Skip to main content
← All Articles

Tag

#SQL Injection

35 articles

Advertisement

HIGH
Data Breach

Mathspace Breach: Over 1 Million Impacted by Metabase Zero-Day

Mathspace disclosed a data breach affecting over 1 million students, staff, and parents due to a Metabase vulnerability.

Runtime Rebel Intel
4 min read · Sep 7, 2026
CRITICAL
Vulnerabilities

CVE-2026-9586: Sangoma Switchvox RCE via SQL Injection

Sangoma Switchvox is affected by CVE-2026-9586, an unauthenticated remote SQL injection vulnerability enabling RCE, with active exploitation confirmed.

Runtime Rebel Intel
4 min read · Sep 2, 2026
HIGH
Data Breach

ShinyHunters Breaches ShipMonk: 14,000 Trezor Customers' Data Exposed

ShinyHunters group breached shipping provider ShipMonk, exposing personal data of 14,000 Trezor customers via a Metabase SQL injection vulnerability.

Runtime Rebel Intel
5 min read · Aug 14, 2026
CRITICAL
Vulnerabilities

CVE-2026-72898: Metabase SQL Injection Active Exploitation

CISA adds Metabase CVE-2026-72898 SQL injection to its KEV catalog, enabling unauthenticated remote attackers to gain admin access.

Runtime Rebel Intel
3 min read · Aug 12, 2026
Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms
HIGH
Vulnerabilities

Metabase Zero-Day SQL Vulnerability Threatens Analytics Platforms

Unpatched Metabase business-analytics zero-day vulnerability allows remote administrative access and threatens downstream corporate networks.

Runtime Rebel Intel
3 min read · Aug 11, 2026
Metabase Zero-Day Exploited: Unauthenticated Admin Access
CRITICAL
Vulnerabilities

Metabase Zero-Day Exploited: Unauthenticated Admin Access

Metabase zero-day vulnerability (CVSS 10.0) actively exploited, allowing unauthenticated remote attackers to gain admin access and steal data.

Runtime Rebel Intel
3 min read · Aug 8, 2026

Advertisement

CRITICAL
Vulnerabilities

Metabase SQLi Zero-Day Exploited: Data Theft Attacks Confirmed

A critical Metabase SQL injection zero-day vulnerability (versions 1.58+) has been exploited in data theft attacks affecting customers like Framework and Tally.

Runtime Rebel Intel
4 min read · Aug 8, 2026
khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access
HIGH
Vulnerabilities

khunt Toolkit Leverages SQLi in Oracle for SYSTEM Access

Attackers exploit SQL injection in a public-facing web app to compile the khunt toolkit within Oracle, achieving SYSTEM-level access on Windows servers.

Runtime Rebel Intel
4 min read · Aug 6, 2026
CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation
HIGH
Vulnerabilities

CVE-2026-58048: cPanel & WHM Critical SQL Privilege Escalation

A critical flaw in cPanel & WHM (CVE-2026-58048) allows authenticated users to execute SQL as database root, potentially leading to OS-level compromise.

Runtime Rebel Intel
4 min read · Aug 4, 2026
CRITICAL
Vulnerabilities

CVE-2026-60137: WordPress Core SQL Injection to RCE — Patch Now

CISA warns of active exploitation for CVE-2026-60137, a WordPress Core SQL Injection vulnerability chaining to RCE for unauthenticated attackers.

Runtime Rebel Intel
4 min read · Aug 2, 2026
CRITICAL
Vulnerabilities

CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE

Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.

Runtime Rebel Intel
4 min read · Jul 20, 2026
CRITICAL
Vulnerabilities

Critical RCEs: FortiNAC CVE-2023-33300 & SonicWall SMA Zero-Day

Two critical vulnerabilities, FortiNAC RCEs (CVE-2023-33300, CVE-2023-33299) and a SonicWall SMA zero-day SQLi, require immediate patching and mitigation.

Runtime Rebel Intel
5 min read · Jul 7, 2026
HIGH
Vulnerabilities

Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 & CVE-2026-41125

Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125).

Runtime Rebel Intel
5 min read · Jun 9, 2026
HIGH
Threat Intel

Hardening Automatic Tank Gauge Systems Against Cyber Threats

CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.

Runtime Rebel Intel
4 min read · Jun 2, 2026
CRITICAL
Vulnerabilities

CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation

Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.

Runtime Rebel Intel
3 min read · May 28, 2026
HIGH
Vulnerabilities

Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert

CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.

Runtime Rebel Intel
3 min read · May 26, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read · May 25, 2026
HIGH
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read · May 24, 2026
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog

CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

Runtime Rebel Intel
3 min read · May 23, 2026
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation

CISA adds CVE-2026-9082, a critical Drupal Core SQL Injection vulnerability, to KEV Catalog due to active exploitation. Immediate patching required for all organizations.

Runtime Rebel Intel
4 min read · May 23, 2026
HIGH
Vulnerabilities

CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance

Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.

Runtime Rebel Intel
3 min read · May 15, 2026
CRITICAL
Vulnerabilities

CVE-2026-42208: BerriAI LiteLLM SQLi Exploitation — Patch Now

CISA adds CVE-2026-42208, a critical SQL injection vulnerability in BerriAI LiteLLM, to KEV catalog. Active exploitation confirmed.

Runtime Rebel Intel
4 min read · May 8, 2026
CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection
CRITICAL
Vulnerabilities

CVE-2026-42208: Active Exploitation of LiteLLM SQL Injection

Attackers are actively exploiting CVE-2026-42208, a critical SQL injection flaw in LiteLLM, within 36 hours of disclosure. Patch to prevent database compromise.

Runtime Rebel Intel
4 min read · Apr 29, 2026
CRITICAL
Vulnerabilities

CVE-2026-42208: LiteLLM Pre-Auth SQLi Actively Exploited – Patch Now

Hackers are actively exploiting CVE-2026-42208, a critical pre-authentication SQL injection vulnerability in LiteLLM, to access sensitive data.

Runtime Rebel Intel
5 min read · Apr 29, 2026