Announcements

CVE-2025-14179 (matched: php)

  • 25th July 2026
In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by-token query construction, a string token containing a NUL byte is copied via strncat(), which stops at the NUL byte, dropping the closing quote and ...
Continue reading

CVE-2026-34084 (matched: php)

  • 25th July 2026
PhpSpreadsheet is a widely used tool that helps websites work with spreadsheet files such as Excel or CSV documents. A security vulnerability affects multiple versions of this library, including all 1.x releases up to 1.30.2, 2.x releases from 2.0.0 to 2.1.14 and 2.2.0 to 2.4.3,Source: NVD (National Vulnerability Database) — ...
Continue reading

Microsoft SharePoint: Microsoft SharePoint Deserialization of Untrusted Data Vulnerability

  • 25th July 2026
A security vulnerability has been found in Microsoft SharePoint, a common platform used to build and manage team websites, document storage, and other collaborative web tools for businesses. The flaw is tied to how the software improperly processes untrusted data it receives, a type of issue called deserialization of untrusted data.If exploited by ...
Continue reading

Check Point SmartConsole: Check Point SmartConsole Improper Authentication Vulnerability

  • 25th July 2026
A security vulnerability has been identified in Check Point SmartConsole, stemming from improper authentication checks built into the software. This flaw creates a risk of unauthorized access to the platform.The issue allows an unauthenticated remote attacker to obtain a valid application login token for the SmartConsole. This token can then be ...
Continue reading