Roundcube SQL injection CVE-2026-48842 is now being exploited in the wild, putting unpatched webmail servers at risk of ...
Threat actors are actively exploiting a critical SQL injection vulnerability in Roundcube Webmail that can be triggered without authentication.
Roundcube Webmail SQL injection flaw CVE-2026-48842 is actively exploited, urging users to update vulnerable installations.
Lasso Security and GBHackers reported in September 2026 that CVE-2026-77521 can let prompt injection trigger operating-system ...
Panel patched CVE-2026-67401, which lets a hosting account with mail privileges create files anywhere and run code as root.
A single unauthenticated HTTP request to Metabase's password-reset endpoint was all it took for an attacker to gain full administrator access to an analytics platform trusted by tens of thousands of ...
Attackers chained SQL injection with Oracle’s embedded Java capabilities to hide a custom post-exploitation toolkit inside the database and gain SYSTEM-level access to the underlying Windows server.
Attackers have begun to exploit two critical vulnerabilities in WordPress that, when combined together, enable unauthenticated remote code execution (RCE) and complete compromise of vulnerable ...
A large-scale campaign is exploiting a critical SQL injection vulnerability (CVE-2026-26980) in Ghost CMS to inject malicious JavaScript code that triggers ClickFix attack flows. The campaign was ...
Drupal is warning that hackers are attempting to exploit a "highly critical" SQL injection vulnerability announced earlier this week. The content management system (CMS) project published a PSA on May ...
A critical SQL injection flaw in FortiClient EMS allows remote code execution and data exfiltration, leaving thousands of internet facing systems at risk. Yet another critical flaw in a Fortinet ...
Some results have been hidden because they may be inaccessible to you
Show inaccessible results