Announcements

DD-WRT DD-WRT: DD-WRT Stack-Based Buffer Overflow Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in DD-WRT, a popular firmware used by many home and small business network routers. The flaw is a stack-based buffer overflow, a type of memory error, that impacts the router's UPnP (Universal Plug and Play) feature, a tool designed to help devices on a local network automatically discover and connect ...
Continue reading

Langflow Langflow: Langflow Inclusion of Functionality from Untrusted Control Sphere Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in Langflow, a no-code tool for building AI workflows that some website owners run on their hosting accounts. The flaw is classified as an "inclusion of functionality from untrusted control sphere" issue, meaning the software can accidentally pull in and run unvetted, external code from sources outside ...
Continue reading

WordPress Core: WordPress Core Interpretation Conflict Vulnerability

  • 22nd July 2026
A security flaw has been identified in WordPress Core, the base software that powers all sites built on the WordPress platform. This issue, classified as an interpretation conflict, creates a potential entry point for attackers to target sites running affected versions of WordPress.If successfully exploited, this vulnerability can be used to carry ...
Continue reading

WordPress Core: WordPress Core SQL Injection Vulnerability

  • 22nd July 2026
A security vulnerability has been identified in the core WordPress software used to run many websites. This is a SQL injection flaw that is triggered when a WordPress plugin or theme passes unscreened, untrusted user input to a specific core parameter.This flaw can be chained with the separate known security issue CVE-2026-63030 to allow an ...
Continue reading