Skip to main content
← All Articles

Tag

#SQL Injection

25 articles

Advertisement

VU
CRITICAL
Vulnerabilities

CVE-2026-63030: WordPress Core SQLi Leads to Unauth RCE

Critical SQL injection vulnerability (CVE-2026-63030) in WordPress Core enables unauthenticated remote code execution. Active exploitation confirmed.

Runtime Rebel Intel
4 min read·Jul 20, 2026
VU
CRITICAL
Vulnerabilities

Critical RCEs: FortiNAC CVE-2023-33300 & SonicWall SMA Zero-Day

Two critical vulnerabilities, FortiNAC RCEs (CVE-2023-33300, CVE-2023-33299) and a SonicWall SMA zero-day SQLi, require immediate patching and mitigation.

Runtime Rebel Intel
5 min read·Jul 7, 2026
VU
HIGH
Vulnerabilities

Siemens KACO Blueplanet Inverter Vulnerabilities: CVE-2025-40946 & CVE-2026-41125

Critical Siemens KACO Blueplanet Inverters are vulnerable to credential derivation (CVE-2025-40946) and SQL injection (CVE-2026-41125). Update now to mitigate

Runtime Rebel Intel
5 min read·Jun 9, 2026
TH
HIGH
Threat Intel

Hardening Automatic Tank Gauge Systems Against Cyber Threats

CISA and partners warn of active cyber threats targeting Automatic Tank Gauge (ATG) systems. Learn to secure critical infrastructure assets now.

Runtime Rebel Intel
4 min read·Jun 2, 2026
VU
CRITICAL
Vulnerabilities

CVE-2023-48788: Critical FortiClient EMS RCE Under Active Exploitation

Exploitation of CVE-2023-48788 in FortiClient EMS allows unauthenticated remote code execution. Administrators must patch to version 7.2.3 or 7.0.11 immediately.

Runtime Rebel Intel
3 min read·May 28, 2026
VU
HIGH
Vulnerabilities

Drupal 7.x SQL Injection CVE-2014-3704 — Active Exploitation Alert

CISA adds Drupalgeddon SQL injection (CVE-2014-3704) to KEV catalog, mandating federal agencies to patch critical legacy systems against active exploits.

Runtime Rebel Intel
3 min read·May 26, 2026
CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks
CRITICAL
Vulnerabilities

CVE-2026-26980: Ghost CMS SQL Injection Leads to ClickFix Attacks

Attackers exploit CVE-2026-26980 in Ghost CMS to compromise 700+ websites, deploying ClickFix malware that tricks users into executing malicious scripts.

Runtime Rebel Intel
4 min read·May 25, 2026
VU
CRITICAL
Vulnerabilities

CVE-2025-26980: Ghost CMS SQL Injection Exploited in ClickFix Campaign

A critical SQL injection vulnerability in Ghost CMS (CVE-2025-26980) is being exploited to deliver ClickFix malware through malicious JavaScript injections.

Runtime Rebel Intel
3 min read·May 24, 2026
CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Added to CISA KEV Catalog

CISA warns of active exploitation of CVE-2026-9082, a critical SQL injection vulnerability in Drupal Core. Organizations must patch to prevent data exposure.

Runtime Rebel Intel
3 min read·May 23, 2026
VU
HIGH
Vulnerabilities

CVE-2026-9082: Drupal Core SQL Injection Under Active Exploitation

CISA adds CVE-2026-9082, a critical Drupal Core SQL Injection vulnerability, to KEV Catalog due to active exploitation. Immediate patching required for all organizations.

Runtime Rebel Intel
4 min read·May 23, 2026
VU
HIGH
Vulnerabilities

CVE-2024-2123 & CVE-2024-2510: Avada Builder Patch Guidance

Critical flaws in Avada Builder WordPress plugin (CVE-2024-2123, CVE-2024-2510) allow for credential theft and LFI. Immediate update to version 3.11.7 required.

Runtime Rebel Intel
3 min read·May 15, 2026
VU
CRITICAL
Vulnerabilities

CVE-2026-42208: BerriAI LiteLLM SQLi Exploitation — Patch Now

CISA adds CVE-2026-42208, a critical SQL injection vulnerability in BerriAI LiteLLM, to KEV catalog. Active exploitation confirmed. Timely patching is essential for all

Runtime Rebel Intel
4 min read·May 8, 2026