CVE-2026-3494
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, Q
CVSS
4.3
Medium
EPSS
0.3%
p20
KEV
—
Exploit Today
6
0-100
Published: Mar 3, 2026 · Last modified: Jul 14, 2026 · CWE-778
0.3%EPSS · 30 days0.3%
2026-07-022026-07-29
In MariaDB server version through 11.8.5, when server audit plugin is enabled with server_audit_events variable configured with QUERY_DCL, QUERY_DDL, or QUERY_DML filtering, if an authenticated database user invokes a SQL statement prefixed with double-hyphen (—) or hash (#) style comments, the statement is not logged.
CVECVSSEPSSKEVRExploitTitleMod.
CVE-2026-417092.7 LOW—
———VMware ESX contains an insufficient logging vulnerability. A malicious administrator could exploit this issue to perform certain operations without them being logged.6hCVE-2026-92472.4 LOW12.5%
——4Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to administrators via a crafted export request.
This issue affects :
* Devolutions Server 2026.1.6.0 through 2026.1.16.0
* Devolutions Server 2025.3.20.0 and earlier7d