CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

SQL injection vulnerabilities

SQL injection143 advisories40 exploitedlatest 2026-08-25

SQL injection lets attacker input rewrite database queries — dumping tables, bypassing logins, or writing files. Decades old and still shipping, SQLi in internet-facing products (file-transfer appliances in particular) has driven some of the largest mass-exploitation campaigns on record.

Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged sql injection, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.

Latest sql injection advisories

Other vulnerability classes

Remote code execution (2023)Privilege escalation (1548)Authentication bypass (1066)Denial of service (2105)Information disclosure (1543)Memory corruption (1308)Path traversal (235)Code injection (343)Cross-site scripting (315)Unsafe deserialization (83)Server-side request forgery (109)
New sql injection advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.