Weaknesses of type CWE-74
4,749 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2026-2691MEDIUMitsourcecode Event Management System manage_register.php sql injectionEPSS 0.6%CVE-2026-2690MEDIUMitsourcecode Event Management System Admin Login ajax.php sql injectionEPSS 0.6%CVE-2026-3134MEDIUMitsourcecode News Portal Project edit-category.php sql injectionEPSS 0.6%CVE-2026-3068MEDIUMitsourcecode Document Management System deluser.php sql injectionEPSS 0.6%CVE-2026-3261MEDIUMitsourcecode School Management System Setting index.php sql injectionEPSS 0.6%CVE-2026-3046MEDIUMitsourcecode E-Logbook with Health Monitoring System for COVID-19 check_profile_old.php sql injectionEPSS 0.6%CVE-2025-1162MEDIUMcode-projects Job Recruitment load\_user-profile.php sql injectionEPSS 0.6%CVE-2026-4039MEDIUMOpenClaw Skill Env applySkillConfigenvOverrides code injectionEPSS 0.6%CVE-2025-2662MEDIUMProject Worlds Online Time Table Generator studentdashboard.php sql injectionEPSS 0.6%CVE-2024-29896HIGHAstro-Shield's Content-Security-Policy header generation in middleware could be compromised by malicious injectionsEPSS 0.6%CVE-2023-42135MEDIUMPAX A920Pro/A50 devices with PayDroid_8.1.0_Sagittarius_V11.1.50_20230614 or earlier can allow local code execution via parameter injection EPSS 0.6%CVE-2025-41083MEDIUMImproper Neutralization in Altitude Communication ServerEPSS 0.6%CVE-2025-8499MEDIUMcode-projects Online Medicine Guide cusfindambulence2.php sql injectionEPSS 0.6%CVE-2024-13024MEDIUMCodezips Blood Bank Management System campaign.php sql injectionEPSS 0.6%CVE-2026-2912MEDIUMcode-projects Online Reviewer System studentresult-view.php sql injectionEPSS 0.6%CVE-2025-10791MEDIUMcode-projects Online Bidding System index.php sql injectionEPSS 0.6%CVE-2025-10795MEDIUMcode-projects Online Bidding System bidupdate.php sql injectionEPSS 0.6%CVE-2025-10673MEDIUMitsourcecode Student Information Management System index.php sql injectionEPSS 0.6%CVE-2025-7176MEDIUMPHPGurukul Hospital Management System view-medhistory.php sql injectionEPSS 0.6%CVE-2025-10793MEDIUMcode-projects E-Commerce Website admin_account_delete.php sql injectionEPSS 0.6%