CWE-89 관련 취약점
같은 약점 유형으로 분류된 취약점입니다. CWE 는 "무엇을 잘못했는가" 의 분류이고, 제품을 가리지 않고 같은 실수가 반복됩니다.
CWE-89 — 주요 취약점
악용이 확인된 것을 먼저 보여줍니다.
● 실제 악용이 확인됨CVE-2024-29824An unspecified SQL Injection vulnerability in Core server of Ivanti EPM 2022 SU5 and prior allows an…99.9%높음8.8● 랜섬웨어 캠페인에 사용됨CVE-2023-34362In Progress MOVEit Transfer before 2021.0.6 (13.0.6), 2021.1.4 (13.1.4), 2022.0.4 (14.0.4), 2022.1.5…99.9%심각9.8● 랜섬웨어 캠페인에 사용됨CVE-2019-7481Vulnerability in SonicWall SMA100 allow unauthenticated user to gain read-only access to unauthorize…99.9%높음7.5● 실제 악용이 확인됨CVE-2025-25257An improper neutralization of special elements used in an SQL command ('SQL Injection') vulnerabilit…99.8%심각9.8● 실제 악용이 확인됨CVE-2024-9465An SQL injection vulnerability in Palo Alto Networks Expedition allows an unauthenticated attacker t…99.6%심각9.2● 랜섬웨어 캠페인에 사용됨CVE-2023-48788A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet F…98.4%심각9.8● 실제 악용이 확인됨CVE-2019-12989Citrix SD-WAN 10.2.x before 10.2.3 and NetScaler SD-WAN 10.0.x before 10.0.8 allow SQL Injection.95.0%심각9.8● 실제 악용이 확인됨CVE-2026-21643An improper neutralization of special elements used in an sql command ('sql injection') vulnerabilit…93.9%심각9.8
전체 목록
120건
CVE-2024-6670랜섬웨어 악용In WhatsUp Gold versions released before 2024.0.0, a SQL Injection vulnerability allows an unauthenticated att…93.0%심각9.8
CVE-2020-17463악용 확인FUEL CMS 1.4.7 allows SQL Injection via the col parameter to /pages/items, /permissions/items, or /navigation/…89.7%심각9.8
CVE-2017-18362랜섬웨어 악용ConnectWise ManagedITSync integration through 2017 for Kaseya VSA is vulnerable to unauthenticated remote comm…86.8%심각9.8
CVE-2025-57819악용 확인FreePBX is an open-source web-based graphical user interface. FreePBX 15, 16, and 17 endpoints are vulnerable …85.5%심각10.0
CVE-2020-5722악용 확인The HTTP interface of the Grandstream UCM6200 series is vulnerable to an unauthenticated remote SQL injection …84.4%심각9.8
CVE-2021-42258랜섬웨어 악용BQE BillQuick Web Suite 2018 through 2021 before 22.0.9.1 allows SQL injection for unauthenticated remote code…74.4%심각9.8
CVE-2018-7841악용 확인A SQL Injection (CWE-89) vulnerability exists in U.motion Builder software version 1.3.4 which could cause unw…72.7%심각9.8
CVE-2016-2386악용 확인SQL injection vulnerability in the UDDI server in SAP NetWeaver J2EE Engine 7.40 allows remote attackers to ex…71.5%심각9.8
CVE-2021-44026악용 확인Roundcube before 1.3.17 and 1.4.x before 1.4.12 is prone to a potential SQL injection via search or search_par…69.9%심각9.8
CVE-2025-25181악용 확인A SQL injection vulnerability in timeoutWarning.asp in Advantive VeraCore through 2025.1.0 allows remote attac…55.5%높음7.5
CVE-2024-9379악용 확인SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attack…43.8%높음7.2
CVE-2020-12271랜섬웨어 악용A SQL injection issue was found in SFOS 17.0, 17.1, 17.5, and 18.0 before 2020-04-25 on Sophos XG Firewall dev…42.4%심각9.8
CVE-2021-20016랜섬웨어 악용A SQL-Injection vulnerability in the SonicWall SSLVPN SMA100 product allows a remote unauthenticated attacker …40.0%심각9.8
CVE-2021-20028랜섬웨어 악용Improper neutralization of a SQL Command leading to SQL Injection vulnerability impacting end-of-life Secure R…30.1%심각9.8
CVE-2026-76461악용 확인A vulnerability in the email parsing of Cisco AsyncOS Software for Cisco Secure Email Gateway could allow an u…28.3%심각9.8
CVE-2026-72898악용 확인Metabase allows a remote, unauthenticated attacker to inject arbitrary SQL via the '/reset_password' database …19.0%심각10.0
CVE-2026-9586악용 확인An unauthenticated SQL injection vulnerability exists in Sangoma Switchvox SMB Edition 8.3 (104997). The /pa e…19.0%심각9.3
CVE-2026-9082악용 확인Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Drupal D…15.7%심각9.8
CVE-2026-60137악용 확인WordPress 6.8.x before 6.8.6, 6.9.x before 6.9.5, and 7.0.x before 7.0.2 does not properly sanitise the author…5.9%보통5.9
CVE-2026-42208악용 확인LiteLLM is a proxy server (AI Gateway) to call LLM APIs in OpenAI (or native) format. From version 1.81.16 to …5.8%심각9.3
CVE-2020-29574랜섬웨어 악용An SQL injection vulnerability in the WebAdmin of Cyberoam OS through 2020-12-04 allows unauthenticated attack…4.7%심각9.8
CVE-2023-46748악용 확인An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an aut…4.5%높음8.8
CVE-2026-86677ZohoCorp ManageEngine Applications Manager versions 182000 and below allowed a low-privileged user to run unau…2.0%높음8.8
CVE-2026-78482Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…1.9%높음7.8
CVE-2026-18912ManageEngine DataSecurity Plus versions before 6310 are vulnerable to an authenticated SQL injection vulnerabi…1.5%높음7.7
CVE-2026-54647CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/settings.index.inc.php directly conc…1.4%높음7.2
CVE-2026-54646CubeCart is an ecommerce software solution. Prior to 6.7.5, admin/sources/maintenance.index.inc.php places adm…1.4%높음7.2
CVE-2026-44642Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, check_upgrade_ac…1.3%높음8.1
CVE-2026-75746ColdFusion is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injectio…1.1%심각9.1
CVE-2026-67401A vulnerability in cPanel allows a mail-enabled account to achieve remote code execution as root through SQLi …1.0%심각9.9
CVE-2026-53629GLPI is a free asset and IT management software package. From 9.4.0 until 10.0.26 and 11.0.8, an attacker with…1.0%높음7.1
CVE-2026-82009Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Comm…1.0%심각9.1
CVE-2026-14913ZohoCorp ManageEngine OpManager and Firewall Analyzer versions 12.8.669 and below were vulnerable to an SQL In…1.0%높음8.8
CVE-2026-69636Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office Share…1.0%보통6.5
CVE-2026-42324Piwigo is a full featured open source photo gallery application for the web. Prior to 16.4.0, admin/element_se…0.9%높음7.2
CVE-2026-69716Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Office Share…0.9%높음8.8
CVE-2026-61781pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, create_par…0.8%심각9.9
CVE-2026-79947Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to 5.36.00.00,…0.8%보통5.5
CVE-2026-61820pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, inherit_te…0.7%높음8.5
CVE-2026-61819pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, when pg_jo…0.7%높음8.5
CVE-2026-61817pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, run_mainte…0.7%높음8.5
CVE-2026-66819Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an a…0.7%높음8.8
CVE-2026-62895Permissive cross-domain policy with untrusted domains in Azure Arc allows an unauthorized attacker to elevate …0.7%높음8.8
CVE-2026-54354MapServer is a system for developing web-based GIS applications. Prior to 8.6.4, MapServer's PostGIS runtime f…0.7%높음8.2
CVE-2026-84082IBM Guardium Data Protection 12.2 could allow a remote attacker to execute arbitrary SQL commands due to impro…0.7%심각9.8
CVE-2026-67370Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an a…0.7%높음8.8
CVE-2026-61667DIRAC is an interware, meaning a software framework for distributed computing. Prior to versions 8.0.79, 9.0.2…0.7%심각9.9
CVE-2026-65980Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data t…0.7%높음7.9
CVE-2026-55416Pimcore is an Open Source Data & Experience Management Platform. Prior to 11.5.19, 12.3.10, and 2026.1.6, an a…0.6%높음8.8
CVE-2026-84064IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to execute arbitrary SQL command…0.6%심각9.9
CVE-2026-8462SQL injection in ClickHouse-backed meter definitions in OpenMeter OpenMeter before v1.0.0-beta.228 on all plat…0.6%높음8.9
CVE-2026-65128NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause SQL injectio…0.6%높음8.8
CVE-2026-9855The Custom Field Template plugin for WordPress is vulnerable to generic SQL Injection via the 'post_ID' parame…0.6%보통6.5
CVE-2026-77051Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Apache S…0.6%심각9.8
CVE-2026-82232Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Apache S…0.6%심각9.8
CVE-2026-86460Cypher injection vulnerability in the Neo4j persistence layer when processing some FIQL search conditions. Thi…0.6%심각9.8
CVE-2026-80441IBM Guardium Data Protection 12.2 is vulnerable to an unauthenticated second-order SQL injection vulnerability…0.6%심각9.8
CVE-2026-82011Adobe Campaign Classic (ACC) is affected by an Improper Neutralization of Special Elements used in an SQL Comm…0.6%심각9.1
CVE-2026-85652The Photo Gallery by 10Web – Mobile-Friendly Image Gallery plugin for WordPress is vulnerable to time-based SQ…0.6%보통6.5
CVE-2026-75682Adobe Connect is affected by an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injec…0.5%심각9.9
CVE-2026-84239IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information …0.5%높음7.6
CVE-2026-66820Improper neutralization of special elements used in an sql command ('sql injection') in SQL Server allows an a…0.5%높음8.8
CVE-2026-61685ReactPress is a publishing system for React developers. Prior to version 3.7.0, ReactPress API list endpoints …0.5%높음7.5
CVE-2026-97882A weakness has been identified in mathurvishal CloudClassroom-PHP-Project up to 5dadec098bfbbf3300d60c3494db3f…0.5%보통5.5
CVE-2026-61818pg_partman is a PostgreSQL extension that manages partitioned tables by time or ID. Prior to 5.5.0, undo_parti…0.5%높음8.5
CVE-2026-6295The WP Optimizer plugin for WordPress is vulnerable to SQL Injection via the 's' parameter in all versions up …0.5%보통4.9
CVE-2025-63564SQL injection vulnerability in Moodle Socialwall plugin v.3.0 through v.3.3 allows an attacker to execute arbi…0.5%심각9.8
CVE-2026-78082Joomla Extension - joomshaper.com - Unauthenticated SQL Injection in Property Search and Map Filtering in SP P…0.5%심각9.3
CVE-2026-84993MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior t…0.5%보통6.5
CVE-2026-75961The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to generic SQL Injectio…0.5%보통4.9
CVE-2026-92366A vulnerability was determined in code-projects Matrimonial System 1.0. This affects an unknown part of the fi…0.5%보통5.5
CVE-2026-93426SigNoz versions 0.87.0 before 0.142.0 fail to escape user-supplied telemetry field-key names in the v5 query_r…0.5%높음8.4
CVE-2026-18442The WCFM Marketplace – Multivendor Marketplace for WooCommerce plugin for WordPress is vulnerable to generic S…0.5%높음7.5
CVE-2026-18782Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Trex Dig…0.5%심각9.8
CVE-2026-79752CakePHP is a rapid development framework for PHP. Prior to 4.5.12, 4.6.5, 5.1.9, 5.2.14, and 5.3.7, FunctionsB…0.5%심각9.2
CVE-2026-54524Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.7.0, an authenticated user…0.5%높음7.1
CVE-2026-53556SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.9.0, the POST /…0.5%보통6.0
CVE-2015-20122Seeyon A6 collaborative office automation platform contains an unauthenticated SQL injection vulnerability in …0.5%높음8.7
CVE-2026-91848A vulnerability was identified in WuzhiCMS up to 4.1.0. Affected by this issue is the function article::getDat…0.5%보통5.5
CVE-2026-54596ITFlow provides an IT documentation, ticketing and accounting system for small managed service providers. Prio…0.5%높음8.1
CVE-2026-82583NextGen Connect (Mirth Connect) versions 4.7.1 and earlier allow an authenticated user to execute arbitrary SQ…0.4%높음7.2
CVE-2023-54400Fumasoft Fumeng Cloud contains a SQL injection vulnerability in the AjaxMethod.ashx endpoint that allows unaut…0.5%심각9.3
CVE-2026-88402A SQL injection vulnerability in the checkSQL function of nocobase v2.1.21 allows attackers to access sesntive…0.5%심각9.8
CVE-2026-67100HCL BigFix Service Management is affected by SQL Injection flaw and a Cross-Tenant Data Exposure flaw vulnerab…0.5%심각9.8
CVE-2026-85705The Location Manager plugin for WordPress is vulnerable to generic SQL Injection via 'latitude' and 'longitude…0.5%높음7.5
CVE-2026-76570Joomla Extension - joomcode.com - Unauthenticated SQL injection in read and write queries in JCTables 1.21.1 -…0.5%심각10.0
CVE-2026-84105IBM Guardium Data Protection 12.2 could allow a remote authenticated attacker to obtain sensitive information …0.5%높음7.7
CVE-2026-73698FileRun before 2026.3.0 contains a SQL injection vulnerability that allows delegated or simple administrators …0.4%높음8.6
CVE-2026-78472The Ni WooCommerce Sales Report WordPress plugin before 4.2.0 does not sanitise and escape a parameter before …0.4%높음8.6
CVE-2026-90526A security vulnerability has been detected in SourceCodester School Registration and Fee System 1.0. This impa…0.4%보통5.5
CVE-2026-82028Magistrala before 1.0.0 contains a SQL injection vulnerability in the timescale-reader and postgres-reader HTT…0.4%높음8.7
CVE-2026-18658IBM Operational Decision Manager 9.6.0.0, 9.5.0.0, 8.11.1.0, 8.11.0.1, 8.12.0.1, 9.5.0.1, and 9.0.0.1 is vulne…0.4%심각9.8
CVE-2026-87771The Product Question and Answer WordPress plugin through 1.1.0 does not sanitize and escape parameters before …0.4%높음8.6
CVE-2026-87775The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before us…0.4%높음8.6
CVE-2026-87770The Price Drop Alert for Woo Commerce WordPress plugin through 1.1 does not sanitize and escape parameters bef…0.4%높음8.6
CVE-2026-87767The wp shortcut link and advertisement baner WordPress plugin through 1.2.0 does not sanitize and escape a par…0.4%높음8.6
CVE-2026-87774The Tz Weekly Radio Schedule WordPress plugin through 1.8.1 does not sanitize and escape a parameter before us…0.4%높음8.6
CVE-2026-88926The VikRentItems Flexible Rental Management System WordPress plugin before 1.2.4 does not sanitise and escape …0.4%높음8.6
CVE-2026-4036An improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Shari…0.4%보통6.5
CVE-2026-75959The GoPay for WooCommerce plugin for WordPress is vulnerable to generic SQL Injection via the 'log_table_filte…0.4%보통4.9
CVE-2026-77874IBM Enterprise Build of Quarkus 3.27.1 through 3.27.5.SP1, and 3.33.1 through 3.33.3.SP1 is vulnerable to SQL …0.4%높음8.6
CVE-2026-93972A security vulnerability has been detected in SourceCodester Online Reviewer Management System 1.0. The affect…0.4%보통5.5
CVE-2026-94143A vulnerability was detected in drogonframework drogon up to 1.9.13. Affected by this issue is the function Ma…0.4%보통5.5
CVE-2026-94144A flaw has been found in drogonframework drogon up to 1.9.13. This affects the function makeCriteria in the li…0.4%보통5.5
CVE-2026-92406A vulnerability was detected in SourceCodester Inventory and Monitoring System 1.0. The impacted element is an…0.4%보통5.5
CVE-2026-92405A security vulnerability has been detected in SourceCodester Inventory and Monitoring System 1.0. The affected…0.4%보통5.5
CVE-2026-90701A vulnerability was detected in subhajitkhan online-clinic-management-system up to e9ee77a8827a1446220fa07ee69…0.4%보통5.5
CVE-2026-90516A vulnerability was found in SourceCodester School Registration and Fee System 1.0. The affected element is an…0.4%보통5.5
CVE-2026-92926A vulnerability has been found in code-projects Matrimonial System 1.0. This vulnerability affects the functio…0.4%보통5.5
CVE-2026-93979A security flaw has been discovered in code-projects Internship Management System 1.0. This affects an unknown…0.4%보통5.5
CVE-2026-93978A vulnerability was identified in code-projects Internship Management System 1.0. Affected by this issue is so…0.4%보통5.5
이 원장은 전체 CVE 가 아닙니다. NVD 에는 30만 건이 넘습니다. 여기 있는 것은 ① 악용이 확인된 것 ② 최근 공개된 것 ③ 국산 SW 관련 ④ KISA 권고에 등장한 것입니다. 무엇을 담았는지 밝히지 않으면 "없다" 를 "안전하다" 로 읽게 됩니다.