Falhas do tipo CWE-74

4.749 resultados

Injeção de código

Ocorre quando dados não confiáveis (entrada do usuário) são incorporados diretamente em comandos ou consultas executadas pelo sistema, sem validação ou escape. Um atacante consegue injetar código malicioso (SQL, script, comando) que será interpretado e executado com os privilégios da aplicação.

Exemplo

Uma busca por usuário que concatena a entrada diretamente em SQL: `SELECT * FROM users WHERE name = '` + input + `'`. Se o usuário digitar `' OR '1'='1`, a consulta retorna todos os registros. Com entrada maliciosa como `'; DROP TABLE users; --`, o banco é destruído.

Como mitigar

Use prepared statements ou queries parametrizadas (placeholders) para separar dados de código. Valide e sanitize todas as entradas, aplicando listas de permissão quando possível. Implemente o princípio do menor privilégio: a conta de banco de dados da aplicação deve ter apenas permissões necessárias.

CVE-2026-9354MEDIUMNousResearch hermes-agent Slack Agent/Mattermost Agent escape outputEPSS 0.6%CVE-2025-6173MEDIUMWebkul QloApps ajax_products_list.php sql injectionEPSS 0.6%CVE-2026-2867MEDIUMitsourcecode Vehicle Management System billaction.php sql injectionEPSS 0.6%CVE-2025-1809MEDIUMPixsoft Sol Login Endpoint servlet sql injectionEPSS 0.6%CVE-2021-21261HIGHFlatpak sandbox escape via spawn portalEPSS 0.6%CVE-2025-1811MEDIUMAT Software Solutions ATSVD Login Endpoint login.aspx sql injectionEPSS 0.6%CVE-2025-1808MEDIUMPixsoft E-Saphira Login Endpoint servlet sql injectionEPSS 0.6%CVE-2025-1821MEDIUMzj1983 zz ZorgAction.java getUserOrgForUserId sql injectionEPSS 0.6%CVE-2025-1831MEDIUMzj1983 zz ZorgAction.java GetDBUser sql injectionEPSS 0.6%CVE-2025-1843MEDIUMMini-Tmall ProductMapper.java select sql injectionEPSS 0.6%CVE-2024-11242MEDIUMZZCMS Keyword Filtering ad_list.php sql injectionEPSS 0.6%CVE-2024-11817MEDIUMPHPGurukul User Registration & Login and User Management System index.php sql injectionEPSS 0.6%CVE-2026-3747MEDIUMitsourcecode University Management System add_result.php sql injectionEPSS 0.6%CVE-2026-5035MEDIUMcode-projects Accounting System Parameter view_work.php sql injectionEPSS 0.6%CVE-2025-9419MEDIUMitsourcecode Apartment Management System addunit.php sql injectionEPSS 0.6%CVE-2026-3740MEDIUMitsourcecode University Management System admin_search_student.php sql injectionEPSS 0.6%CVE-2026-3757MEDIUMprojectworlds Online Art Gallery Shop pass sql injectionEPSS 0.6%CVE-2026-5033MEDIUMcode-projects Accounting System Parameter view_costumer.php sql injectionEPSS 0.6%CVE-2026-3765MEDIUMitsourcecode University Management System att_single_view.php sql injectionEPSS 0.6%CVE-2026-3760MEDIUMitsourcecode University Management System view_result.php sql injectionEPSS 0.6%