Overview
- PHP Group
- PHP
- ext-pgsql
30 Jul 2026
Published
31 Jul 2026
Updated
CVSS v4.0
HIGH (8.1)
EPSS
0.47%
KEV
Description
Improper escaping of backslashes in attacker-provided parameters would allow for trivial SQL injection in PHP versions from 8.2.* before 8.2.33, from 8.3.* before 8.3.33, from 8.4.* before 8.4.24, and from 8.5.* before 8.5.9.
Statistics
- 1 Post
Last activity: 3 hours ago
Overview
- Progress Software Corporation
- MarkLogic Server
05 Aug 2026
Published
07 Aug 2026
Updated
CVSS v3.1
HIGH (8.1)
EPSS
0.22%
KEV
Description
An improper privilege management vulnerability in the REST API document processing pipeline of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with an administrative REST role to escalate privileges. This can result in unauthorized disclosure of sensitive server-side data when it is accessed by a higher-privileged user.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
- Progress Software Corporation
- MarkLogic Server
05 Aug 2026
Published
07 Aug 2026
Updated
CVSS v3.1
CRITICAL (9.9)
EPSS
0.32%
KEV
Description
An improper privilege management vulnerability in the SQL, SPARQL, and Optic REST query interfaces of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows an authenticated user with a low-privileged REST role to escalate privileges to administrator. This enables execution of privileged operations and unauthorized data access.
Statistics
- 1 Post
Last activity: 22 hours ago
Description
The default configuration in Elasticsearch before 1.2 enables dynamic scripting, which allows remote attackers to execute arbitrary MVEL expressions and Java code via the source parameter to _search. NOTE: this only violates the vendor's intended security policy if the user does not run Elasticsearch in its own independent virtual machine.
Statistics
- 1 Post
Last activity: 19 hours ago
Overview
- Progress Software Corporation
- MarkLogic Server
05 Aug 2026
Published
07 Aug 2026
Updated
CVSS v3.1
HIGH (7.5)
EPSS
0.14%
KEV
Description
A cross-site request forgery vulnerability in the Admin UI of Progress MarkLogic Server before 11.3.6 and 12.0.3 allows a remote attacker who lures an authenticated administrator to a malicious web page to perform administrative actions on the administrator's behalf. This can result in unauthorized changes to security configuration.
Statistics
- 1 Post
Last activity: 22 hours ago
Overview
Description
Directory traversal vulnerability in Elasticsearch before 1.6.1 allows remote attackers to read arbitrary files via unspecified vectors related to snapshot API calls.
Statistics
- 1 Post
Last activity: 19 hours ago
Description
The Groovy scripting engine in Elasticsearch before 1.3.8 and 1.4.x before 1.4.3 allows remote attackers to bypass the sandbox protection mechanism and execute arbitrary shell commands via a crafted script.
Statistics
- 1 Post
Last activity: 19 hours ago