Weaknesses of type CWE-74
4,749 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2025-67733HIGHValkey Affected by RESP Protocol Injection via Lua error_replyEPSS 0.6%CVE-2025-9662MEDIUMcode-projects Simple Grading System Admin Panel login.php sql injectionEPSS 0.6%CVE-2025-10802MEDIUMcode-projects Online Bidding System remove.php sql injectionEPSS 0.6%CVE-2024-42914CRITICALA host header injection vulnerability exists in the forgot password functionality of ArrowCMS version 1.0.0. By sending a specially crafted EPSS 0.6%CVE-2025-10841MEDIUMcode-projects Online Bidding System weweee.php sql injectionEPSS 0.6%CVE-2025-9766MEDIUMitsourcecode Sports Management System facilitator.php sql injectionEPSS 0.6%CVE-2025-10801MEDIUMSourceCodester Pet Grooming Management Software edit_tax.php sql injectionEPSS 0.6%CVE-2025-1902MEDIUMPHPGurukul Student Record System password-recovery.php sql injectionEPSS 0.6%CVE-2025-1901MEDIUMPHPGurukul Restaurant Table Booking System check_availability.php sql injectionEPSS 0.6%CVE-2025-3330MEDIUMcodeprojects Online Restaurant Management System reservation_save.php sql injectionEPSS 0.6%CVE-2025-3308MEDIUMcode-projects Blood Bank Management System viewrequest.php sql injectionEPSS 0.6%CVE-2025-3332MEDIUMcodeprojects Online Restaurant Management System menu_save.php sql injectionEPSS 0.6%CVE-2025-3331MEDIUMcodeprojects Online Restaurant Management System payment_save.php sql injectionEPSS 0.6%CVE-2026-3135MEDIUMitsourcecode News Portal Project add-category.php sql injectionEPSS 0.6%CVE-2026-2865MEDIUMitsourcecode Agri-Trading Online Shopping System HTTP POST Request productcontroller.php sql injectionEPSS 0.6%CVE-2026-2690MEDIUMitsourcecode Event Management System Admin Login ajax.php sql injectionEPSS 0.6%CVE-2026-3042MEDIUMitsourcecode Event Management System index.php sql injectionEPSS 0.6%CVE-2026-3133MEDIUMitsourcecode Document Management System Login loging.php sql injectionEPSS 0.6%CVE-2026-3046MEDIUMitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile_old.php sql injectionEPSS 0.6%CVE-2026-3069MEDIUMitsourcecode Document Management System edtlbls.php sql injectionEPSS 0.6%