<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
  <id>https://cve.radiocsirt.org/rss/recent/all/10</id>
  <title>Most recent entries from all</title>
  <updated>2026-10-03T09:00:24.435000+00:00</updated>
  <author>
    <name>Vulnerability-Lookup</name>
    <email>csirt@opendfir.org</email>
  </author>
  <link href="https://cve.radiocsirt.org" rel="alternate"/>
  <generator uri="https://lkiesow.github.io/python-feedgen" version="1.0.0">python-feedgen</generator>
  <subtitle>Contains only the most 10 recent entries.</subtitle>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/bdu:2022-00005</id>
    <title>bdu:2022-00005</title>
    <updated>2026-10-03T09:00:24.438166+00:00</updated>
    <content>bdu:2022-00005</content>
    <link href="https://cve.radiocsirt.org/vuln/bdu:2022-00005"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/euvd-2026-53934</id>
    <title>EUVD-2026-53934</title>
    <updated>2026-10-03T09:00:24.438197+00:00</updated>
    <content>EUVD-2026-53934</content>
    <link href="https://cve.radiocsirt.org/vuln/euvd-2026-53934"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10752</id>
    <title>fkie_cve-2019-10752</title>
    <updated>2026-10-03T09:00:24.438211+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml">
        <p>Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.</p>
      </div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/fkie_cve-2019-10752"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/ghsa-m9jw-237r-gvfv</id>
    <title>GHSA-m9jw-237r-gvfv — SQL Injection in sequelize</title>
    <updated>2026-10-03T09:00:24.438239+00:00</updated>
    <content type="xhtml">
      <div xmlns="http://www.w3.org/1999/xhtml"><p><strong>Affected:</strong> npm: sequelize</p>
<p>Affected versions of `sequelize` are vulnerable to SQL Injection. The function `sequelize.json()` incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query.  Exploitation example:</p>
<p>```js
return User.findAll({
  where: this.sequelize.json("data.id')) AS DECIMAL) = 1 DELETE YOLO INJECTIONS; -- ", 1)
});
```</p>
<p>## Recommendation</p>
<p>If you are using `sequelize` 5.x, upgrade to version 5.15.1 or later.
If you are using `sequelize` 4.x, upgrade to version 4.44.3 or later.</p></div>
    </content>
    <link href="https://cve.radiocsirt.org/vuln/ghsa-m9jw-237r-gvfv"/>
  </entry>
  <entry>
    <id>https://cve.radiocsirt.org/vuln/gsd-2019-10752</id>
    <title>gsd-2019-10752</title>
    <updated>2026-10-03T09:00:24.438269+00:00</updated>
    <content>gsd-2019-10752</content>
    <link href="https://cve.radiocsirt.org/vuln/gsd-2019-10752"/>
  </entry>
</feed>
