Weaknesses of type CWE-74
4,740 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-9581MEDIUMComfast CF-N1 webmgnt multi_pppoe command injectionEPSS 5.3%CVE-2025-9582MEDIUMComfast CF-N1 webmgnt ntp_timezone command injectionEPSS 5.3%CVE-2025-7836MEDIUMD-Link DIR-816L Environment Variable cgibin lxmldbc_system command injectionEPSS 5.2%CVE-2020-11002HIGHRemote Code Execution (RCE) vulnerability in dropwizard-validationEPSS 5.2%CVE-2025-1947MEDIUMhzmanyun Education and Training System UploadImageController.java scorm command injectionEPSS 5.1%CVE-2025-1946MEDIUMhzmanyun Education and Training System exportPDF command injectionEPSS 5.1%CVE-2024-10919MEDIUMdidi Super-Jacoco triggerUnitCover os command injectionEPSS 5.1%CVE-2026-4205MEDIUMD-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injectionEPSS 5.1%CVE-2026-4206MEDIUMD-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injectionEPSS 5.1%CVE-2025-15257MEDIUMEdimax BR-6208AC Web-based Configuration formRoute command injectionEPSS 5.1%CVE-2025-9585MEDIUMComfast CF-N1 webmgnt wifilith_delete_pic_file command injectionEPSS 5.1%CVE-2025-9583MEDIUMComfast CF-N1 webmgnt ping_config command injectionEPSS 5.1%CVE-2022-25167—Apache Flume vulnerable to a JNDI RCE in JMSSourceEPSS 5.1%CVE-2025-12916MEDIUMSangfor Operation and Maintenance Security Management System Frontend portal_login command injectionEPSS 5.1%CVE-2026-10060MEDIUMTRENDnet TEW-432BRP formSetRoute command injectionEPSS 5.0%CVE-2026-10061MEDIUMTRENDnet TEW-432BRP formWPS command injectionEPSS 5.0%CVE-2021-43837HIGHTemplate injection in vault-cliEPSS 5.0%CVE-2025-7932MEDIUMD-Link DIR‑817L ssdpcgi lxmldbc_system command injectionEPSS 5.0%CVE-2026-8345MEDIUMD-Link DIR-816 singlePortForward sub_445E7C command injectionEPSS 5.0%CVE-2026-8346MEDIUMD-Link DIR-816 portForward command injectionEPSS 5.0%