Announcements

CVE-2025-14179 (matched: php)

  • 27th July 2026
A security flaw tracked as CVE-2025-14179 affects specific recent versions of PHP, the programming language that powers many dynamic websites. The impacted versions are PHP 8.2 before 8.2.31, 8.3 before 8.3.31, 8.4 before 8.4.21, and 8.5 before 8.5.6. This flaw impacts sites that use the Firebird database driver via PHP's PDO database ...
Continue reading

CVE-2026-34084 (matched: php)

  • 27th July 2026
A security flaw has been found in PhpSpreadsheet, a popular library that many websites and web applications use to work with spreadsheet files like Excel, Google Sheets, and CSV files.Versions 1.30.2 and older, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0 of the library are affected. If your site or app ...
Continue reading

Arista VeloCloud Orchestrator: Arista VeloCloud Orchestrator On-Prem OS Command Injection Vulnerability

  • 27th July 2026
If you use the Arista VeloCloud Orchestrator On-Prem to manage your cloud or network operations, a security vulnerability has been identified in this system. The flaw is an operating system command injection issue, which allows a remote, unauthorized person to send malicious commands to the affected system.If an attacker successfully exploits this ...
Continue reading

Fortinet FortiOS: Fortinet FortiOS Exposure of Sensitive Information to an Unauthorized Actor Vulnerability

  • 27th July 2026
A security vulnerability has been identified in Fortinet FortiOS, a network security product used to protect websites and online infrastructure. This flaw can allow an unauthorized remote user to access sensitive information that should be restricted to approved parties only.To exploit this issue, an attacker would first need to have already ...
Continue reading