The security stories that matter, explained by our team — with the concrete steps to take.
Collected every two hours from specialised publications — each link leads to the original article.
An out-of-bounds read and write flaw was discovered in the PHP-FPM code, which could result in escalation of privileges from local unprivileged user to the roo…
An out-of-bounds read and write flaw was discovered in the PHP-FPM code, which could result in escalation of privileges from local unprivileged user to the roo…
Several vulnerabilities were discovered in smarty3, a template engine for PHP. CVE-2018-13982
It was discovered that there was a use-after-free vulnerability when parsing PHAR files, a method of putting entire PHP applications into a single file.
A security researcher earlier today publicly revealed details and proof-of-concept exploit code for an unpatched, critical zero-day remote code execution vulne…
Updated mediawiki packages fix security vulnerability: In MediaWiki before 1.31.8, private wikis behind a caching server using the img_auth.php image authoriza…
If you are running an online discussion forum based on vBulletin software, make sure it has been updated to install a newly issued security patch that fixes a …
A vulnerability in Imagick PHP extension might allow an attacker to execute arbitrary code.
- Update to 1.2.9 - CVE-2020-7106, CVE-2020-7237 Release notes: https://www.cacti.net/release_notes.php?version=1.2.9
- Update to 1.2.9 - CVE-2020-7106, CVE-2020-7237 Release notes: https://www.cacti.net/release_notes.php?version=1.2.9
- Update to 1.2.9 - CVE-2020-7106, CVE-2020-7237 Release notes: https://www.cacti.net/release_notes.php?version=1.2.9
- Update to 1.2.9 - CVE-2020-7106, CVE-2020-7237 Release notes: https://www.cacti.net/release_notes.php?version=1.2.9
**Version 4.9.4** (2020-01-07) - issue #15724 Fix 2FA was disabled by a bug - issue [security] Fix SQL injection vulnerability on the user accounts page (PM…
Several vulnerabilities were discovered in the Oniguruma regular expressions library, notably used in PHP mbstring.
oniguruma security fix bugport, including fix for CVE-2019-16163 and bugs found on PHP.
oniguruma security fix bugport, including fix for CVE-2019-16163 and bugs found on PHP.
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…
Multiple vulnerabilities have been found in the Symfony PHP framework which could lead to a timing attack/information leak, argument injection and code executi…
Emil Lerner, beched and d90pwn found a buffer underflow in php5-fpm, a Fast Process Manager for the PHP language, which can lead to remote code execution.
CVE-2019-16993 In phpBB, includes/acp/acp_bbcodes.php had improper verification of a CSRF token on the BBCode page in the Administration Control Panel. An