Weaknesses of type CWE-74

4,801 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2025-8230MEDIUMCampcodes Courier Management System manage_user.php sql injectionEPSS 0.4%CVE-2026-12355HIGHIBM MQ Resource Adapter IVT servlet is vulnerable to unauthenticated remote code executionEPSS 0.4%CVE-2025-8186MEDIUMCampcodes Courier Management System edit_branch.php sql injectionEPSS 0.4%CVE-2026-1176MEDIUMitsourcecode School Management System index.php sql injectionEPSS 0.4%CVE-2026-1688MEDIUMitsourcecode Directory Management System index.php sql injectionEPSS 0.4%CVE-2026-1595MEDIUMitsourcecode Society Management System edit_student_query.php sql injectionEPSS 0.4%CVE-2025-1192MEDIUMSourceCodester Multi Restaurant Table Reservation System select-menu.php sql injectionEPSS 0.4%CVE-2026-1160MEDIUMPHPGurukul Directory Management System Search index.php sql injectionEPSS 0.4%CVE-2025-15166MEDIUMitsourcecode Online Cake Ordering System updatesupplier.php sql injectionEPSS 0.4%CVE-2025-14989MEDIUMCampcodes Complete Online Beauty Parlor Management System search-invoices.php sql injectionEPSS 0.4%CVE-2025-14990MEDIUMCampcodes Complete Online Beauty Parlor Management System view-appointment.php sql injectionEPSS 0.4%CVE-2025-12607MEDIUMitsourcecode Online Loan Management System manage_payment.php sql injectionEPSS 0.4%CVE-2026-1546MEDIUMjishenghua jshERP com.jsh.erp.datasource.mappers.DepotItemMapperEx importItemExcel getBillItemByParam sql injectionEPSS 0.4%CVE-2025-15165MEDIUMitsourcecode Online Cake Ordering System updatecustomer.php sql injectionEPSS 0.4%CVE-2024-1619MEDIUMKaspersky has fixed a security issue in the Kaspersky Security 8.0 for Linux Mail Server. The issue was that an attacker could potentially fEPSS 0.4%CVE-2026-29777MEDIUMTraefik has a kubernetes gateway rule injection via unescaped backticks in HTTPRoute match valuesEPSS 0.4%CVE-2025-15167MEDIUMitsourcecode Online Cake Ordering System detailtransac.php sql injectionEPSS 0.4%CVE-2026-1552MEDIUMSEMCMS SEMCMS_Info.php sql injectionEPSS 0.4%CVE-2025-10012MEDIUMPortabilis i-Educar educar_historico_escolar_lst.php sql injectionEPSS 0.4%CVE-2025-10218MEDIUMlostvip-com ruoyi-go Background Management SysRoleDao.go SelectListPage sql injectionEPSS 0.4%