Weaknesses of type CWE-74
4,843 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-24904HIGHlibsignal-service-rs doesn't sanity check plaintext envelopes are not sanity-checkedEPSS 0.2%CVE-2025-13178MEDIUMBdtask/CodeCanyon SalesERP User Profile edit_profile cross site scriptingEPSS 0.2%CVE-2024-13187MEDIUMKingsoft WPS Office TCC code injectionEPSS 0.2%CVE-2025-13180MEDIUMBdtask/CodeCanyon Wholesale Inventory Control and Inventory Management System edit_profile cross site scriptingEPSS 0.2%CVE-2026-95929MEDIUMiFlytek astron-agent getBotList API endpoint ChatBotMarketMapper.xml sql injectionEPSS 0.2%CVE-2026-97321MEDIUMYunaiV/zhijiantianya ruoyi-vue-pro GoView Data Endpoint GoViewDataServiceImpl.java GoViewDataServiceImpl.getDataBySQL sql injectionEPSS 0.2%CVE-2025-14186MEDIUMGrandstream GXP1625 Network Status api.values.post cross site scriptingEPSS 0.2%CVE-2023-3665MEDIUM
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI componentEPSS 0.2%CVE-2025-3804MEDIUMthautwarm vscode-diana Jinja2 Template Gen.py injectionEPSS 0.2%CVE-2025-4261MEDIUMGAIR-NLP factool tool.py run_single code injectionEPSS 0.2%CVE-2025-3805MEDIUMsarrionandia tournatrack Jinja2 Template check_id.py injectionEPSS 0.2%CVE-2026-46546LOWFrappe LMS: HTML injection in user-controlled metadataEPSS 0.2%CVE-2026-91986MEDIUMgitoxide gix-transport before 0.59.2 CR/LF/NUL InjectionEPSS 0.2%CVE-2026-1089MEDIUMUser‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS LookupsEPSS 0.2%CVE-2025-14185MEDIUMYonyou U8 Cloud AppServletService.class sql injectionEPSS 0.2%CVE-2025-14259MEDIUMJihai Jshop MiniProgram Mall System api.html sql injectionEPSS 0.2%CVE-2025-14780MEDIUMXiongwei Smart Catering Cloud Platform dish_trade_detail_get sql injectionEPSS 0.2%CVE-2025-15014MEDIUMloganhong php loganSite Article article_detail.php sql injectionEPSS 0.2%CVE-2025-14568MEDIUMhaxxorsid Stock-Management-System User.php sql injectionEPSS 0.2%CVE-2025-3026MEDIUMImproper Neutralization of Special Elements vulnerability in EJBCAEPSS 0.2%