#Database Security
All CosmicBytez Labs articles tagged #Database Security, across news, security advisories, how-to guides, and projects.
- Security
IBM Concert SQL Injection Flaw Allows Unauthenticated Database Compromise
CVE-2026-3627 (CVSS 9.1) lets remote attackers run arbitrary SQL against IBM Concert 1.0.0-2.3.1 with no authentication, exposing the backend DB.
- Security
CVE-2026-78155: Critical Privilege Escalation in StackGres Kubernetes Operator
A CVSS 9.9 flaw in the StackGres Kubernetes operator lets a low-privilege tenant escalate to full cluster admin rights.
- Security
CVE-2026-72811: SiYuan SQL Injection in Backlink Search Scores Perfect 10.0
SiYuan note-taking app up to v3.7.2 is vulnerable to SQL injection via stored block metadata in the backlink search query path.
- Security
CVE-2026-19001: MongoDB BI Connector ODBC Driver Buffer Overflow (CVSS 9.8)
Critical CVSS 9.8 buffer overflow in the MongoDB BI Connector ODBC Driver may allow remote code execution via long metadata names.
- Security
CVE-2026-24013: Apache IoTDB Authentication Bypass via Forged Session ID
A critical authentication bypass in Apache IoTDB allows unauthenticated attackers to forge Thrift RPC session IDs and receive valid time-series query...
- Security
CVE-2026-24014: Apache IoTDB DataNode Path Traversal via Trigger JAR Upload
A critical path traversal vulnerability in Apache IoTDB's DataNode RPC interface allows unauthenticated attackers to write arbitrary files outside the...
- Security
CVE-2026-2993: SQL Injection in AIWU AI Chatbot WordPress
A high-severity SQL injection vulnerability (CVE-2026-2993) in the AI Chatbot & Workflow Automation by AIWU WordPress plugin allows unauthenticated...
- Security
CVE-2026-34260 — SAP S/4HANA SQL Injection via ABAP
A critical SQL injection vulnerability in SAP S/4HANA Enterprise Search for ABAP allows authenticated attackers to inject malicious SQL statements via...
- Security
CVE-2018-25272: ELBA5 5.8.0 RCE via Default Database
ELBA5 5.8.0 contains a critical remote code execution vulnerability where default database connector credentials allow attackers to connect to the...