PostgreSQL backup accounts open 12-year backdoor
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.
21 results for “sql”
A 12-year-old PostgreSQL flaw lets low-privilege replication accounts gain superuser access and remote code execution across platforms.
CVE-2026-9586, an unauthenticated SQL injection in Switchvox, is under active exploitation, Horizon3 reports.
Patches cover three critical code injection bugs and a sandbox escape in the Now Platform.
CISA adds six exploited flaws to KEV, including NetScaler, Linux, and SQL Server bugs.
Critical SQL injection flaw in Metabase allowed zero-day attacks; urgent patches released for self-hosted users.
A high-severity vulnerability in Azure SQL Managed Instance allows unauthorized network-based privilege escalation, requiring immediate attention.
A critical authentication bypass in Azure SQL Database allows unauthorized attackers to gain elevated privileges over a network.
Researchers identified a post-exploitation toolkit concealed within Oracle database schema objects to bypass endpoint security tools.
A critical SQL injection vulnerability in Loca Software CMS allows unauthorized attackers to gain full control over affected database systems.
A critical SQL injection vulnerability in Adobe Campaign Classic allows low-privileged attackers to execute arbitrary code without user interaction.
A severe vulnerability in PyAthena versions prior to 3.35.4 allows unauthenticated attackers to execute arbitrary SQL commands.
A critical vulnerability in SiYuan software allows unauthorized database manipulation via the searchDocs API endpoint.
A severe SQL injection flaw in NocoBase allows unauthenticated attackers to gain remote code execution via a simple registration and API request.
A severe SQL injection vulnerability in @hypequery/clickhouse allows attackers to execute arbitrary SQL commands by manipulating input parameters.
A critical vulnerability in the PROCON-WEB SCADA GetGridData endpoint allows unauthenticated attackers to execute arbitrary SQL commands.
A configuration vulnerability in the platform's MySQL integration allows for unauthorized command execution and database takeover.
WordPress Core is under active attack via an interpretation conflict vulnerability that allows for SQL injection and remote code execution.
WordPress Core is currently under active exploitation via a SQL injection vulnerability that can be chained to achieve remote code execution.
A critical, unauthenticated SQL injection vulnerability has been identified in Sangoma Switchvox SMB Edition 8.3.
A dual-vulnerability chain allows unauthenticated code execution on WordPress core installations, prompting emergency updates.
Researchers are moving beyond theoretical AI capabilities, building automated pipelines to find live vulnerabilities in software.