Collected every two hours from specialised publications — each link leads to the original article.
Veeam has released security updates to address multiple flaws in its Backup & Replication software, including a "critical" issue that could result in remote co…
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2025-12819 Untrusted search path in auth_query connection handler in PgBouncer before 1.25.1 a…
Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL Fixes CVE-2025-64460: Potential denial-of-service vulnerability …
Fixes CVE-2025-13372: Potential SQL injection in FilteredRelation column aliases on PostgreSQL Fixes CVE-2025-64460: Potential denial-of-service vulnerability …
An authentication bypass was found in n pgpool-II, the connection pool server and replication proxy for PostgreSQL. For Debian 11 bullseye, this problem has be…
Redis could be made to crash or run programs if it received specially crafted network traffic from an authenticated user.
Release 5.14.1 - 2025-10-02 Restore support for rediss:// URLs, and add support for valkeys:// as well Add support for Redis connections using unix sockets Rel…
Let's talk about something that's been slipping under the radar: Soco404 . If you manage Linux systems in any capacity''or just spend time keeping production e…
ADOdb is a PHP database class library that provides abstractions for performing queries and managing databases. Prior to version 5.22.9, improper escaping of a…
MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client sys…
PgBouncer is a lightweight connection pooler for PostgreSQL. CVE-2021-3539
SQL injection in the PostgreSQL driver has been fixed in the ADOdb database access library for PHP. For Debian 11 bullseye, this problem has been fixed in vers…
Keeping WordPress secure can be challenging, especially when considering Linux security concerns in a typical LAMP stack setup. Most WordPress security issues …
Multiple vulnerabilities have been fixed in the PostgreSQL JDBC Driver. CVE-2022-31197
Two vulnerabilities were discovered in pgpool2, a connection pool server and replication proxy for PostgreSQL. CVE-2023-22332
A new stable version was released for galera-4, a synchronous multimaster replication engine for MySQL and MariaDB. This fixes several issues detailed at:
pymongo a python interface to the MongoDB document-oriented database was vulnerable. An out-of-bounds read in the 'bson' module allowed deserialization of
The peer-to-peer malware botnet known as P2PInfect has been found targeting misconfigured Redis servers with ransomware and cryptocurrency miners.The developme…
MariaDB 10.5.25 & Galera 26.4.18 Release notes: https://mariadb.com/kb/en/mariadb-10-5-25-release-notes/
MariaDB 10.11.8 & Galera 26.4.18 Release notes: https://mariadb.com/kb/en/mariadb-10-11-7-release-notes/ https://mariadb.com/kb/en/mariadb-10-11-8-release-note…
A possible SQL injection vulnerability was found in libpgjava, the PostgreSQL JDBC Driver. It allows an attacker to inject SQL if using PreferQueryMode=SIMPLE …
The malicious code inserted into the open-source library XZ Utils, a widely used package present in major Linux distributions, is also capable of facilitating …
A set of fake npm packages discovered on the Node.js repository has been found to share ties with North Korean state-sponsored actors, new findings from Phylum…
Four security vulnerabilities in the ScrutisWeb ATM fleet monitoring software made by Iagona could be exploited to remotely break into ATMs, upload arbitrary f…