Skip to content
Threat Feed

Product

MySQL

5 briefs RSS
critical advisory

SQL Injection Vulnerability in Budibase MySQL Integration

A critical SQL injection vulnerability was discovered in Budibase's MySQL integration (versions <= 3.38.1) that allows remote attackers to execute arbitrary SQL commands through user input fields due to the `multipleStatements: true` configuration, leading to complete database compromise.

Budibase Server +1 sql-injection web-application vulnerability nosql-injection data-exfiltration data-destruction application-vulnerability csrft +4
1r 7t
high advisory

Oracle Security Updates — July 2026

Roundup of Oracle security advisories published in July 2026.

Oracle Application Testing Suite 13.3.0.1 +177 roundup
5c 1i updated
critical advisory

Multiple Vulnerabilities in Oracle MySQL

A remote, anonymous, or authenticated attacker can exploit multiple vulnerabilities in Oracle MySQL to compromise confidentiality, integrity, and availability.

MySQL vulnerability database exploitation
2r
high advisory

Kysely JSON-path Injection Vulnerability

A JSON-path traversal injection vulnerability exists in Kysely versions prior to 0.28.16, allowing attackers to traverse JSON sub-fields outside the intended scope, potentially leading to unauthorized read and write access to sensitive data in MySQL, PostgreSQL, and SQLite databases due to insufficient sanitization of JSON-path metacharacters in the `JSONPathBuilder.key()` and `.at()` functions.

MySQL +3 jsonpath injection kysely cwe-89 cwe-915 cwe-1284
2r 1t 1c
medium advisory

Potential Database Dumping Activity on Linux

This rule detects the use of database dumping utilities to exfiltrate data from a database on Linux systems, where attackers may attempt to dump the database to a file and then exfiltrate the file to a remote server.

PostgreSQL +3 exfiltration database linux
2r 1t