Threats Tagged 'sqli'
View all threats tagged with 'sqli'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'sqli'
Click on any threat for detailed analysis and mitigation recommendations
0 CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly concatenates the administrator-controlled download_expire POST parameter into a raw UPDATE statement for CubeCart_downloads without numeric validation. An authenticated administrator can supply a comma-delimited value that changes the SET clause because HTML sanitization does not neutralize SQL syntax, allowing manipulation of database columns and potentially other data within the application's database privileges. This issue is fixed in version 6.7.5. Join the discussion | Exploit-DB RSS Feed | 09/17/2026, 22:02:48 UTC Added: 08/31/2026, 17:43:04 UTC |
Cisco has released patches for multiple critical vulnerabilities affecting Secure Firewall Management Center (FMC), Identity Services Engine (ISE), and Nexus Dashboard. These vulnerabilities include remote code execution, command injection, authentication bypass, SQL injection, and other flaws that could lead to root access and denial-of-service conditions. Some of the vulnerabilities have been publicly disclosed and exploited in the wild, including a zero-day authentication bypass in ISE. Cisco has issued security advisories detailing these issues and providing fixes. Join the discussion | SecurityWeek | 09/17/2026, 12:17:40 UTC Added: 09/17/2026, 12:31:40 UTC |
0 In late August 2026, a sophisticated device code phishing campaign was identified, distributed through web contact forms. Threat actors impersonated procurement officers from legitimate businesses, specifically BJ's Wholesale Club, using lookalike domains registered with Zoho Mail. The campaign, tracked as GhostCode, abused Microsoft's OAuth 2.0 device authorization grant flow to obtain authentication tokens. Victims received WeTransfer links to password-protected HTML files containing three layers of obfuscation: junk padding, character-level HTML comment injection, and AES-256-GCM encrypted redirect URLs. After passing multiple security checks including Cloudflare Turnstile, victims were directed to legitimate Microsoft sign-in pages where they unwittingly authorized attacker-controlled devices. Within 78 seconds of successful authentication, threat actors registered three devices, obtained Primary Refresh Tokens, and harvested emails using residential proxy rotation to evade detection. Join the discussion | CVE Database V5 | 09/16/2026, 12:51:13 UTC Added: 08/28/2026, 15:38:05 UTC |
0 The threat intelligence report from September 14, 2026, details multiple cyber incidents including data breaches, vulnerabilities, and AI-related threats. Notably, a data breach at Mathspace was caused by exploitation of CVE-2026-72898, a SQL injection vulnerability in the self-hosted Metabase tool, exposing user names, emails, usernames, and locations. Other significant vulnerabilities include Microsoft’s Patch Tuesday addressing 974 flaws including privilege escalation zero-days, and GitLab’s critical path traversal vulnerability CVE-2026-85706 allowing unauthenticated arbitrary file reads. MikroTik RouterOS vulnerabilities enabling passwordless SSH and privilege escalation were also fixed. The report includes AI threats involving prompt evasion and sandbox escapes. Check Point IPS provides protections for several mentioned vulnerabilities. The report does not specify affected versions for CVE-2026-72898. No CVSS score is provided for this vulnerability. Join the discussion | Check Point Research | 09/14/2026, 12:22:06 UTC Added: 09/14/2026, 12:25:50 UTC |
A joint Tenable-SentinelOne analysis of 93 CVE-actor attribution pairs reveals that both state-sponsored actors and cybercriminals independently converge on the same edge infrastructure. Special thanks to SentinelOne® Incident Readiness & Response for their contributions to this publication. It is the shared attack surface where state-sponsored threat actors and financially motivated criminal groups independently converge — not the province of a single adversary category, and not exclusively a nation-state problem, despite two years of headlines about China-nexus actors targeting Ivanti, Fortinet, and Palo Alto Networks. The data here tells a different and much broader story. One focused on vendors vs CVEs. Key Takeaways Two independent observation systems, Tenable exposure telemetry across thousands of customer containers and SentinelOne DFIR casework across 66 CVEs, converge 79% on the same vendor attack surfaces despite minimal CVE-level overlap. Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories (China, Russia, DPRK, Iran, ransomware). The exposure picture is flatter than the headlines suggest: Fortinet, the vendor most associated with edge-device attacks in the press, sits mid-pack on container-grain exposure (25%) — well behind F5 (54%) and in a tight 10-point band with Check Point, Ivanti, and Citrix. 54% of customer environments running F5 products have at least one exposed, actively-exploited CVE; Citrix customers show the slowest remediation patterns at 461 days median time to patch. Remediation complexity, particularly of high priority CVEs, leads to a statistically significant 24-day remediation gap, leaving large windows of opportunity for attackers. The same product lines get hit again and again: Ivanti EPMM and Ivanti Connect Secure each show a newly exploited CVE roughly every 8.5 to 13 months. Leverage multiple defense-in-depth strategies: patch as quickly as possible, but also minimize the attack surface (feature-set minimization) and run endpoints in protect mode to better stop lateral movement from attacks that gain initial access. The convergence is the story Twelve CVEs in the combined dataset have confirmed multi-nexus attribution: state-sponsored and criminal actors independently exploiting the same vulnerability, across five nexus categories. Four examples illustrate the pattern: CVE Product Actors (Nexus) Significance CVE-2026-15409 SonicWall SMA1000 UTA0533 (unattributed) + INC Ransomware Espionage-to-ransomware succession on an active zero-day CVE-2023-42793 JetBrains TeamCity APT29 (Russia) + Lazarus (DPRK) Two state-sponsored actors from different nations on the same CVE CVE-2024-3400 PAN-OS GlobalProtect UTA0218 (China) + INC Ransomware China-nexus zero-day reused by ransomware operators CVE-2024-24919 Check Point Quantum PurpleHaze (China) + Fox Kitten (Iran) China and Iran independently exploiting the same gateway vulnerability The remaining eight confirmed multi-nexus CVEs span Fortinet, Citrix, Cisco, and Ivanti product lines. State-sponsored actors and ransomware operators are not operating in separate vulnerability ecosystems. They share the same entry points into the same products. The breadth of the convergence, not any single actor's activity, is the finding. That pattern holds across the full combined analysis. Three conclusions emerge: Vendor attack surfaces are the persistent exploitation target. The same eleven vendors (i.e., Fortinet, Citrix, Ivanti, Palo Alto Networks, Cisco, Juniper, VMware, Microsoft, Oracle, CrushFTP, and Meta's React framework ) appear in both observation systems at 79% convergence, and all seven edge-product vendors converge. Serial exploitation timing on Ivanti products shows the vulnerability-to-exploitation pipeline refreshing at 8.5 to 13-month intervals on the same product lines. This is structural, not episodic. Patch… Join the discussion | CVE Database V5 | 09/10/2026, 17:48:31 UTC Added: 07/14/2026, 20:03:48 UTC |
An SQL injection vulnerability exists in the All-in-One WP Migration and Backup plugin for WordPress. This flaw could allow unauthenticated attackers to execute remote code and potentially take control of affected websites. The vulnerability affects millions of WordPress sites using this plugin. No specific affected versions or patch information is provided in the available data. Join the discussion | Bleeping Computer | 09/02/2026, 19:28:46 UTC Added: 09/02/2026, 19:37:23 UTC |
0 SQL injection vulnerability exists in the order_by parameter of the /customers/search endpoint in Alex Tselegidis EasyAppointments <= 1.5.1. The vulnerability arises from unsanitized user input passed to the order_by method of the CodeIgniter Query Builder, enabling attackers to perform time-based queries and schema enumeration. Under certain MySQL configurations, the flaw may lead to remote code execution by writing a PHP shell using INTO OUTFILE. Join the discussion | CVE Database V5 | 09/01/2026, 00:00:00 UTC Added: 07/27/2026, 15:37:40 UTC |
0 Payload is a free and open source headless content management system. Prior to 3.73.0, when querying JSON or richText fields, user input was directly embedded into SQL without escaping, enabling blind SQL injection attacks. An unauthenticated attacker could extract sensitive data (emails, password reset tokens) and achieve full account takeover without password cracking. This vulnerability is fixed in 3.73.0. Join the discussion | CVE Database V5 | 09/01/2026, 00:00:00 UTC Added: 02/06/2026, 21:30:09 UTC |
ServiceNow disclosed and patched three critical vulnerabilities in its AI Platform, including code injection, SQL injection, and privilege escalation flaws. These vulnerabilities can be exploited by unauthenticated attackers with low complexity and no user interaction required. Additionally, a high-severity sandbox escape vulnerability was also addressed. ServiceNow advises customers to apply patches promptly to secure self-hosted instances. No active exploitation is currently known. The affected platform powers numerous enterprise AI applications across Fortune 500 companies. Join the discussion | Bleeping Computer | 08/28/2026, 10:29:42 UTC Added: 08/28/2026, 10:53:01 UTC |
The All-in-One WP Migration and Backup plugin for WordPress contains an SQL Injection vulnerability in its archive restore functionality affecting all versions up to and including 7.109. This flaw allows unauthenticated attackers to inject additional SQL queries due to insufficient escaping and lack of proper query preparation. Exploitation can lead to extraction of sensitive data such as the ai1wm_secret_key and potentially remote code execution when the site administrator performs an archive restore. Join the discussion | CVE Database V5 | 08/25/2026, 11:27:11 UTC Added: 08/25/2026, 11:52:42 UTC |
Showing 1 to 10 of 28 results