Announcements

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in DD-WRT, a popular custom firmware for Wi-Fi routers. The flaw is a buffer overflow weakness in the router's UPnP feature, a tool designed to let devices on your local network automatically connect and communicate with each other. An unauthenticated attacker, or someone with no prior permission to ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in Langflow, a tool many website owners use to build custom AI-powered workflows and interactive site features. This flaw is classified as an "inclusion of functionality from an untrusted control sphere" issue, meaning Langflow can be tricked into running code from sources it was not designed to ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 23rd July 2026
There is a newly identified security flaw in WordPress Core, the base software that powers the vast majority of WordPress websites. Referred to as an interpretation conflict vulnerability, this flaw affects unpatched versions of the WordPress platform. If exploited by a bad actor, the flaw could enable two high-risk attacks: SQL injection, which ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 23rd July 2026
A security flaw has been identified in core WordPress software. This is a SQL injection vulnerability, which occurs when a plugin or theme installed on your WordPress site passes untrusted, unvetted input to a specific parameter built into WordPress core.This flaw can be combined with a separate, known security issue to allow attackers who do not ...
Continue reading