CWE-89 · 17 346 записей
SQL-инъекция
Почему это происходит?
Текст запроса формируется конкатенацией с пользовательским вводом. СУБД не может определить, где заканчиваются данные и начинается команда.
Уязвимый и исправленный код
Показательный учебный пример. Выделенные строки показывают, где ошибка и где исправление.
Уязвимый код
const owner = req.query.owner;const rows = await db.query( "SELECT * FROM files WHERE owner = '" + owner + "'");Исправленный код
const owner = req.query.owner;const rows = await db.query( "SELECT * FROM files WHERE owner = $1", [owner]);Как предотвратить
- 01Для каждого запроса используйте параметризованные запросы или надёжную ORM.
- 02Предоставляйте учётной записи СУБД права только на необходимые таблицы.
- 03Ограничивайте динамические имена столбцов и полей сортировки списком разрешённых.
CVE этого класса
10 000 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
99Срочно | CVE-2023-34362Готовый эксплойт | In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL progress · moveit cloud · CWE-89 | Критическая9,8 | KEV | 99,9 % | 2 июн. 2023 г. |
99Срочно | CVE-2025-25257Готовый эксплойт | An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet Forfortinet · fortiweb · CWE-89 | Критическая9,8 | KEV | 99,8 % | 17 июл. 2025 г. |
99Срочно | CVE-2023-48788Готовый эксплойт | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.fortinet · forticlient enterprise management server · CWE-89 | Критическая9,8 | KEV | 98,4 % | 12 мар. 2024 г. |
97Срочно | CVE-2019-12989Готовый эксплойт | Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.citrix · netscaler sd-wan · CWE-89 | Критическая9,8 | KEV | 95,0 % | 16 июл. 2019 г. |
97Срочно | CVE-2026-21643Готовый эксплойт | An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may afortinet · forticlientems · CWE-89 | Критическая9,8 | KEV | 93,7 % | 6 февр. 2026 г. |
97Срочно | CVE-2024-6670Готовый эксплойт | WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerabilityprogress · whatsup gold · CWE-89 | Критическая9,8 | KEV | 93,0 % | 29 авг. 2024 г. |
96Срочно | CVE-2024-9465Готовый эксплойт | Expedition: SQL Injection Leads to Firewall Admin Credential Disclosurepaloaltonetworks · expedition · CWE-89 | Критическая9,2 | KEV | 99,6 % | 9 окт. 2024 г. |
96Срочно | CVE-2020-17463Готовый эксплойт | FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.thedaylightstudio · fuel cms · CWE-89 | Критическая9,8 | KEV | 89,7 % | 13 авг. 2020 г. |
96Срочно | CVE-2025-57819Готовый эксплойт | FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCEsangoma · freepbx · CWE-89 | Критическая10,0 | KEV | 85,5 % | 28 авг. 2025 г. |
95Срочно | CVE-2024-29824Готовый эксплойт | An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the samivanti · endpoint manager · CWE-89 | Высокая8,8 | KEV | 99,9 % | 31 мая 2024 г. |
95Срочно | CVE-2017-18362Готовый эксплойт | ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct acconnectwise · manageditsync · CWE-89 | Критическая9,8 | KEV | 86,8 % | 5 февр. 2019 г. |
94Срочно | CVE-2020-5722Готовый эксплойт | The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.grandstream · ucm6200 firmware · CWE-89 | Критическая9,8 | KEV | 84,4 % | 23 мар. 2020 г. |
93Срочно | CVE-2024-43468Готовый эксплойт | Microsoft Configuration Manager Remote Code Execution Vulnerabilitymicrosoft · configuration manager 2403 · CWE-89 | Критическая9,8 | KEV | 80,9 % | 8 окт. 2024 г. |
91Срочно | CVE-2021-42258Готовый эксплойт | BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in thbqe · billquick web suite · CWE-89 | Критическая9,8 | KEV | 74,4 % | 22 окт. 2021 г. |
91Срочно | CVE-2018-7841Готовый эксплойт | A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an ischneider-electric · u.motion builder · CWE-89 | Критическая9,8 | KEV | 72,7 % | 22 мая 2019 г. |
90Срочно | CVE-2019-7481Готовый эксплойт | Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.sonicwall · sma 100 firmware · CWE-89 | Высокая7,5 | KEV | 99,9 % | 17 дек. 2019 г. |
90Срочно | CVE-2016-2386Готовый эксплойт | SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands vsap · netweaver application server java · CWE-89 | Критическая9,8 | KEV | 71,5 % | 16 февр. 2016 г. |
90Срочно | CVE-2021-44026Готовый эксплойт | Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.roundcube · webmail · CWE-89 | Критическая9,8 | KEV | 69,9 % | 19 нояб. 2021 г. |
82Срочно | CVE-2020-12271Готовый эксплойт | A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wildsophos · sfos · CWE-89 | Критическая9,8 | KEV | 42,4 % | 27 апр. 2020 г. |
81Срочно | CVE-2021-20016Готовый эксплойт | A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to accesssonicwall · sma 100 firmware · CWE-89 | Критическая9,8 | KEV | 40,0 % | 4 февр. 2021 г. |
78На этой неделе | CVE-2021-20028Готовый эксплойт | Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, ssonicwall · sma 210 firmware · CWE-89 | Критическая9,8 | KEV | 30,1 % | 4 авг. 2021 г. |
77На этой неделе | CVE-2025-25181Готовый эксплойт | A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL advantive · veracore · CWE-89 | Высокая7,5 | KEV | 57,3 % | 3 февр. 2025 г. |
77На этой неделе | CVE-2026-76461Готовый эксплойт | Cisco Secure Email Gateway SQL Injection Vulnerabilitycisco · asyncos · CWE-89 | Критическая9,8 | KEV | 28,3 % | 14 сент. 2026 г. |
76На этой неделе | CVE-2026-72898Готовый эксплойт | Metabase SQL injection via password reset endpointmetabase · metabase · CWE-89 | Критическая10,0 | KEV | 19,0 % | 10 авг. 2026 г. |
74На этой неделе | CVE-2026-9082Готовый эксплойт | Drupal core - Highly critical - SQL injection - SA-CORE-2026-004drupal · drupal · CWE-89 | Критическая9,8 | KEV | 15,7 % | 20 мая 2026 г. |
- CVE-2023-3436299Срочно
In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5 (14.1.5), and 2023.0.1 (15.0.1), a SQL
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %progress · moveit cloud2 июн. 2023 г.
- CVE-2025-2525799Срочно
An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerability [CWE-89] vulnerability in Fortinet For
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %fortinet · fortiweb17 июл. 2025 г.
- CVE-2023-4878899Срочно
A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %fortinet · forticlient enterprise management server12 мар. 2024 г.
- CVE-2019-1298997Срочно
Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 95 %citrix · netscaler sd-wan16 июл. 2019 г.
- CVE-2026-2164397Срочно
An improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.4 may a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 94 %fortinet · forticlientems6 февр. 2026 г.
- CVE-2024-667097Срочно
WhatsUp Gold HasErrors SQL Injection Authentication Bypass Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 93 %progress · whatsup gold29 авг. 2024 г.
- CVE-2024-946596Срочно
Expedition: SQL Injection Leads to Firewall Admin Credential Disclosure
КритическаяCVSS 9,2KEVГотовый эксплойтEPSS 100 %paloaltonetworks · expedition9 окт. 2024 г.
- CVE-2020-1746396Срочно
FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/items.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 90 %thedaylightstudio · fuel cms13 авг. 2020 г.
- CVE-2025-5781996Срочно
FreePBX Affected by Authentication Bypass Leading to SQL Injection and RCE
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 85 %sangoma · freepbx28 авг. 2025 г.
- CVE-2024-2982495Срочно
An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an unauthenticated attacker within the sam
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 100 %ivanti · endpoint manager31 мая 2024 г.
- CVE-2017-1836295Срочно
ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote commands that allow full direct ac
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 87 %connectwise · manageditsync5 февр. 2019 г.
- CVE-2020-572294Срочно
The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection via crafted HTTP request.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 84 %grandstream · ucm6200 firmware23 мар. 2020 г.
- CVE-2024-4346893Срочно
Microsoft Configuration Manager Remote Code Execution Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 81 %microsoft · configuration manager 24038 окт. 2024 г.
- CVE-2021-4225891Срочно
BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code execution, as exploited in th
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 74 %bqe · billquick web suite22 окт. 2021 г.
- CVE-2018-784191Срочно
A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unwanted code execution when an i
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 73 %schneider-electric · u.motion builder22 мая 2019 г.
- CVE-2019-748190Срочно
Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorized resources.
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 100 %sonicwall · sma 100 firmware17 дек. 2019 г.
- CVE-2016-238690Срочно
SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to execute arbitrary SQL commands v
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 72 %sap · netweaver application server java16 февр. 2016 г.
- CVE-2021-4402690Срочно
Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_params.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 70 %roundcube · webmail19 нояб. 2021 г.
- CVE-2020-1227182Срочно
A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall devices, as exploited in the wild
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 42 %sophos · sfos27 апр. 2020 г.
- CVE-2021-2001681Срочно
A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker to perform SQL query to access
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 40 %sonicwall · sma 100 firmware4 февр. 2021 г.
- CVE-2021-2002878На этой неделе
Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure Remote Access (SRA) products, s
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 30 %sonicwall · sma 210 firmware4 авг. 2021 г.
- CVE-2025-2518177На этой неделе
A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attackers to execute arbitrary SQL
ВысокаяCVSS 7,5KEVГотовый эксплойтEPSS 57 %advantive · veracore3 февр. 2025 г.
- CVE-2026-7646177На этой неделе
Cisco Secure Email Gateway SQL Injection Vulnerability
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 28 %cisco · asyncos14 сент. 2026 г.
- CVE-2026-7289876На этой неделе
Metabase SQL injection via password reset endpoint
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 19 %metabase · metabase10 авг. 2026 г.
- CVE-2026-908274На этой неделе
Drupal core - Highly critical - SQL injection - SA-CORE-2026-004
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 16 %drupal · drupal20 мая 2026 г.