Weaknesses of type CWE-74

4,749 results

Injeção de código

É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.

Example

Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.

How to mitigate

Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.

CVE-2025-3181MEDIUMprojectworlds Online Doctor Appointment Booking System appointment.php sql injectionEPSS 0.6%CVE-2025-3183MEDIUMprojectworlds Online Doctor Appointment Booking System patientupdateprofile.php sql injectionEPSS 0.6%CVE-2025-3265MEDIUMPHPGurukul e-Diary Management System add-category.php sql injectionEPSS 0.6%CVE-2025-3178MEDIUMprojectworlds Online Doctor Appointment Booking System deleteappointment.php sql injectionEPSS 0.6%CVE-2025-3180MEDIUMprojectworlds Online Doctor Appointment Booking System deleteschedule.php sql injectionEPSS 0.6%CVE-2025-3179MEDIUMprojectworlds Online Doctor Appointment Booking System deletepatient.php sql injectionEPSS 0.6%CVE-2021-39175HIGHXSS vector in slide mode speaker-viewEPSS 0.6%CVE-2024-12481MEDIUMcjbi wetech-cms UserDao.java findUser sql injectionEPSS 0.6%CVE-2025-7838MEDIUMCampcodes Online Movie Theater Seat Reservation System manage_seat.php sql injectionEPSS 0.6%CVE-2025-4283MEDIUMSourceCodester/oretnom23 Stock Management System Login.php sql injectionEPSS 0.6%CVE-2024-12479MEDIUMcjbi wetech-cms TopicDao.java searchTopicByKeyword sql injectionEPSS 0.6%CVE-2022-4145MEDIUMContent spoofingEPSS 0.6%CVE-2026-48203CRITICALApache Camel: Camel-Solr: The SolrParam. and SolrField. Exchange header prefixes used non-Camel-prefixed names that bypass the HTTP header filter, allowing an HTTP client to inject Solr query parameters (server-side request forgery) and document fieldsEPSS 0.6%CVE-2025-0967MEDIUMcode-projects Chat System add_chatroom.php sql injectionEPSS 0.6%CVE-2025-0847MEDIUM1000 Projects Employee Task Management System Login index.php sql injectionEPSS 0.6%CVE-2025-2054MEDIUMcode-projects Blood Bank Management System edit_state.php sql injectionEPSS 0.6%CVE-2025-0491MEDIUMFanli2012 native-php-cms cat_dodel.php sql injectionEPSS 0.6%CVE-2025-2655MEDIUMSourceCodester AC Repair and Services System Users.php delete_users sql injectionEPSS 0.6%CVE-2025-5971MEDIUMcode-projects School Fees Payment System ajx.php sql injectionEPSS 0.6%CVE-2025-67733HIGHValkey Affected by RESP Protocol Injection via Lua error_replyEPSS 0.6%