Weaknesses of type CWE-74

4,788 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2025-10798MEDIUMcode-projects Hostel Management System index.php sql injectionEPSS 0.4%CVE-2025-8969MEDIUMitsourcecode Online Tour and Travel Management System approve_user.php sql injectionEPSS 0.4%CVE-2025-10833MEDIUM1000projects Bookstore Management System login.php sql injectionEPSS 0.4%CVE-2025-9601MEDIUMitsourcecode Apartment Management System employee_salary_setup.php sql injectionEPSS 0.4%CVE-2025-10799MEDIUMcode-projects Hostel Management System index.php sql injectionEPSS 0.4%CVE-2025-10459MEDIUMPHPGurukul Beauty Parlour Management System all-appointment.php sql injectionEPSS 0.4%CVE-2025-8973MEDIUMSourceCodester Cashier Queuing System Actions.php sql injectionEPSS 0.4%CVE-2025-10829MEDIUMCampcodes Computer Sales and Inventory System sup_edit1.php sql injectionEPSS 0.4%CVE-2025-10796MEDIUMcode-projects Hostel Management System login.php sql injectionEPSS 0.4%CVE-2025-9009MEDIUMitsourcecode Online Tour and Travel Management System email_setup.php sql injectionEPSS 0.4%CVE-2025-8990MEDIUMcode-projects Online Medicine Guide browsemdcn.php sql injectionEPSS 0.4%CVE-2025-10670MEDIUMitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile.php sql injectionEPSS 0.4%CVE-2025-10783MEDIUMCampcodes Online Learning Management System add_subject.php sql injectionEPSS 0.4%CVE-2025-9597MEDIUMitsourcecode Apartment Management System rented_all_info.php sql injectionEPSS 0.4%CVE-2025-25477HIGHA host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be EPSS 0.4%CVE-2025-11479MEDIUMSourceCodester Wedding Reservation Management System function.php insertReservation sql injectionEPSS 0.4%CVE-2025-10112MEDIUMitsourcecode Student Information Management System index.php sql injectionEPSS 0.4%CVE-2025-9047MEDIUMprojectworlds Visitor Management System visitor_out.php sql injectionEPSS 0.4%CVE-2025-8982MEDIUMitsourcecode Online Tour and Travel Management System currency.php sql injectionEPSS 0.4%CVE-2025-10111MEDIUMitsourcecode Student Information Management System index.php sql injectionEPSS 0.4%