Announcements

CVE-2025-14179 (matched: php)

  • 28th July 2026
A security flaw tracked as CVE-2025-14179 has been found in specific versions of PHP, the common software that runs most dynamic websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The issue impacts the PHP tool used to connect to ...
Continue reading

CVE-2026-15014 (matched: wordpress)

  • 28th July 2026
A security vulnerability has been identified in the SMS Alert – SMS & OTP for WooCommerce, Order Notifications & Abandoned Cart Recovery plugin for WordPress. All versions of the plugin up to and including 3.9.7 are affected by a flaw that allows unauthenticated attackers to bypass login security and take over user accounts on sites running the ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 28th July 2026
A security vulnerability has been identified in the Arista VeloCloud Orchestrator On-Prem platform, a tool many organizations use to manage their cloud and network infrastructure. This flaw is a command injection issue, which allows a remote, unauthorized user to send malicious commands to the system.If exploited, this vulnerability would let an ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 28th July 2026
A security flaw has been identified in Fortinet FortiOS, a system used to manage network and hosting infrastructure for many online services. This flaw creates a risk of sensitive private information being exposed to people who are not authorized to access it.To take advantage of this specific flaw, an attacker would first need to have already ...
Continue reading