Announcements

CVE-2026-44172 (matched: mariadb)

  • 31st July 2026
A security vulnerability has been identified in specific versions of MariaDB, a popular open-source database software used to power many websites. The flaw affects MariaDB versions 3.3.18 and 3.4.8.Under specific conditions, attackers could bypass a common security tool that websites use to block harmful database commands. This occurs when a site ...
Continue reading

CVE-2026-46634 (matched: php)

  • 31st July 2026
Twig is a template language for PHP. From 3.9.0 until 3.26.0, template_from_string() compiles an inner template under a synthesized __string_template__ name that can fall outside a SourcePolicyInterface sandbox decision, allowing a sandboxed template that can call template_from_string and include to render an inner template without security policy ...
Continue reading

CVE-2026-14483 (matched: wordpress)

  • 31st July 2026
A security flaw has been identified in the Realtyna Organic IDX and WPL Real Estate plugins for WordPress, affecting all versions up to and including 5.2.0. The issue exists in the plugins’ file upload feature, which does not verify the type of file a user is attempting to upload.This upload feature is secured only by default, identical API ...
Continue reading

Cisco Secure Firewall Management Center (FMC): Cisco Secure Firewall Management Center Use of Hard-coded Password Vulnerability

  • 31st July 2026
A security flaw has been identified in Cisco Secure Firewall Management Center (FMC), a product previously known as Firepower Management Center. The issue stems from a hard-coded password, meaning a password is embedded directly into the software rather than being set and controlled by the device owner.This vulnerability could allow an ...
Continue reading