<?xml version='1.0' encoding='UTF-8'?>
<?xml-stylesheet href="/static/style.xsl" type="text/xsl"?>
<rss xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title>Most recent entries from all</title>
    <link>https://cve.radiocsirt.org</link>
    <description>Contains only the most 10 recent entries.</description>
    <docs>http://www.rssboard.org/rss-specification</docs>
    <generator>python-feedgen</generator>
    <language>en</language>
    <lastBuildDate>Sat, 03 Oct 2026 09:00:22 +0000</lastBuildDate>
    <item>
      <title>bdu:2022-00005</title>
      <link>https://cve.radiocsirt.org/vuln/bdu:2022-00005</link>
      <description>bdu:2022-00005</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/bdu:2022-00005</guid>
    </item>
    <item>
      <title>EUVD-2026-53934</title>
      <link>https://cve.radiocsirt.org/vuln/euvd-2026-53934</link>
      <description>EUVD-2026-53934</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/euvd-2026-53934</guid>
    </item>
    <item>
      <title>fkie_cve-2019-10752</title>
      <link>https://cve.radiocsirt.org/vuln/fkie_cve-2019-10752</link>
      <description>&lt;p&gt;Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;Sequelize, all versions prior to version 4.44.3 and 5.15.1, is vulnerable to SQL Injection due to sequelize.json() helper function not escaping values properly when formatting sub paths for JSON queries for MySQL, MariaDB and SQLite.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/fkie_cve-2019-10752</guid>
    </item>
    <item>
      <title>GHSA-m9jw-237r-gvfv — SQL Injection in sequelize</title>
      <link>https://cve.radiocsirt.org/vuln/ghsa-m9jw-237r-gvfv</link>
      <description>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sequelize&lt;/p&gt;
&lt;p&gt;Affected versions of `sequelize` are vulnerable to SQL Injection. The function `sequelize.json()` incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query.  Exploitation example:&lt;/p&gt;
&lt;p&gt;```js
return User.findAll({
  where: this.sequelize.json(&amp;#34;data.id&amp;#39;)) AS DECIMAL) = 1 DELETE YOLO INJECTIONS; -- &amp;#34;, 1)
});
```&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;If you are using `sequelize` 5.x, upgrade to version 5.15.1 or later.
If you are using `sequelize` 4.x, upgrade to version 4.44.3 or later.&lt;/p&gt;</description>
      <content:encoded>&lt;p&gt;&lt;strong&gt;Affected:&lt;/strong&gt; npm: sequelize&lt;/p&gt;
&lt;p&gt;Affected versions of `sequelize` are vulnerable to SQL Injection. The function `sequelize.json()` incorrectly formatted sub paths for JSON queries, which allows attackers to inject SQL statements and execute arbitrary SQL queries if user input is passed to the query.  Exploitation example:&lt;/p&gt;
&lt;p&gt;```js
return User.findAll({
  where: this.sequelize.json(&amp;#34;data.id&amp;#39;)) AS DECIMAL) = 1 DELETE YOLO INJECTIONS; -- &amp;#34;, 1)
});
```&lt;/p&gt;
&lt;p&gt;## Recommendation&lt;/p&gt;
&lt;p&gt;If you are using `sequelize` 5.x, upgrade to version 5.15.1 or later.
If you are using `sequelize` 4.x, upgrade to version 4.44.3 or later.&lt;/p&gt;</content:encoded>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/ghsa-m9jw-237r-gvfv</guid>
    </item>
    <item>
      <title>gsd-2019-10752</title>
      <link>https://cve.radiocsirt.org/vuln/gsd-2019-10752</link>
      <description>gsd-2019-10752</description>
      <guid isPermaLink="false">https://cve.radiocsirt.org/vuln/gsd-2019-10752</guid>
    </item>
  </channel>
</rss>
