HCL Technologies released security updates, addressing five severe HCL BigFix vulnerabilities. These critical software defects allow unauthenticated...
sql injection
TL;DR Cisco confirmed active attacks on a critical Cisco Secure Email Gateway vulnerability. Tracked as CVE-2026-76461, it...
TL;DR A maximum-severity SQL injection flaw sits in the Android Contacts Provider. Tracked as CVE-2026-28576 with a...
A newly discovered cPanel SQL injection flaw exposes web hosting environments to total compromise. Threat actors can...
TL;DR Attackers are exploiting CVE-2026-9586 in the wild. This critical Sangoma Switchvox vulnerability turns an unauthenticated SQL...
TL;DR ServiceNow disclosed four vulnerabilities on August 27, 2026. Three carry a maximum CVSS score of 10,...
TL;DR Apache InLong patched three flaws in version 2.4.0. The most notable is an Apache InLong SQL...
TL;DR Cisco fixed a critical SQL injection flaw in Crosswork, tracked as CVE-2026-20030 at CVSS 10.0. The...
TL;DR Google patched CVE-2026-0075, an Android elevation of privilege flaw in ContactsProvider2. The bug can expose the...
TL;DR A GeoServer unauthenticated SQL injection flaw is under active attack. It lives in the jsonArrayContains filter...
TL;DR Phoenix Contact disclosed three vulnerabilities in PLCnext firmware on August 12, 2026. One flaw, CVE-2025-41771, lets...
TL;DR Metabase disclosed a critical SQL injection zero-day rated CVSS 10. An unauthenticated remote attacker can gain...
TL;DR: The pgAdmin Development Team patched a pgAdmin 4 RCE flaw tracked as CVE-2026-17566, rated CVSS 9.4....
TL;DR Adobe published a Priority 1 security update for Adobe Campaign Classic. The patch resolves seven severe...
TL;DR A critical SQL injection flaw hits Weidmueller PROCON-WEB SCADA. Tracked as CVE-2026-16462, it scores a CVSS...
TL;DR: The CodeIgniter4 team patched four security flaws in release v4.7.4. The most severe, a CodeIgniter4 RCE...
TL;DR The PHP project fixed three flaws in its latest releases. The headline bug is a PHP...
The Apache Syncope project has patched two security flaws in its identity management platform. Both Apache Syncope...
TL;DR Two new FreePBX vulnerabilities each carry a CVSS score of 9.3. One gives unauthenticated remote code...
TL;DR CISA added four flaws to its KEV catalog on July 21, 2026. The list covers critical...
TL;DR Apache has patched three SQL injection flaws in Fineract, the open-source core banking platform. The Apache...
TL;DR WordPress shipped 7.0.2 on July 17, 2026 to fix a critical flaw chain. The bug is...