Announcements

CVE-2026-6722 (matched: php)

  • 24th July 2026
A security vulnerability has been identified in specific older versions of PHP, the software used to run many dynamic websites. The affected versions are PHP 8.2 releases older than 8.2.31, 8.3 releases older than 8.3.31, 8.4 releases older than 8.4.21, and 8.5 releases older than 8.5.6.The flaw exists in PHP's SOAP extension, a component used for ...
Continue reading

CVE-2026-15981 (matched: wordpress)

  • 24th July 2026
A security flaw has been found in the WordPress SAML Single Sign On (SSO Login) plugin, affecting all versions up to and including 5.4.4. The issue stems from a coding error in how the plugin verifies the legitimacy of SAML login requests, the system that lets users sign into your site using an external account (like a work or school login).This ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 24th July 2026
A security flaw has been found in DD-WRT, a widely used firmware for routers and other network hardware that many people use to support their websites and online services. This is a stack-based buffer overflow vulnerability, a type of programming error that can cause systems to operate in unexpected, unsafe ways. The issue exists in the part of ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 24th July 2026
A security vulnerability has been identified in Langflow, a tool many website owners use to build custom applications and automated workflows. This flaw is classified as an inclusion of functionality from an untrusted control sphere, meaning remote attackers can run their own unauthorized code on any affected Langflow installations.If you use ...
Continue reading