Fallos del tipo CWE-89

11.906 resultados

Injeção de SQL

Ocorre quando dados fornecidos por um usuário são incorporados diretamente em comandos SQL sem validação ou sanitização, permitindo que um atacante modifique a lógica da consulta. O risco é grave: exposição de dados sensíveis, modificação ou deleção de registros, e até comprometimento do servidor de banco de dados.

Ejemplo

Um formulário de login que constrói a consulta como `SELECT * FROM users WHERE login = '` + entrada_do_usuario + `'` permite que alguém digite `admin' --` e contorne a verificação de senha, ou `' OR '1'='1` para listar todos os usuários.

Cómo mitigar

Use prepared statements ou stored procedures com parâmetros vinculados (nunca concatenação de strings). Se necessário filtrar, aplique whitelist rigorosa e escape adequado para o banco de dados específico. Implemente validação de entrada e princípio do menor privilégio na conta do banco.

CVE-2025-61023HIGHAn issue in the st_compare component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftedEPSS 0.5%CVE-2025-25520CRITICALSeacms <13.3 is vulnerable to SQL Injection in admin_pay.php.EPSS 0.5%CVE-2025-61018HIGHAn issue in the sqlo_place_dt_set component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via EPSS 0.5%CVE-2024-45755HIGHAn issue was discovered in Centreon centreon-dsm-server 24.10.x before 24.10.0, 24.04.x before 24.04.3, 23.10.x before 23.10.1, 23.04.x befoEPSS 0.5%CVE-2025-61028HIGHAn issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via craftEPSS 0.5%CVE-2024-45756HIGHAn issue was discovered in Centreon centreon-open-tickets 24.10.x before 24.10.0, 24.04.x before 24.04.2, 23.10.x before 23.10.1, 23.04.x beEPSS 0.5%CVE-2024-5357MEDIUMPHPGurukul Zoo Management System forgot-password.php sql injectionEPSS 0.5%CVE-2024-8624CRITICALMDTF – Meta Data and Taxonomies Filter <= 1.3.3.3 - Authenticated (Contributor+) SQL InjectionEPSS 0.5%CVE-2025-25521CRITICALSeacms <=13.3 is vulnerable to SQL Injection in admin_type_news.php.EPSS 0.5%CVE-2024-12832HIGHArista NG Firewall ReportEntry SQL Injection Arbitrary File Read and Write VulnerabilityEPSS 0.5%CVE-2025-25517CRITICALSeacms <=13.3 is vulnerable to SQL Injection in admin_reslib.php.EPSS 0.5%CVE-2025-61020HIGHAn issue in the sqlo_strip_in_join component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) viaEPSS 0.5%CVE-2026-12045CRITICALpgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remote code executionEPSS 0.5%CVE-2024-53354MEDIUMMultiple SQL injection vulnerabilities in EasyVirt DCScope <= 8.6.0 and CO2Scope <= 1.3.0 allows remote authenticated attackers to execute aEPSS 0.5%CVE-2025-2677MEDIUMPHPGurukul Bank Locker Management System changeidproof.php sql injectionEPSS 0.5%CVE-2024-33872CRITICALKeyfactor Command 10.5.x before 10.5.1 and 11.5.x before 11.5.1 allows SQL Injection which could result in code execution and escalation of EPSS 0.5%CVE-2024-37699CRITICALAn issue in DataLife Engine v.17.1 and before is vulnerable to SQL Injection in dboption.EPSS 0.5%CVE-2025-2063MEDIUMprojectworlds Life Insurance Management System deleteNominee.php sql injectionEPSS 0.5%CVE-2025-2642MEDIUMPHPGurukul Art Gallery Management System edit-art-product-detail.php sql injectionEPSS 0.5%CVE-2025-2663MEDIUMPHPGurukul Bank Locker Management System search-locker-details.php sql injectionEPSS 0.5%