Weaknesses of type CWE-74

4,830 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2026-4573MEDIUMSourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injectionEPSS 0.3%CVE-2026-7392MEDIUMSourceCodester Pharmacy Sales and Inventory System ajax.php delete_supplier sql injectionEPSS 0.3%CVE-2026-7731MEDIUMcode-projects BloodBank Managing System get_state.php sql injectionEPSS 0.3%CVE-2026-7699MEDIUMDromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injectionEPSS 0.3%CVE-2026-4230MEDIUMvanna-ai vanna Endpoint __init__.py update_sql sql injectionEPSS 0.3%CVE-2026-5560MEDIUMPHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionEPSS 0.3%CVE-2026-4574MEDIUMSourceCodester Simple E-learning System User Profile Update sql injectionEPSS 0.3%CVE-2026-7410MEDIUMSourceCodester Pizzafy Ecommerce System ajax.php add_to_cart sql injectionEPSS 0.3%CVE-2026-7591MEDIUMTimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injectionEPSS 0.3%CVE-2026-94492MEDIUMYonyou U8cloud OpenAPI so.saleorder.sendaudit sql injectionEPSS 0.3%CVE-2026-7744MEDIUMCodeAstro Online Classroom addnewstudent sql injectionEPSS 0.3%CVE-2026-86172MEDIUMDefaultFuction CRM delete.php sql injectionEPSS 0.3%CVE-2026-84061MEDIUMzhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injectionEPSS 0.3%CVE-2026-7447MEDIUMSourceCodester Pet Grooming Management Software update_customer.php sql injectionEPSS 0.3%CVE-2026-7391MEDIUMSourceCodester Pharmacy Sales and Inventory System ajax.php save_supplier sql injectionEPSS 0.3%CVE-2026-4836MEDIUMcode-projects Accounting System delete.php sql injectionEPSS 0.3%CVE-2026-4876MEDIUMitsourcecode Free Hotel Reservation System index.php sql injectionEPSS 0.3%CVE-2026-6190MEDIUMitsourcecode Construction Management System employees.php sql injectionEPSS 0.3%CVE-2026-8231MEDIUMCodeAstro Online Catering Ordering System deleteorder.php sql injectionEPSS 0.3%CVE-2026-6005MEDIUMcode-projects Patient Record Management System hematology_print.php sql injectionEPSS 0.3%