Proactive Insights and Support For Open-Source Applications
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
Book a demo
Book a demo
  • Applications
  • Platform
  • Support
  • Resources
    • 2025 OSS Research
    • FAQ
    • Newsflash
    • OSSpedia
    • How-to Guides
    • Case Studies
    • Articles
  • Company
    • About Us
    • The OSS in Hossted
  • Contact
  • Home
  • Knowledge Base
  • Newsflash
  • Data Management and Analytics
  • Database

Database

All OSSpediaArticlesHow ToNewsflashCase Studies
Don't Miss out!
Join our newsletter for exclusive updates on open source innovations.

    Selected category
    • Communication
      • Communication
    • Communication and Collaboration
      • Communication
    • Specialized Software
      • Educational
      • Graphic Design
    • Business and Enterprise Solutions
      • Customer Service
      • Productivity
      • Supply Chain Management (SCM)
      • CRM
      • E-commerce
      • CMS
      • Marketing Automation
      • ERP
    • Project and Agile Management
      • Project Management
      • IT Business Management
    • Infrastructure and Network
      • CMS
      • Networking
      • Storage
      • Security
    • DevOps
      • DevOps
      • Mobile App Development
      • Backup and Recovery
      • Data Analytics
      • Web Development
      • Developer Stacks
      • Cloud Computing
      • Monitoring
      • Application Development
      • Developer Tools
    • Data Management and Analytics
      • Communication
      • Application Development
      • Analytics
      • Machine Learning
      • Database
      • Data Analytics
    9 Oct 2025 Data Management and Analytics
    Redis: Denial of Service via Malicious Lua Scripts

    In Redis versions 8.2.1 and below a medium severity vulnerability CVE-2025-46819 was detected. Authenticated users can use specially crafted Lua scripts to read out-of-bounds data or crash the server, leading to denial of service (DoS). This issue affects all Redis versions with Lua scripting enabled. To address this issue, users should upgrade Redis to version 8.2.2 or later. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46819.

    Read more
    Database
    22 Aug 2025 Data Management and Analytics
    PostgreSQL: Code Injection Vulnerability

    In PostgreSQL versions 13 through 17 a high severity vulnerability CVE-2025-8714 was detected. This vulnerability allows attackers to inject arbitrary code for restore-time execution as the client operating system account running psql via psql meta-commands. To address this issue, users should upgrade PostgreSQL to versions 13.22, 14.19, 15.14, 16.10 or 17.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8714.

    Read more
    Database
    21 Aug 2025 Data Management and Analytics
    PostgreSQL: Code and SQL Injection Vulnerability

    In PostgreSQL versions 13 through 17 a high severity vulnerability CVE-2025-8715 was detected. This vulnerability allows attackers to inject arbitrary code or achieve SQL injection via a purpose-crafted object name during the restore process. To address this issue, users should upgrade PostgreSQL to versions 13.22, 14.19, 15.14, 16.10 or 17.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8715.

    Read more
    Database
    21 Aug 2025 Data Management and Analytics
    PostgreSQL: Data Leakage Vulnerability

    In PostgreSQL versions 13 through 17 a low severity vulnerability CVE-2025-8713 was detected. This vulnerability allows attackers to read sampled data from views or tables that are protected by access control lists (ACLs) or row security policies. To address this issue, users should upgrade PostgreSQL to versions 13.22, 14.19, 15.14, 16.10 or 17.6. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-8713.

    Read more
    Database
    30 Jul 2025 Data Management and Analytics
    SQLite: Crafted SQL Query Can Crash System or Leak Data

    In SQLite versions from 3.39.2 to before 3.41.2 a medium severity vulnerability CVE-2025-7458 was detected. This vulnerability allows attackers to crash the system or read sensitive data from memory by running a specially crafted SELECT query with many items in the ORDER BY part. To address this issue, users should upgrade SQLite to versions 3.41.2 or later. For more details, visit https://avd.aquasec.com/nvd/2025/cve-2025-7458.

    Read more
    Database
    25 Jul 2025 Data Management and Analytics
    Redis: Memory Consumption via Multi-Bulk Command

    In Redis versions up to and including 8.0.3 a medium severity vulnerability CVE-2025-46686 was detected. This vulnerability allows authenticated attackers to cause excessive memory consumption by sending a multi-bulk command with many bulks, even if the command is skipped due to insufficient permissions. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-46686.

    Read more
    Database
    16 Jul 2025 Data Management and Analytics
    Oracle MySQL: Unauthorized Data Access and Modification via mysqldump Client Vulnerability

    In Oracle MySQL Client versions 8.0.0 through 8.0.42, 8.4.0 through 8.4.5 and 9.0.0 through 9.3.0 a low severity vulnerability CVE-2025-50081 was detected in the mysqldump component. This vulnerability allows high-privileged attackers with network access and requiring user interaction to perform unauthorized updates, inserts, deletes, or read access to MySQL Client-accessible data. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-50081.

    Read more
    Database
    16 Jul 2025 Data Management and Analytics
    Oracle MySQL: Remote DoS via Replication Component

    In Oracle MySQL Server versions 8.0.0 through 8.0.42 a medium severity vulnerability CVE-2025-53023 was detected in the Replication component. This vulnerability allows high-privileged attackers with network access to cause a hang or repeatable crash of the MySQL Server, resulting in denial-of-service (DoS). Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-53023.

    Read more
    Database
    16 Jul 2025 Data Management and Analytics
    Oracle MySQL: Remote Data Integrity Vulnerability via Optimizer Component

    In Oracle MySQL Server versions 8.0.0 through 8.0.42, 8.4.0 through 8.4.5 and 9.0.0 through 9.3.0 a medium severity vulnerability CVE-2025-50087 was detected in the Optimizer component. This vulnerability allows high-privileged attackers with network access to create, delete, or modify critical data without authorization. Currently, there is no fix version for this issue. For more details, visit https://nvd.nist.gov/vuln/detail/CVE-2025-50087.

    Read more
    Database
    Proactive Insights and Support For Open-Source Applications
    Contact us: Whatsapp
    Company
    • About Hossted
    • Data Processing Addendum
    Solutions
    • Applications
    • Support Plans
    • About Solution
    Resources
    • FAQ
    • Knowledge Base

    © HOSSTED 2026 All rights reserved

    • Privacy Policy
    • Terms and Conditions
    • Cookies Policy
    Cookie Settings

    We use cookies to measure marketing efforts and improve our services. Please review the cookie settings and confirm your choice.

    Functional Always active
    The technical storage or access is strictly necessary for the legitimate purpose of enabling the use of a specific service explicitly requested by the subscriber or user, or for the sole purpose of carrying out the transmission of a communication over an electronic communications network.
    Preferences
    The technical storage or access is necessary for the legitimate purpose of storing preferences that are not requested by the subscriber or user.
    Statistics
    The technical storage or access that is used exclusively for statistical purposes. The technical storage or access that is used exclusively for anonymous statistical purposes. Without a subpoena, voluntary compliance on the part of your Internet Service Provider, or additional records from a third party, information stored or retrieved for this purpose alone cannot usually be used to identify you.
    Marketing
    The technical storage or access is required to create user profiles to send advertising, or to track the user on a website or across several websites for similar marketing purposes.
    • Manage options
    • Manage services
    • Manage {vendor_count} vendors
    • Read more about these purposes
    View preferences
    • {title}
    • {title}
    • {title}