Multiple vulnerabilities have been discovered in PHP, the most severe of which could allow an attacker to execute arbitrary code. PHP is a programming language originally designed for use in web-based applications with HTML content. PHP supports a wide variety of platforms and is used by numerous web-based software applications. 
March 2, 2018
February 22, 2018
January 5, 2018
A team of security researchers disclosed several software analysis methods that, when used for malicious purposes, have the potential to improperly gather sensitive data from many types of computing devices with many different vendors’ processors and operating systems.
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. 
November 29, 2017
October 18, 2017
October 17, 2017
Researchers have discovered serious weaknesses in WPA2, a protocol that secures all modern protected Wi-Fi networks. This includes everything from computers, tablets, phones, home wireless routers and any device that supports WPA2 over Wi-Fi.
While details are still emerging, not all vendors have released patches as of yet. So, in some cases, there will be little users can do until patches are released. An attacker needs to be in range of an access-point to leverage this attack.
September 6, 2017
A critical vulnerability has been discovered in the Apache Struts web application framework for Java web applications. A remote code execution attack is possible when using the Apache Struts REST plugin with XStream handler to deserialise XML requests. 
Attackers can execute arbitrary code remotely by exploiting this vulnerability.
June 14, 2017
A remote code execution vulnerability exists when Windows Search handles objects in memory. This can be exploited by an attacker sending a specially crafted SMB message to the Windows Search service. 
Due to recent nation-state activity and the elevated risk of potential cyber attacks, Microsoft has released security updates for older unsupported versions of Windows for this issue as well as other high-severity fixes in the June patch release. 
May 25, 2017
The samba team has released a patch for a Remote Code Execution bug that affects all versions between 3.5.0 and 4.6.3/4.5.9/4.4.13. This vulnerability will allow a malicious attacker to upload a library to a writable share then cause the server to execute that library.  Patches are available from the samba.org. 
March 9, 2017
A critical vulnerability has been discovered and released in the Apache Struts 2 framework. Patches are available from Apache. 
This vulnerability allows for unauthenticated, remote code execution on the server. Further, there are at least two known public exploits for this vulnerability  and ISP has already started to see scanning and exploit attempts against campus systems.
February 3, 2017
WordPress has fixed several critical flaws in its content management system, addressing cross-site scripting and sql injection bugs, along with a severe privilege escalation / content injection vulnerability.