Weaknesses of type CWE-74

4,798 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2026-3955MEDIUMelecV2P jsfile Endpoint wbjs.js runJSFile code injectionEPSS 0.4%CVE-2026-6599MEDIUMlangflow-ai langflow Model Context Protocol Configuration API mcp_projects.py install_mcp_config injectionEPSS 0.4%CVE-2026-100314MEDIUMmathurvishal CloudClassroom-PHP-Project updatedetailsfromstudent.php sql injectionEPSS 0.4%CVE-2026-7700MEDIUMlangflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injectionEPSS 0.4%CVE-2026-6125MEDIUMDromara warm-flow Workflow Definition save-json SpelHelper.parseExpression code injectionEPSS 0.4%CVE-2026-5011MEDIUMelecV2 elecV2P JSON webhook runJSFile code injectionEPSS 0.4%CVE-2026-4506MEDIUMMindinventory MindSQL mindsql_core.py ask_db code injectionEPSS 0.4%CVE-2026-0733MEDIUMPHPGurukul Online Course Registration System manage-students.php sql injectionEPSS 0.4%CVE-2026-3992MEDIUMCodeGenieApp serverless-express Users Endpoint dynamodb.ts injectionEPSS 0.4%CVE-2026-3682MEDIUMwelovemedia FFmate ffmpeg.go Execute argument injectionEPSS 0.4%CVE-2026-5556MEDIUMbadlogic pi-mono loader.ts discoverAndLoadExtensions code injectionEPSS 0.4%CVE-2026-100315MEDIUMmathurvishal CloudClassroom-PHP-Project mydetailsfaculty.php sql injectionEPSS 0.4%CVE-2026-7508MEDIUMBootstrap CMS Page Creation show.blade.php code injectionEPSS 0.4%CVE-2026-95806HIGHMISP: PHP phar stream wrapper enables deserialization and code execution via caller-influenced filesystem pathsEPSS 0.4%CVE-2025-15496MEDIUMguchengwuyue yshopmall jobs getPage sql injectionEPSS 0.4%CVE-2017-20197MEDIUMpropanetank Roommate-Bill-Tracking login.php sql injectionEPSS 0.4%CVE-2026-1154MEDIUMSourceCodester E-Learning System Lesson index.php cross site scriptingEPSS 0.4%CVE-2025-7886MEDIUMpmTicket Project-Management-Software class.database.php getUserLanguage sql injectionEPSS 0.4%CVE-2025-8930MEDIUMcode-projects Medical Store Management System Update Company UpdateCompany.java sql injectionEPSS 0.4%CVE-2025-8929MEDIUMcode-projects Medical Store Management System MainPanel.java sql injectionEPSS 0.4%