cwe-89
Safeguard articles tagged "cwe-89" — guides, analysis, and best practices for software supply chain and application security.
38 articles
CVE-2021-44026: Roundcube Webmail SQL Injection Vulnerability
CVE-2021-44026 affects Roundcube Roundcube Webmail and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-06-22.
CVE-2023-46748: F5 BIG-IP Configuration Utility SQL Injection Vulnerability
CVE-2023-46748 affects F5 BIG-IP Configuration Utility and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2023-10-31.
CVE-2023-48788: Fortinet FortiClient EMS SQL Injection Vulnerability
CVE-2023-48788 affects Fortinet FortiClient EMS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-03-25.
CVE-2024-6670: Progress WhatsUp Gold SQL Injection Vulnerability
CVE-2024-6670 affects Progress WhatsUp Gold and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-09-16.
CVE-2024-29824: Ivanti Endpoint Manager (EPM) SQL Injection Vulnerability
CVE-2024-29824 affects Ivanti Endpoint Manager (EPM) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-10-02.
CVE-2024-9379: Ivanti Cloud Services Appliance (CSA) SQL Injection Vulnerability
CVE-2024-9379 affects Ivanti Cloud Services Appliance (CSA) and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-10-09.
CVE-2024-9465: Palo Alto Networks Expedition SQL Injection Vulnerability
CVE-2024-9465 affects Palo Alto Networks Expedition and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2024-11-14.
CVE-2020-29574: CyberoamOS (CROS) SQL Injection Vulnerability
CVE-2020-29574 affects Sophos CyberoamOS and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-02-06.
CVE-2025-25181: Advantive VeraCore SQL Injection Vulnerability
CVE-2025-25181 affects Advantive VeraCore and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-03-10.
CVE-2025-25257: Fortinet FortiWeb SQL Injection Vulnerability
CVE-2025-25257 affects Fortinet FortiWeb and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-07-18.
CVE-2025-57819: Sangoma FreePBX Authentication Bypass Vulnerability
CVE-2025-57819 affects Sangoma FreePBX and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2025-08-29.
CVE-2024-43468: Microsoft Configuration Manager SQL Injection Vulnerability
CVE-2024-43468 affects Microsoft Configuration Manager and is listed in CISA's Known Exploited Vulnerabilities catalog, meaning exploitation has been observed in the wild. Added 2026-02-12.
Self-healing security runs on Safeguard.
Your first fix PR is minutes away.
No sales call required, even your agent can complete the purchase over MCP.