Announcements

CVE-2021-40438 (matched: apache http server)

  • 8th August 2026

A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.

Source: NVD (National Vulnerability Database) — https://nvd.nist.gov/vuln/detail/CVE-2021-40438

Continue reading

CVE-2026-14526 (matched: wordpress)

  • 8th August 2026
A security vulnerability has been identified in the AI Copilot – Content Generator plugin for WordPress, impacting all versions up to and including 1.5.6. The plugin does not properly confirm that a user is authorized to carry out sensitive actions on your website.If your site displays the plugin's [aiwu-form] shortcode or public chatbot on any ...
Continue reading

JetBrains TeamCity: JetBrains TeamCity Deserialization of Untrusted Data Vulnerability

  • 8th August 2026
A security flaw has been found in JetBrains TeamCity, a tool many development teams use to manage website and software build, test, and deployment workflows. The issue stems from the way the tool processes untrusted data as part of its regular check-in process with connected worker systems, known as the agent polling protocol.This vulnerability ...
Continue reading

Progress LoadMaster: Progress LoadMaster Command Injection Vulnerability

  • 8th August 2026
A security vulnerability has been identified in Progress LoadMaster, a tool many website operators use to distribute incoming traffic across multiple servers to improve site speed and reliability.The flaw is a command injection issue. This means an attacker does not need any valid login credentials to exploit it: they can send specially crafted, ...
Continue reading