#sql


Roundcube Pre-Auth SQL Injection Flaw Actively Exploited in the Wild

Sep 25, 2026 // 13:27

The Canadian Centre for Cyber Security has warned that a now-patched Roundcube Webmail vulnerability is being actively exploited in the wild. The vulnerability in question […]

Three CVSS 10.0 ServiceNow Flaws Could Let Unauthenticated Attackers Execute Code and SQL

Aug 28, 2026 // 14:30

ServiceNow has released patches for four security flaws impacting the ServiceNow AI Platform, three of them rated 10.0 on the CVSS scoring system and exploitable, […]

CISA Adds Six Exploited Flaws to KEV, Including NetScaler, Linux, and SQL Server Bugs

Aug 27, 2026 // 10:57

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) on Wednesday added six flaws to its Known Exploited Vulnerabilities (KEV) catalog, including a high-severity security vulnerability […]

Attackers Compile khunt Inside Oracle to Turn SQL Injection Into Windows SYSTEM Access

Aug 6, 2026 // 13:42

Attackers broke into an organization’s Oracle database through a SQL injection flaw in a public-facing web application, then installed a post-exploitation toolkit without writing an […]

New cPanel Critical Flaw Could Let Hosting Customers Run SQL as Database Root

Aug 5, 2026 // 14:35

cPanel has patched a flaw that let an authenticated hosting customer execute SQL in the database’s root context, crossing the privilege boundary between a cPanel […]

Ghost CMS SQL injection flaw exploited in large-scale ClickFix campaign

May 24, 2026 // 18:57

A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The […]

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

May 23, 2026 // 10:49

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) […]

Drupal Core SQL Injection Bug Actively Exploited, Added to CISA KEV

May 23, 2026 // 10:46

The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has added a recently patched critical security flaw impacting Drupal Core to its Known Exploited Vulnerabilities (KEV) […]

Drupal: Critical SQL injection flaw now targeted in attacks

May 22, 2026 // 16:16

Drupal is warning that hackers are attempting to exploit a “highly critical” SQL injection vulnerability announced earlier this week. The content management system (CMS) project […]

LiteLLM CVE-2026-42208 SQL Injection Exploited within 36 Hours of Disclosure

May 1, 2026 // 00:42

In yet another instance of threat actors quickly jumping on the exploitation bandwagon, a newly disclosed critical security flaw in BerriAI’s LiteLLM Python package has […]

1 2 Next