Weaknesses of type CWE-74

4,841 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2026-18085MEDIUMImproper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEMEPSS 0.3%CVE-2026-10225MEDIUMraisulislamg4 student_management_system_by_php Login login_check.php sql injectionEPSS 0.3%CVE-2026-105169MEDIUMkishor-23 food-waste-management-system Take Order delivery.php sql injectionEPSS 0.3%CVE-2026-11501MEDIUMSourceCodester Hospitals Patient Records Management System Master.php save_patient sql injectionEPSS 0.3%CVE-2026-10253MEDIUMitsourcecode Online House Rental System manage_payment.php sql injectionEPSS 0.3%CVE-2026-105185MEDIUMitsourcecode Online Admission System examinee.php sql injectionEPSS 0.3%CVE-2026-10252MEDIUMitsourcecode Online House Rental System manage_tenant.php sql injectionEPSS 0.3%CVE-2026-10260MEDIUMCodeAstro Online Job Portal delete-jobs.php sql injectionEPSS 0.3%CVE-2026-105253MEDIUMitsourcecode Online Admission System Project login1.php sql injectionEPSS 0.3%CVE-2026-102909MEDIUMSourceCodester Online Reviewer Management System btn_functions.php sql injectionEPSS 0.3%CVE-2026-105230MEDIUMkishor-23 food-waste-management-system deliverymyord.php sql injectionEPSS 0.3%CVE-2026-104609MEDIUMonetwothreeneth HospitalManagementSystem edit_accounts.php get sql injectionEPSS 0.3%CVE-2026-105172MEDIUMitsourcecode Online Admission System login1.php sql injectionEPSS 0.3%CVE-2026-10208MEDIUMcode-projects Online Hospital Management System login_1.php login_user sql injectionEPSS 0.3%CVE-2026-10250MEDIUMitsourcecode Online Blood Bank Management System campsdetails.php sql injectionEPSS 0.3%CVE-2026-95924MEDIUMSourceCodester Online Reviewer Management System btn_functions.php add sql injectionEPSS 0.3%CVE-2026-10227MEDIUMraisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injectionEPSS 0.3%CVE-2026-105231MEDIUMkishor-23 food-waste-management-system Admin Registration signup.php sql injectionEPSS 0.3%CVE-2026-105229MEDIUMkishor-23 food-waste-management-system User Registration Endpoint signup.php sql injectionEPSS 0.3%CVE-2026-105247MEDIUMSourceCodester Online Reviewer Management System btn_functions.php course sql injectionEPSS 0.3%