Vulnerabilities
Summary — last 7 days
New vulnerabilities3,029▲ 460 vs. last week
Critical / high1,445▲ 228 vs. last week
New active exploitation (KEV)8▼ 2 vs. last week
Unscored (no CVSS)365▲ 156 vs. last week
628 results, sorted by published date (most recent first)
| CVE | Status | Severity | EPSS | Active exploitation | Affected technologies | Published ▼ | Modified | Description |
|---|---|---|---|---|---|---|---|---|
| Awaiting Analysis | High (7.4) | 0.40% | — | KeycloakAIMysqlAIMariadbAI | 9/17/2026 | 9/22/2026 | A flaw was found in Keycloak. When deployed in stateless mode with MySQL or MariaDB, a mismatch in row-count semantics between the database driver and Keycloak's application logic allows an attacker to bypass replay protection. This vulnerability enables an attacker who intercepts single-use security artifacts, such… | |
| Awaiting Analysis | Low (3.7) | 0.37% | — | Mariadb Connector JAI | 9/17/2026 | 9/23/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, ClientMessage.readPacket processes a server-initiated LOCAL INFILE protocol packet 0xfb without enforcing allowLocalInfile=false. When an application sends a LOAD DATA LOCAL… | |
| Deferred | Medium (6.5) | 0.22% | — | Product Variations Swatches FOR WoocommerceAI | 9/3/2026 | 9/4/2026 | Subscriber Cross Site Scripting (XSS) in Product Variations Swatches for WooCommerce <= 1.1.18 versions. | |
| Awaiting Analysis | Medium (5.9) | 0.23% | — | Mariadb Connector R2dbcAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb does not gate clear-text password authentication plugins on transport encryption because the AuthenticationPlugin interface has no capability for a plugin to require a secure connection. A… | |
| Awaiting Analysis | Medium (5.9) | 0.49% | — | Mariadb Connector R2dbcAIMariadbAIMysqlAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/R2DBC is a non-blocking MariaDB and MySQL client implemented in Java. Prior to 1.4.1, org.mariadb:r2dbc-mariadb encodes and decodes all character data under the assumption that the connection character set is UTF-8. A server can announce a mid-session change to character_set_client through the… | |
| Awaiting Analysis | Medium (5.9) | 0.87% | — | Mariadb Connector/jAIMariadbAIOracle MysqlAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, the connector encodes and decodes protocol text and performs client-side escaping under the assumption that the connection character set is UTF-8. The server can report a… | |
| Awaiting Analysis | Medium (5.9) | 0.39% | — | Mariadb Connector JAIMysqlAIMariadbAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, PAM dialog authentication can be coerced into transmitting the account password over an insecure connection. The mysql_clear_password plugin is gated behind a secure… | |
| Awaiting Analysis | Medium (5.9) | 0.44% | — | Mariadb Connector/jAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/J is used to connect applications developed in Java to MariaDB and MySQL databases. Prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9, when a Java application connects with sslMode=verify-full or sslMode=verify-ca, supplies a password, and does not configure serverSslCert or trustStore, Connector/J can accept… | |
| Awaiting Analysis | Medium (6.5) | 0.47% | — | Mariadb Connector/node.jsAIMysqlAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js permits SQL injection when attacker-controlled Buffer parameters are escaped client-side under the big5, gbk, sjis, cp932, or gb18030 client… | |
| Awaiting Analysis | Medium (5.9) | 0.42% | — | Mariadb Connector/node.jsAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to 3.2.4, 3.3.3, 3.4.6, and 3.5.3, MariaDB Connector/Node.js can disclose an account password when PAM dialog authentication is negotiated over an insecure transport. In… | |
| Awaiting Analysis | High (7.5) | 0.57% | — | Mariadb Connector Node.jsAI | 8/28/2026 | 9/8/2026 | MariaDB Connector/Node.js is used to connect applications developed on Node.js to MariaDB and MySQL databases. Prior to versions 3.3.3, 3.4.6, and 3.5.3, when ssl is enabled without a pinned CA or server certificate, MariaDB Connector/Node.js sends credentials before completing certificate fingerprint validation. In… | |
| Deferred | High (8.8) | 0.39% | — | MariadbAI | 8/27/2026 | 8/28/2026 | The ‘/ws/apiprensa/getVideo’ endpoint is vulnerable to SQL injection due to improper validation of the GET parameter `id_ambito`. An attacker can inject SQL syntax that breaks the underlying structure of the MariaDB query, resulting in syntax errors and the exposure of database error messages via PDOException. This… | |
| Deferred | High (8.8) | 0.47% | — | MariadbAI | 8/27/2026 | 8/28/2026 | A vulnerability in the endpoint ‘/ws/apitribuna/ultimosVideos’ where the `limit_videos` parameter is directly concatenated into a MariaDB SQL query without proper sanitization or parameterization. By injecting SQL syntax into this parameter, a remote attacker can cause SQL syntax errors and potentially manipulate… | |
| Deferred | Critical (9.3) | 0.48% | — | MariadbAI | 8/27/2026 | 8/28/2026 | The endpoint ‘/ws/apiprensa/getVideoNextPrev’ is vulnerable to SQL injection via the id_ambito parameter. Unsanitized input is directly incorporated into a MariaDB query, allowing attackers to inject SQL syntax that interrupts the query's execution. The vulnerability results in detailed database error messages and… | |
| Deferred | Medium (4) | 0.16% | — | Aria2AI | 8/25/2026 | 9/8/2026 | aria2 <=1.37.0 has a stack-buffer-underflow vulnerability in the IOFile::getLine() function. | |
| Deferred | Medium (6.2) | 0.16% | — | Aria2AI | 8/24/2026 | 9/8/2026 | Aria2 version 1.37.0 and below is affected by a Divide By Zero issue in src/bittorrent_helper.cc, which allows a remote malicious user to cause a Denial of Service | |
| Deferred | High (7.1) | 0.25% | — | Swatchly - Woocommerce Variation Swatches FOR ProductsAI | 8/20/2026 | 8/20/2026 | Unauthenticated Cross Site Scripting (XSS) in Swatchly – WooCommerce Variation Swatches for Products <= 1.4.13 versions. | |
| Awaiting Analysis | High (7.1) | 0.45% | — | KohaAIMariadbAIMysqlAI | 8/11/2026 | 8/28/2026 | A stored SQL injection vulnerability in Koha through 24.11.17, 25.05.12, 25.11.06, and 26.05.01 allows authenticated staff with the tools => items_batchmod permission to read arbitrary database contents by storing a SQL payload in the agefield value of an automatic item modification rule. The agefield value is stored… | |
| Awaiting Analysis | High (7.5) | 0.61% | — | MariadbAIMinioAIRedhat Data Science Pipelines OperatorAI | 8/10/2026 | 9/21/2026 | A flaw was found in the Data Science Pipelines Operator. This vulnerability allows an unauthenticated attacker to derive sensitive credentials, such as MariaDB root/user passwords and MinIO access/secret keys, if they can access the MinIO Route or MariaDB Service. The flaw occurs because the operator uses a… | |
| Deferred | Medium (6.4) | 0.67% | — | DokployAIPostgresqlAIMariadbAIMysqlAI+2 | 8/10/2026 | 9/8/2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, database backup and restore command builders in packages/server/src/utils/backups/utils.ts and packages/server/src/utils/restore/utils.ts interpolate database names, usernames, and passwords into nested shell command strings passed to… | |
| Deferred | Critical (9.9) | 0.65% | — | DokployAIPostgresqlAIMariadbAIMysqlAI+1 | 8/10/2026 | 9/8/2026 | Dokploy is a free, self-hostable Platform as a Service (PaaS). Prior to 0.29.13, the backup.restoreBackupWithLogs tRPC subscription passes the databaseName parameter to restore builders in packages/server/src/utils/restore/utils.ts, where PostgreSQL, MariaDB, MySQL, and MongoDB commands embed the value in nested shell… | |
| Deferred | Low (2.1) | 0.43% | — | Akariasai Self RAGAI | 7/13/2026 | 7/13/2026 | A vulnerability was determined in AkariAsai self-rag up to 1fcdc420e48f50a7d7ab1ece5494221b93252e99. Affected by this issue is the function Indexer.deserialize_from of the file retrieval_lm/src/index.py of the component retrieval_lm. Executing a manipulation of the argument index_meta.faiss can lead to… | |
| Awaiting Analysis | High (7.6) | 0.47% | — | Langchain4jAILangchain4j-mariadbAILangchain4j-pgvectorAI | 7/10/2026 | 7/13/2026 | LangChain4j is a Java library for building LLM-powered applications on the JVM. Prior to 1.2.1-beta8, 1.5.1-beta11, 1.11.8-beta19, and 1.16.3-beta26, the MariaDB and pgvector embedding stores build metadata-filter SQL by string-concatenating filter keys, and in MariaDB string values, directly into the query without… | |
| Awaiting Analysis | Medium (5.3) | 0.31% | — | Bitnami Mariadb GaleraAIBitnami Mariadb Galera Helm ChartAI | 6/18/2026 | 6/22/2026 | Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIADB_REPLICATION_PASSWORD environment variables defaulted to monitor and monitor respectively. This user is granted… | |
| Modified | High (7.2) | 1.6% | — | Mariadb | 6/12/2026 | 8/3/2026 | MariaDB server is a community developed fork of MySQL server. From versions 10.6.1 to before 10.6.27, 10.11.1 to before 10.11.18, 11.4.1 to before 11.4.12, 11.8.1 to before 11.8.8, and 12.3.1, a high-privileged MariaDB user could've used wsrep_sst_receive_address or wsrep_sst_donor global system variables to execute… |