Security
Headlines
HeadlinesLatestCVEs

Tag

#sql

CVE-2023-32027

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE
#sql#vulnerability#microsoft#rce
CVE-2023-32026

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-29356

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-32025

Microsoft ODBC Driver for SQL Server Remote Code Execution Vulnerability

CVE-2023-2080: Forcepoint Customer Hub

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.

CVE-2023-31672: [CVE-2023-31672] Improper neutralization of an SQL parameter in ailinear module for PrestaShop

In the PrestaShop < 2.4.3 module "Length, weight or volume sell" (ailinear) there is a SQL injection vulnerability.

URLs have always been a great hiding place for threat actors

The information leak threats are certainly new, but the education and messaging from security evangelists (and even just anyone trying to educate an older or less security-savvy family member) doesn’t change.

CVE-2023-34666: OffSec’s Exploit Database Archive

Cross-site scripting (XSS) vulnerability in Phpgurukul Cyber Cafe Management System 1.0 allows remote attackers to inject arbitrary web script or HTML via the admin username parameter.