-65883 (matched: php)

  • 7th August 2026

Joomla Extension - aimy-extensions.com - RCE via PHP object injection in Aimy Captcha-Less Form Guard 18.0 - 20.0 - A forged clfgd field allows PHP objection injection and thereby remote code execution.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2026-65883

Continue reading

IBM Langflow: IBM Langflow Code Injection Vulnerability

  • 7th August 2026
A security flaw has been identified in IBM Langflow, a tool some users run on their web hosting accounts. This is a code injection vulnerability, a type of issue that lets attackers run their own arbitrary code on the affected system, and they do not need any login credentials to exploit it.For default Langflow deployments, this flaw gives ...
Continue reading

Apache Tomcat: Apache Tomcat Missing Encryption of Sensitive Data Vulnerability

  • 7th August 2026
A security vulnerability has been discovered in Apache Tomcat, a widely used web server platform that many websites rely on to operate. This flaw involves a failure to properly encrypt sensitive data, which can allow bad actors to bypass a built-in security feature called the EncryptInterceptor that is intended to protect sensitive information ...
Continue reading