Tag
SQL Injection in Marten LINQ Provider via Unescaped Literals
2 TTPs 1 CVEMarten versions 7.0.0 through 9.12.0 contain critical SQL injection vulnerabilities in the LINQ provider and tenant-management internals, allowing attackers to perform unauthorized data access, multi-tenant bypass, and data modification via crafted dictionary keys or tenant IDs.
Stack-Based Buffer Overflow in IBM Db2 DRDA Client Implementation
2 TTPs 1 CVEIBM Db2 versions 11.5.0-11.5.9 and 12.1.0-12.1.5 are vulnerable to a stack-based buffer overflow via malicious DRDA server responses, potentially leading to arbitrary command execution on clients.
Authorization Bypass in IBM i DDM Target Dispatcher
1 CVEA vulnerability in the IBM i DDM target dispatcher allows remote attackers to manipulate database transactions due to improper authorization handling.
Missing Authorization Vulnerability in ArcadeDB DELETE FUNCTION Statement
1 rule 3 TTPs 1 CVEArcadeDB versions 26.7.3 and earlier are vulnerable to a missing authorization flaw allowing any authenticated database user to delete server-side functions via the command API.
Authentication Bypass and Privilege Escalation in ArcadeDB
1 rule 5 TTPs 1 CVEArcadeDB versions before 26.8.1 contain a vulnerability in the gRPC transaction executor that allows authenticated readers to execute arbitrary JavaScript, leading to server-wide privilege escalation.
NoSQL Injection in Budibase Server
1 TTP 1 CVEBudibase Server versions before 3.40.0 contain a NoSQL injection vulnerability in the MongoDB query execution endpoint, enabling authenticated attackers to bypass filters and perform unauthorized database operations.
Remote Code Execution in IBM Informix via sq_sgkprepare
2 TTPs 1 CVEA critical buffer-related vulnerability (CVE-2026-13361) in IBM Informix allows remote, unauthenticated attackers to achieve code execution via the SQL interface by exploiting an unchecked length field in the oninit process.
ArcadeDB Privilege Escalation via JavaScript Triggers
1 rule 3 TTPs 1 CVEArcadeDB versions before 26.7.3 insecurely expose the LocalDatabase object to JavaScript triggers, allowing attackers with schema update permissions to perform unauthorized administrative actions.