Weaknesses of type CWE-74

4,743 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2025-7883HIGHEluktronics Control Center Powershell Script Command command injectionEPSS 1.7%CVE-2026-11452MEDIUMGL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injectionEPSS 1.7%CVE-2023-46304HIGHmodules/Users/models/Module.php in Vtiger CRM 7.5.0 allows a remote authenticated attacker to run arbitrary PHP code because an unprotected EPSS 1.7%CVE-2025-7578LOWTeledyne FLIR FB-Series O/FLIR FH-Series ID runcmd.sh sendCommand command injectionEPSS 1.6%CVE-2025-14276MEDIUMIlevia EVE X1 Server leaf_search.php command injectionEPSS 1.6%CVE-2025-11488MEDIUMD-Link DIR-852 HNAP1 command injectionEPSS 1.6%CVE-2022-39382CRITICALNODE_ENV in Keystone defaults to development with esbuildEPSS 1.6%CVE-2021-21263HIGHQuery Binding Exploitation in LaravelEPSS 1.6%CVE-2022-20693MEDIUMCisco IOS XE Software Web UI API Injection VulnerabilityEPSS 1.6%CVE-2020-7489CRITICALA CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruEPSS 1.6%CVE-2026-27727HIGHmchange-commons-java: Remote Code Execution via JNDI Reference ResolutionEPSS 1.6%CVE-2022-31777MEDIUMApache Spark XSS vulnerability in log viewer UI JavascriptEPSS 1.6%CVE-2026-11448MEDIUMGL.iNet GL-MT3000 Minidlna Service rpc realpath command injectionEPSS 1.6%CVE-2021-41170CRITICALEvaluation of closures can lead to execution of methods & functions in current program scopeEPSS 1.6%CVE-2020-7475—A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability EPSS 1.6%CVE-2026-93966MEDIUMaiyiyi121 SxDevOps TASK_RUN_COMMAND host_tasks.py paramiko.SSHClient.exec_command command injectionEPSS 1.6%CVE-2026-11450MEDIUMGL.iNet GL-MT3000 Path Normalization dlopen command injectionEPSS 1.6%CVE-2021-21278HIGHRisk of code injection in RSSHubEPSS 1.6%CVE-2025-3546HIGHH3C Magic BE18000 HTTP POST Request getLanguage FCGI_CheckStringIfContainsSemicolon command injectionEPSS 1.6%CVE-2020-26298MEDIUMInjection in RedcarpetEPSS 1.6%