Weaknesses of type CWE-74

4,786 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2025-3208MEDIUMcode-projects Patient Record Management System xray_print.php sql injectionEPSS 0.5%CVE-2025-3210MEDIUMcode-projects Patient Record Management System birthing_pending.php sql injectionEPSS 0.5%CVE-2025-3018MEDIUMSourceCodester Online Eyewear Shop Users.php sql injectionEPSS 0.5%CVE-2025-3207MEDIUMcode-projects Patient Record Management System birthing_form.php sql injectionEPSS 0.5%CVE-2025-5857MEDIUMcode-projects Patient Record Management System urinalysis_record.php sql injectionEPSS 0.5%CVE-2025-5660MEDIUMPHPGurukul Complaint Management System register-complaint.php sql injectionEPSS 0.5%CVE-2025-6607MEDIUMSourceCodester Best Salon Management System stock.php sql injectionEPSS 0.5%CVE-2025-6608MEDIUMSourceCodester Best Salon Management System edit-services.php sql injectionEPSS 0.5%CVE-2025-6410MEDIUMPHPGurukul Art Gallery Management System edit-art-medium-detail.php sql injectionEPSS 0.5%CVE-2025-6570MEDIUMPHPGurukul Hospital Management System search.php sql injectionEPSS 0.5%CVE-2025-6609MEDIUMSourceCodester Best Salon Management System bwdates-reports-details.php sql injectionEPSS 0.5%CVE-2025-6605MEDIUMSourceCodester Best Salon Management System edit-staff.php sql injectionEPSS 0.5%CVE-2025-15002MEDIUMSeaCMS mysqli.class.php sql injectionEPSS 0.5%CVE-2025-5652MEDIUMPHPGurukul Complaint Management System between-date-complaintreport.php sql injectionEPSS 0.5%CVE-2026-12717CRITICALRemote Code Execution in BigQuery Data Transfer Service via JDBC Connection String InjectionEPSS 0.5%CVE-2025-6581MEDIUMSourceCodester Best Salon Management System add-customer.php sql injectionEPSS 0.5%CVE-2025-6606MEDIUMSourceCodester Best Salon Management System add-services.php sql injectionEPSS 0.5%CVE-2025-6412MEDIUMPHPGurukul Art Gallery Management System changeimage.php sql injectionEPSS 0.5%CVE-2025-6411MEDIUMPHPGurukul Art Gallery Management System changepropic.php sql injectionEPSS 0.5%CVE-2025-6417MEDIUMPHPGurukul Art Gallery Management System add-artist.php sql injectionEPSS 0.5%