Announcements

CVE-2026-78570 (matched: wordpress)

  • 26th August 2026
A security vulnerability has been found in the Total Donations plugin for WordPress, impacting all versions of the plugin up to and including version 2.0.5. This flaw is a privilege escalation issue, meaning attackers who do not have any existing login credentials for your WordPress site can gain full administrator-level access to your site. With ...
Continue reading

Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in: Oracle HTTP Server and Oracle Weblogic Server Proxy Plug-in Improper Access Control Vulnerability

  • 26th August 2026
A security vulnerability has been identified in the Oracle HTTP Server and Oracle WebLogic Server Proxy Plug-in. This is an improper access control flaw, meaning the tool does not properly restrict who can interact with the data it manages.If exploited, this flaw could allow an unauthorized person to gain access to critical data stored or managed ...
Continue reading

Gitea Gitea: Gitea Code Injection Vulnerability

  • 26th August 2026
A security vulnerability has been identified in Gitea, a popular tool many web hosting clients use to host and manage code repositories for their development projects. The issue is a code injection flaw that allows an attacker who already has write access to a Gitea repository to send a maliciously crafted patch to Gitea’s diffpatch API ...
Continue reading

Microsoft SQL Server: Microsoft SQL Server Remote Code Execution Vulnerability

  • 26th August 2026
A remote code execution vulnerability has been identified in Microsoft SQL Server, a common database system used to store website data like customer records, site content, and order information. This flaw could allow an attacker to run unauthorized, harmful code on the server hosting your SQL Server database.The harmful code would operate under ...
Continue reading