Falhas do tipo CWE-74

4.801 resultados

Injeção de código

Ocorre quando dados não confiáveis (entrada do usuário) são incorporados diretamente em comandos ou consultas executadas pelo sistema, sem validação ou escape. Um atacante consegue injetar código malicioso (SQL, script, comando) que será interpretado e executado com os privilégios da aplicação.

Exemplo

Uma busca por usuário que concatena a entrada diretamente em SQL: `SELECT * FROM users WHERE name = '` + input + `'`. Se o usuário digitar `' OR '1'='1`, a consulta retorna todos os registros. Com entrada maliciosa como `'; DROP TABLE users; --`, o banco é destruído.

Como mitigar

Use prepared statements ou queries parametrizadas (placeholders) para separar dados de código. Valide e sanitize todas as entradas, aplicando listas de permissão quando possível. Implemente o princípio do menor privilégio: a conta de banco de dados da aplicação deve ter apenas permissões necessárias.

CVE-2025-2117MEDIUMBeijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System reportCenter.do electricDocList sql injectionEPSS 0.4%CVE-2025-11113MEDIUMCodeAstro Online Leave Application signup.php sql injectionEPSS 0.4%CVE-2025-12614MEDIUMSourceCodester Best House Rental Management System admin_class.php delete_payment sql injectionEPSS 0.4%CVE-2026-0729MEDIUMcode-projects Intern Membership Management System add_activity.php sql injectionEPSS 0.4%CVE-2025-2587MEDIUMJinher OA C6 IncentivePlanFulfillAppprove.aspx sql injectionEPSS 0.4%CVE-2025-15182MEDIUMcode-projects Refugee Food Management System served.php sql injectionEPSS 0.4%CVE-2025-15184MEDIUMcode-projects Refugee Food Management System refugeesreport2.php sql injectionEPSS 0.4%CVE-2025-7936MEDIUMfuyang_lipengjun platform ScheduleJobLogController.java queryPage sql injectionEPSS 0.4%CVE-2025-13811MEDIUMjsnjfz WebStack-Guns PageFactory.java sql injectionEPSS 0.4%CVE-2021-32622MEDIUMFile upload local preview can run embedded scripts after user interactionEPSS 0.4%CVE-2026-2469HIGHVersions of the package directorytree/imapengine before 1.22.3 are vulnerable to Improper Neutralization of Special Elements in Output Used EPSS 0.4%CVE-2025-10251MEDIUMFoxCMS Images.php batchCope sql injectionEPSS 0.4%CVE-2025-3163MEDIUMInternLM LMDeploy conf.py open code injectionEPSS 0.4%CVE-2025-8018MEDIUMcode-projects Food Ordering Review System reservation_page.php sql injectionEPSS 0.4%CVE-2025-13121MEDIUMcameasy Liketea API Endpoint StoreController.php list sql injectionEPSS 0.4%CVE-2024-40637MEDIUMImplicit override for built-in materializations from installed packages in dbt-coreEPSS 0.4%CVE-2026-49452MEDIUMWeasyPrint: CSS Injection via Presentational HintsEPSS 0.4%CVE-2025-13485MEDIUMitsourcecode Online File Management System ajax.php sql injectionEPSS 0.4%CVE-2025-7482MEDIUMPHPGurukul Vehicle Parking Management System print.php sql injectionEPSS 0.4%CVE-2026-0852MEDIUMcode-projects Online Music Site AdminUpdateUser.php sql injectionEPSS 0.4%