This advisory is provided as a courtesy. We want to bring to your attention two newly discovered vulnerabilities in WordPress, a very popular content management system (CMS) for websites. CVE-2026-60137 - A facilitated SQL injection issue reported as a team by TF1T, dtro, and haongo CVE-2026-63030 – A REST API batch-route confusion and SQL injection issue leading to Remote Code Execution r ...
This advisory is provided as a courtesy. We want to bring to your attention two newly discovered vulnerabilities in the Plesk hosting control panel. Blind SQL Injection - CVE-2026-64636 An attacker could extract data from the server database through a read-only SQL injection. Affected Versions: Plesk Versions 18.0.51 up to 18.0.79.4 Fixed Versions: Plesk 18.0.80.1 and Plesk ...
This advisory is provided as a courtesy. We would like to bring to your attention multiple critical vulnerabilities in Broadcom VMware ESX and vCenter products. Attackers can exploit multiple vulnerabilities in the VMware products to bypass authentication, execute arbitrary code, access sensitive information or cause denial-of-service. We recommend customers running VMware ESX and vCenter ...