Weaknesses of type CWE-74

4,832 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2026-7678MEDIUMYunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injectionEPSS 0.3%CVE-2026-4597MEDIUM648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injectionEPSS 0.3%CVE-2026-90511MEDIUMGongShengyue OnlineBooks listSplit BooksServlet.java sql injectionEPSS 0.3%CVE-2026-84153MEDIUMXinhu Rainrock RockOA index.php toaddval sql injectionEPSS 0.3%CVE-2026-7716MEDIUMcode-projects Gym Management System In PHP/Windows NT index.php sql injectionEPSS 0.3%CVE-2026-6006MEDIUMcode-projects Patient Record Management System edit_hpatient.php sql injectionEPSS 0.3%CVE-2026-5606MEDIUMPHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionEPSS 0.3%CVE-2026-9449MEDIUMcode-projects Employee Management System changepassemp.php sql injectionEPSS 0.3%CVE-2026-86172MEDIUMDefaultFuction CRM delete.php sql injectionEPSS 0.3%CVE-2026-7447MEDIUMSourceCodester Pet Grooming Management Software update_customer.php sql injectionEPSS 0.3%CVE-2026-84061MEDIUMzhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injectionEPSS 0.3%CVE-2026-7267MEDIUMSourceCodester Pizzafy Ecommerce System view_prod.php sql injectionEPSS 0.3%CVE-2026-4970MEDIUMcode-projects Social Networking Site Endpoint delete_photos.php sql injectionEPSS 0.3%CVE-2026-5578MEDIUMCodeAstro Online Classroom Parameter addassessment.php sql injectionEPSS 0.3%CVE-2026-6190MEDIUMitsourcecode Construction Management System employees.php sql injectionEPSS 0.3%CVE-2026-7591MEDIUMTimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injectionEPSS 0.3%CVE-2026-4574MEDIUMSourceCodester Simple E-learning System User Profile Update sql injectionEPSS 0.3%CVE-2026-5552MEDIUMPHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionEPSS 0.3%CVE-2026-5560MEDIUMPHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionEPSS 0.3%CVE-2026-4230MEDIUMvanna-ai vanna Endpoint __init__.py update_sql sql injectionEPSS 0.3%