Announcements

CVE-2026-48907 (matched: php)

  • 23rd July 2026
A security flaw has been discovered in the JCE editor extension used by many Joomla content management system websites. The issue lets people who do not have authorized login access to your site create new editor profiles for your Joomla installation. If attackers exploit this flaw, they can use those unauthorized profiles to upload and run ...
Continue reading

CVE-2026-48687 (matched: php)

  • 23rd July 2026
A security flaw has been identified in FastNetMon Community Edition, affecting all versions up to 1.2.9. This is a command injection vulnerability that could allow unauthorized people to run unapproved commands on servers where this software is installed.The flaw exists in a plugin designed to connect FastNetMon to Juniper routers. The plugin ...
Continue reading

CVE-2026-6722 (matched: php)

  • 23rd July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global map without incrementing their reference counts. When an apache:Map node contains duplicate keys, processing the second entry overwrites the first in ...
Continue reading

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 23rd July 2026
A security vulnerability has been identified in DD-WRT, a popular open-source firmware used for many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error that can cause a program to behave unexpectedly or run unauthorized instructions.The error exists in DD-WRT’s built-in UPnP (Universal Plug ...
Continue reading