In Redis in affected versions a high severity vulnerability CVE-2026-92925 was detected. This vulnerability allows an attacker to cause a denial of service or potentially execute arbitrary code. To address this issue, users should upgrade Redis to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-92925.
Read more DatabaseIn MariaDB Connector/J component for MariaDB versions prior to 2.7.14, 3.3.5, 3.4.3, and 3.5.9 a low severity vulnerability CVE-2026-61700 was detected. This vulnerability allows a malicious server to read local files on the client. To address this issue, users should upgrade MariaDB Connector/J to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-61700.
Read more DatabaseIn PostGIS component for PostgreSQL versions 3.7.0 and earlier a medium severity vulnerability CVE-2026-90775 was detected. This vulnerability allows attackers to cause the backend process to crash, leading to a denial of service. To address this issue, users should upgrade PostGIS to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-90775.
Read more DatabaseIn PostgreSQL Anonymizer component for PostgreSQL versions earlier than 3.1.4 a high severity vulnerability CVE-2026-19633 was detected. This vulnerability allows unprivileged masked users to execute arbitrary code with elevated privileges. To address this issue, users should upgrade PostgreSQL Anonymizer to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19633.
Read more DatabaseIn Baserow version 2.3.3 a high severity vulnerability CVE-2026-19754 was detected. This vulnerability allows a low-privileged authenticated user to execute arbitrary database queries, leading to SQL Injection (SQLi) and potential privilege escalation. This occurs due to improper input validation in the index() formula function. A user with permissions to create or modify formula fields can provide an undocumented fourth argument that is treated as a SQL template and interpolated directly into a PostgreSQL expression. When Baserow recalculates the formula field values, the injected payload is executed. Because the generated SQL runs through the application’s database connection, it executes with the full privileges of the Baserow PostgreSQL role rather than the restricted permissions of the authenticated user. To address this issue, users should upgrade Baserow to a patched version 2.3.3. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-19754.
In SQLite in affected versions a medium severity vulnerability CVE-2025-41771 was detected. This vulnerability allows an authenticated attacker to perform a SQL injection. To address this issue, users should upgrade SQLite to the latest available version. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-41771.
Read more DatabaseIn Baserow versions up to 2.3.2 a medium severity vulnerability CVE-2026-18816 was detected. This vulnerability allows a remote attacker to bypass two-factor authentication (2FA) mechanisms, leading to improper authentication and potential unauthorized account access. This occurs due to a flaw in the verify function within the backend/src/baserow/api/two_factor_auth/views.py file of the 2FA Verify Endpoint. Although the attack complexity is considered high and exploitation is difficult, successful manipulation of this endpoint compromises the authentication process. To address this issue, users should upgrade Baserow to version 2.3.3 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-18816.
In MongoDB versions prior to 7.0.39 a medium severity vulnerability CVE-2026-13066 was detected. This vulnerability allows for the disclosure of internal process memory contents. To address this issue, users should upgrade MongoDB to version 7.0.39 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13066.
Read more DatabaseIn MongoDB versions prior to 8.0.28 a medium severity vulnerability CVE-2026-13064 was detected. This vulnerability allows attackers to cause resource exhaustion through specially crafted queries. To address this issue, users should upgrade MongoDB to version 8.0.28 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2026-13064.
Read more Database