Weaknesses of type CWE-74
4,749 resultsInjeção de código
É quando uma aplicação incorpora dados não validados em um comando ou consulta que será interpretado como código. O atacante consegue injetar instruções maliciosas que são executadas com os privilégios da aplicação, como SQL, shell ou XML.
Example
Um formulário de login que monta uma query SQL concatenando diretamente a entrada do usuário: `SELECT * FROM usuarios WHERE email = '` + email_usuario + `'`. Um atacante digita `' OR '1'='1` e consegue bypassar a autenticação.
How to mitigate
Use prepared statements ou parameterized queries (bind variables), que separam dados de código. Valide e sanitize todas as entradas contra regras rígidas de whitelist, e aplique o princípio do menor privilégio nas contas de banco de dados e processos.
CVE-2026-3818MEDIUMTiandy Easy7 CMS Windows GetDBData.jsp sql injectionEPSS 0.6%CVE-2026-63621MEDIUMApache Camel: Camel-Knative: CloudEvent extension fields received in structured content mode were mapped onto message headers without applying any header filter strategyEPSS 0.6%CVE-2025-1963MEDIUMprojectworlds Online Hotel Booking reservation.php sql injectionEPSS 0.6%CVE-2023-36250HIGHCSV Injection vulnerability in GNOME time tracker version 3.0.2, allows local attackers to execute arbitrary code via crafted .tsv file whenEPSS 0.6%CVE-2025-3856MEDIUMxxyopen Novel-Plus searchByPage sql injectionEPSS 0.6%CVE-2025-6959MEDIUMCampcodes Employee Management System eloginwel.php sql injectionEPSS 0.6%CVE-2026-25814CRITICALNoSQL Injection Risk via Unsanitized Query ParametersEPSS 0.6%CVE-2025-6960MEDIUMCampcodes Employee Management System empproject.php sql injectionEPSS 0.6%CVE-2025-4020MEDIUMPHPGurukul Old Age Home Management System contact.php sql injectionEPSS 0.6%CVE-2025-3559MEDIUMghostxbh uzy-ssm-mall 20 ForeProductListController sql injectionEPSS 0.6%CVE-2025-4297MEDIUMPHPGurukul Men Salon Management System change-password.php sql injectionEPSS 0.6%CVE-2026-4014MEDIUMitsourcecode Cafe Reservation System Registration signup.php sql injectionEPSS 0.6%CVE-2025-4331MEDIUMSourceCodester Online Student Clearance System login.php sql injectionEPSS 0.6%CVE-2025-5580MEDIUMCodeAstro Real Estate Management System login.php sql injectionEPSS 0.6%CVE-2025-4794MEDIUMPHPGurukul Online Course Registration news.php sql injectionEPSS 0.6%CVE-2025-4913MEDIUMPHPGurukul Auto Taxi Stand Management System index.php sql injectionEPSS 0.6%CVE-2025-4908MEDIUMPHPGurukul Daily Expense Tracker System expense-datewise-reports-detailed.php sql injectionEPSS 0.6%CVE-2025-4306MEDIUMPHPGurukul Nipah Virus Testing Management System edit-phlebotomist.php sql injectionEPSS 0.6%CVE-2025-4307MEDIUMPHPGurukul Art Gallery Management System add-art-medium.php sql injectionEPSS 0.6%CVE-2025-4910MEDIUMPHPGurukul Zoo Management System edit-animal-details.php sql injectionEPSS 0.6%