Falhas do tipo CWE-74

4.832 resultados

Injeção de código

Ocorre quando dados não confiáveis (entrada do usuário) são incorporados diretamente em comandos ou consultas executadas pelo sistema, sem validação ou escape. Um atacante consegue injetar código malicioso (SQL, script, comando) que será interpretado e executado com os privilégios da aplicação.

Exemplo

Uma busca por usuário que concatena a entrada diretamente em SQL: `SELECT * FROM users WHERE name = '` + input + `'`. Se o usuário digitar `' OR '1'='1`, a consulta retorna todos os registros. Com entrada maliciosa como `'; DROP TABLE users; --`, o banco é destruído.

Como mitigar

Use prepared statements ou queries parametrizadas (placeholders) para separar dados de código. Valide e sanitize todas as entradas, aplicando listas de permissão quando possível. Implemente o princípio do menor privilégio: a conta de banco de dados da aplicação deve ter apenas permissões necessárias.

CVE-2026-7678MEDIUMYunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injectionEPSS 0.3%CVE-2026-4597MEDIUM648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injectionEPSS 0.3%CVE-2026-90511MEDIUMGongShengyue OnlineBooks listSplit BooksServlet.java sql injectionEPSS 0.3%CVE-2026-84153MEDIUMXinhu Rainrock RockOA index.php toaddval sql injectionEPSS 0.3%CVE-2026-7716MEDIUMcode-projects Gym Management System In PHP/Windows NT index.php sql injectionEPSS 0.3%CVE-2026-6006MEDIUMcode-projects Patient Record Management System edit_hpatient.php sql injectionEPSS 0.3%CVE-2026-5606MEDIUMPHPGurukul Online Shopping Portal Project Parameter order-details.php sql injectionEPSS 0.3%CVE-2026-9449MEDIUMcode-projects Employee Management System changepassemp.php sql injectionEPSS 0.3%CVE-2026-86172MEDIUMDefaultFuction CRM delete.php sql injectionEPSS 0.3%CVE-2026-7447MEDIUMSourceCodester Pet Grooming Management Software update_customer.php sql injectionEPSS 0.3%CVE-2026-84061MEDIUMzhongyu09 OpenChatBI generate_sql.py _validate_sql_safety sql injectionEPSS 0.3%CVE-2026-7267MEDIUMSourceCodester Pizzafy Ecommerce System view_prod.php sql injectionEPSS 0.3%CVE-2026-4970MEDIUMcode-projects Social Networking Site Endpoint delete_photos.php sql injectionEPSS 0.3%CVE-2026-5578MEDIUMCodeAstro Online Classroom Parameter addassessment.php sql injectionEPSS 0.3%CVE-2026-6190MEDIUMitsourcecode Construction Management System employees.php sql injectionEPSS 0.3%CVE-2026-7591MEDIUMTimBroddin astro-mcp-server MCP Tool Query Construction index.ts sql injectionEPSS 0.3%CVE-2026-4574MEDIUMSourceCodester Simple E-learning System User Profile Update sql injectionEPSS 0.3%CVE-2026-5552MEDIUMPHPGurukul Online Shopping Portal Project Parameter sub-category.php sql injectionEPSS 0.3%CVE-2026-5560MEDIUMPHPGurukul Online Shopping Portal Project Parameter payment-method.php sql injectionEPSS 0.3%CVE-2026-4230MEDIUMvanna-ai vanna Endpoint __init__.py update_sql sql injectionEPSS 0.3%