A newly disclosed zero-day flaw in GeoServer is seeing active exploitation efforts, per watchTowr. The vulnerability, which has yet to be assigned a CVE identifier, is an SQL injection vulnerability ...
A seemingly routine HTTP request revealed a modern SQL Injection evasion technique and a timely reminder of why layered security remains indispensable for enterprise applications. During the course of ...
A newly disclosed pair of flaws in PHP’s database driver layer shows that even mature code can hide dangerous surprises. The bugs live inside PHP Data Objects (PDO), the abstraction layer web ...
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. The content management system (CMS) project published a PSA on May ...
Administrators of the Drupal open source content management platform are rushing to install an emergency patch issued today to fix a “highly critical” SQL injection vulnerability in the application’s ...
PostgreSQL released emergency security updates on May 14, 2026, covering all supported versions 18.4, 17.10, 16.14, 15.18, and 14.23, addressing 11 CVEs spanning stack buffer overflows, SQL injection, ...
A critical SQL injection vulnerability in ProFTPD’s mod_sql extension, tracked as CVE-2026-42167, that enables remote code execution, authentication bypass, and privilege escalation in some ...
A critical pre-authentication SQL injection vulnerability in LiteLLM, a widely used open-source AI gateway with over 22,000 GitHub stars, is actively being exploited in the wild. Tracked as ...
A critical SQL injection flaw in FortiClient EMS allows remote code execution and data exfiltration, leaving thousands of internet facing systems at risk. Yet another critical flaw in a Fortinet ...
The issue allows attackers to inject SQL queries and extract sensitive information from the database. A vulnerability in the Ally WordPress plugin, which is designed for adding accessibility features ...