24h | 7d | 30d

Overview

  • PHP Group
  • PHP
  • ext-pgsql

30 Jul 2026
Published
31 Jul 2026
Updated

CVSS v4.0
HIGH (8.1)
EPSS
0.47%

KEV

Description

Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.

Statistics

  • 1 Post

Last activity: 3 hours ago

Bluesky

Profile picture fallback
🛡️ Security updates: Modules: - php-7.3.33-22 - php-7.2.34-29 Software Collections: - php73-php-7.3.33-22 - php72-php-7.2.34-29 With recent security fix backported from 8.2.33 (CVE-2026-17543, CVE-2026-7260)
  • 0
  • 0
  • 0
  • 3h ago

Overview

  • Progress Software Corporation
  • MarkLogic Server

05 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
HIGH (8.1)
EPSS
0.22%

KEV

Description

An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Advisories issued for Zyxel firewall/AP vulnerabilities and Progress MarkLogic Server flaws. - IOCs: CVE-2026-7326, CVE-2026-7327, CVE-2026-7329 - #Progress #ThreatIntel #VulnManagement #Zyxel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Progress Software Corporation
  • MarkLogic Server

05 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
CRITICAL (9.9)
EPSS
0.32%

KEV

Description

An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Advisories issued for Zyxel firewall/AP vulnerabilities and Progress MarkLogic Server flaws. - IOCs: CVE-2026-7326, CVE-2026-7327, CVE-2026-7329 - #Progress #ThreatIntel #VulnManagement #Zyxel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

28 Jul 2014
Published
22 Oct 2025
Updated

CVSS
Pending
EPSS
88.56%

Description

The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
~Spiderlabs~ RAVEN framework exploits six Elasticsearch CVEs including root-level RCE via MVEL/Groovy script injection and arbitrary file reads via directory traversal. - IOCs: CVE-2014-3120, CVE-2015-1427, CVE-2015-5531 - ...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Progress Software Corporation
  • MarkLogic Server

05 Aug 2026
Published
07 Aug 2026
Updated

CVSS v3.1
HIGH (7.5)
EPSS
0.14%

KEV

Description

A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.

Statistics

  • 1 Post

Last activity: 22 hours ago

Bluesky

Profile picture fallback
~Cybergcca~ Advisories issued for Zyxel firewall/AP vulnerabilities and Progress MarkLogic Server flaws. - IOCs: CVE-2026-7326, CVE-2026-7327, CVE-2026-7329 - #Progress #ThreatIntel #VulnManagement #Zyxel
  • 0
  • 0
  • 0
  • 22h ago

Overview

  • Pending

17 Aug 2015
Published
06 Aug 2024
Updated

CVSS vV2
MEDIUM (5.0)
EPSS
91.75%

KEV

Description

Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
~Spiderlabs~ RAVEN framework exploits six Elasticsearch CVEs including root-level RCE via MVEL/Groovy script injection and arbitrary file reads via directory traversal. - IOCs: CVE-2014-3120, CVE-2015-1427, CVE-2015-5531 - ...
  • 0
  • 0
  • 0
  • 19h ago

Overview

  • Pending

17 Feb 2015
Published
22 Oct 2025
Updated

CVSS
Pending
EPSS
99.91%

Description

The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.

Statistics

  • 1 Post

Last activity: 19 hours ago

Bluesky

Profile picture fallback
~Spiderlabs~ RAVEN framework exploits six Elasticsearch CVEs including root-level RCE via MVEL/Groovy script injection and arbitrary file reads via directory traversal. - IOCs: CVE-2014-3120, CVE-2015-1427, CVE-2015-5531 - ...
  • 0
  • 0
  • 0
  • 19h ago
Showing 41 to 47 of 47 CVEs