search
SQL
Trends
- 1High-severity SQL injection flaw found in YesWikiโ๐ CVE-2026-104460 - High (7.5) YesWiki before 4.6.7 contains a blind SQL injection vulnerability in the {{newtextsearch}
A high-severity vulnerability, tracked as CVE-2026-104460 with a score of 7.5, has been identified in YesWiki versions before 4.6.7. The blind SQL injection flaw sits in the newtextsearch action, where Bazar list option ids are concatenated into SQL REGEXP and LIKE clauses without escaping. Anonymous attackers can exploit it remotely, and users are being urged to update.
- 2High-severity SQL injection flaw reported in HAVELSAN Sef chatbotโผ๐จ EUVD-2026-91329 ๐ Score: 8.8/10 (CVSS v3.1) ๐ฆ Product: Sef - AI Chatbot Platform ๐ข Vendor: Havelsan Inc. ๐ Updated: 20
A SQL injection vulnerability, tracked as EUVD-2026-91329, has been disclosed in the Sef AI Chatbot Platform developed by Turkish defence and IT company HAVELSAN. The flaw carries a CVSS v3.1 score of 8.8, placing it in the high-severity range. SQL injection bugs of this kind can let attackers manipulate database queries, potentially exposing or altering sensitive data.
- 3Critical Stirling PDF flaw with public exploit demands urgent patchโDetails and a PoC are public for CVE-2026-85714, a 9.1 Stirling PDF RCE via crafted SQL import. Upgrade to version 2.13.
A critical remote code execution vulnerability in Stirling PDF, tracked as CVE-2026-85714 and rated 9.1, has full technical details and a proof-of-concept exploit publicly available. The flaw stems from a crafted SQL import affecting the bundled H2 database. Administrators are urged to upgrade to version 2.13.2 immediately, as the public exploit makes attacks likely.
Repos
- Effect-TS/effect Build production-ready applications in TypeScript
- t8y2/dbx 25 MB lightweight cross-platform database client for 100+ databases, including MySQL, PostgreSQL, SQLite, Redis, MongoDB