Fallos del tipo CWE-89

12.954 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2024-30867CRITICALnetentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_virtual_site_info.php.EPSS 0.7%CVE-2026-32767CRITICALSiYuan: Authorization Bypass Allows Arbitrary SQL Execution via Search APIEPSS 0.7%CVE-2024-25523CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the file_id parameter at /filemanage/file_memo.aspx.EPSS 0.7%CVE-2024-25517CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the tbTable argument at /WebUtility/MF.aspx.EPSS 0.7%CVE-2023-50718MEDIUMNocoDB SQL Injection vulnerabilityEPSS 0.7%CVE-2023-42660HIGHMOVEit Transfer Machine Interface SQL InjectionEPSS 0.7%CVE-2024-30985CRITICALSQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execEPSS 0.7%CVE-2022-47432MEDIUMWordPress Shortcode IMDB Plugin <= 6.0.8 is vulnerable to SQL InjectionEPSS 0.7%CVE-2023-7023MEDIUMTongda OA 2017 delete.php sql injectionEPSS 0.7%CVE-2024-2554MEDIUMSourceCodester Employee Task Management System update-employee.php sql injectionEPSS 0.7%CVE-2026-26198CRITICALormar is vulnerable to SQL Injection through aggregate functions min() and max()EPSS 0.7%CVE-2023-7022MEDIUMTongda OA 2017 delete_all.php sql injectionEPSS 0.7%CVE-2024-25510CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /AddressBook/address_public_show.aEPSS 0.7%CVE-2024-0786HIGHConversios <= 7.0.7 - Authenticated (Subscriber+) SQL Injection via ee_syncProductCategoryEPSS 0.7%CVE-2023-7020MEDIUMTongda OA 2017 view.php sql injectionEPSS 0.7%CVE-2024-30980CRITICALSQL Injection vulnerability in phpgurukul Cyber Cafe Management System Using PHP & MySQL 1.0 allows attackers to run arbitrary SQL commands EPSS 0.7%CVE-2025-55674MEDIUMApache Superset: Improper SQL authorisation, parse not checking for specific engine functionsEPSS 0.7%CVE-2023-27610MEDIUMWordPress Transbank Webpay REST Plugin <= 1.6.6 is vulnerable to SQL InjectionEPSS 0.7%CVE-2026-25879CRITICALLangroid has Prompt to SQL Injection, Leading to RCEEPSS 0.7%CVE-2024-25508CRITICALRuvarOA v6.01 and v12.01 were discovered to contain a SQL injection vulnerability via the id parameter at /bulletin/bulletin_template_show.aEPSS 0.7%