Announcements

CVE-2026-18431 (matched: php)

  • 27th August 2026
A security vulnerability impacts the Avada WordPress theme (all versions up to and including 7.16) when the companion Fusion Builder plugin (all versions up to and including 3.16) is also installed and active on your site.The flaw is caused by gaps in permission checks and input validation between the two tools, which allows unauthenticated ...
Continue reading

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

  • 27th August 2026
A security vulnerability has been found in two common tools used to run and manage websites: Oracle HTTP Server, and the Oracle Weblogic Server Proxy Plug-in. The flaw is caused by improper access controls, meaning these tools do not properly block unauthorized users from reaching restricted parts of your site's systems and data.If this flaw is ...
Continue reading

Gitea Gitea: Gitea Code Injection Vulnerability

  • 27th August 2026
A security flaw has been found in Gitea, a tool used to host and manage code repositories. This vulnerability allows an attacker who already has permission to make changes to your Gitea repository to send a specially crafted file patch to Gitea's diffpatch API feature. When this patch is processed, it installs a hidden, malicious Git hook that ...
Continue reading

Microsoft SQL Server: Microsoft SQL Server Remote Code Execution Vulnerability

  • 27th August 2026
A security vulnerability has been identified in Microsoft SQL Server, the database management system used by many websites and applications to store and organize data. This flaw is classified as a remote code execution issue, meaning an attacker could potentially trigger it from a remote location without needing direct, authorized access to your ...
Continue reading