Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threat Intelligence Database

Comprehensive database of the latest cyber threats affecting organizations worldwide. Filter and search to find specific threat intelligence relevant to your organization.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.

Threat Intelligence

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-56705: External Control of File Name or Path in vrana adminerCVE-2026-56705
0

Adminer versions before 5.4.3 contain a vulnerability where the server field is not properly sanitized before constructing a PDO DSN string. This allows unauthenticated attackers to inject ODBC parameters via semicolons, including TraceFile and TraceOn, which can write PHP code to the web root. Accessing the trace file leads to remote code execution.

Join the discussion
CVE-2026-56704: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') in vrana adminerCVE-2026-56704
0

CVE-2026-56704 is a cross-site scripting (XSS) vulnerability in Adminer before version 5.4.3. The issue arises because Adminer inserts unsanitized database server version strings into script tags that use valid Content Security Policy (CSP) nonces without proper validation. This allows an attacker controlling a malicious MySQL server to craft version strings that break out of the JavaScript context and execute arbitrary code, effectively bypassing CSP protections.

Join the discussion
CVE-2026-56703: Improper Control of Generation of Code ('Code Injection') in vrana adminerCVE-2026-56703
0

Adminer versions before 5.4.3 have a remote code execution vulnerability due to improper control of SQLite query handling. Authenticated attackers can exploit the VACUUM INTO command to write PHP code to arbitrary file paths and execute commands on the server.

Join the discussion
CVE-2026-34968: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') in vrana adminerCVE-2026-34968
0

Adminer versions before 5.4.3 have a vulnerability in SQLite mode where the database-list drop action does not properly validate file extensions before deleting files. This allows an authenticated attacker to provide arbitrary relative file paths via the db[] parameter to delete any files writable by the PHP process.

Join the discussion
CVE-2026-34967: External Control of File Name or Path in vrana adminerCVE-2026-34967
0

Adminer versions 5.3.0 through 5.4.2 with the sql-log plugin enabled have an arbitrary file write vulnerability. An authenticated user can exploit a path traversal issue in the ns parameter of plugins/sql-log.php to write attacker-controlled .sql files to any writable directory on the host.

Join the discussion
CVE-2026-34964: Server-Side Request Forgery (SSRF) in vrana adminerCVE-2026-34964
0

Adminer versions before 5.5.0 have a server-side request forgery (SSRF) vulnerability in the login form's server field validator. The validator only checks leading integers for privileged ports and does not reject non-numeric port values. This allows attackers to inject PDO DSN keys such as host= and port= into the server parameter, bypassing privileged-port restrictions and enabling TCP connections to arbitrary internal hosts and ports before authentication.

Join the discussion
CVE-2026-34959: Improper Input Validation in vrana adminerCVE-2026-34959
0

Adminer versions 4.6.0 before 5.5.0 improperly validate the client-supplied X-Forwarded-Prefix header, allowing it to be prepended to the REQUEST_URI without trusted-proxy checks or validation. This flaw enables an authenticated attacker to cause open redirects after POST requests, control the session cookie path attribute without authentication, and poison self-referential links. However, injection of CR/LF characters is not possible, preventing header splitting or XSS attacks.

Join the discussion
CVE-2026-16434: Improper Input Validation in vrana adminerCVE-2026-16434
0

Adminer versions 4.6.0 through 5.5.0 contain an incomplete fix for a prior X-Forwarded-Prefix header validation vulnerability. The validation only blocks prefixes starting with double forward slashes but allows prefixes with a backslash as the second character, which browsers normalize to a forward slash. This can cause anomalous cookie-path scoping via the Set-Cookie Path attribute. Exploitation requires the ability to set the X-Forwarded-Prefix header, typically due to a misconfigured or absent reverse proxy. The issue was fixed in version 5.5.1.

Join the discussion

Showing 1 to 8 of 8 results

Filters:Package: pkg:github/vrana/adminer
Page 1 of 1
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses