CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,170)
This SQL injection vulnerability in Currency Exchange System 1.0 allows attackers to execute arbitrary SQL commands through the ID parameter in /edit....
Dec 8, 2025CVE-2025-14210 is an SQL injection vulnerability in Advanced Library Management System 1.0 that allows remote attackers to execute arbitrary SQL comma...
Dec 8, 2025CVE-2025-14211 is a SQL injection vulnerability in Advanced Library Management System 1.0 that allows attackers to manipulate database queries via the...
Dec 8, 2025This CVE describes a SQL injection vulnerability in Advanced Library Management System 1.0's member_search.php file. Attackers can manipulate the roll...
Dec 8, 2025Campcodes School File Management System 1.0 contains a SQL injection vulnerability in the /update_query.php file via the stud_id parameter. This allow...
Dec 8, 2025This CVE describes a SQL injection vulnerability in the Hotel-Management-System's invoiceprint.php file where the ID parameter can be manipulated. Att...
Dec 8, 2025This CVE describes a SQL injection vulnerability in the RashminDungrani online-banking application's login functionality. Attackers can manipulate the...
Dec 7, 2025This SQL injection vulnerability in Chanjet TPlus allows remote attackers to execute arbitrary SQL commands via the 'currentAccId' parameter in the Mu...
Dec 7, 2025This CVE describes a SQL injection vulnerability in Chanjet CRM through version 20251121. Attackers can exploit the gblOrgID parameter in /tools/jxf_d...
Dec 7, 2025This CVE describes a SQL injection vulnerability in TrippWasTaken PHP-Guitar-Shop that allows remote attackers to execute arbitrary SQL commands via t...
Dec 5, 2025This vulnerability allows remote attackers to execute arbitrary code on Qualitor systems by manipulating the 'passageiros' parameter in the /html/st/s...
Nov 30, 2025This CVE describes a SQL injection vulnerability in Chanjet CRM's /tools/upgradeattribute.php file, specifically in the gblOrgID parameter. Attackers ...
Nov 30, 2025This CVE describes a remote code injection vulnerability in taosir WTCMS that allows attackers to execute arbitrary code by manipulating the 'content'...
Nov 30, 2025This CVE describes an SQL injection vulnerability in taosir WTCMS's SlideController component. Attackers can exploit this to execute arbitrary SQL com...
Nov 30, 2025CVE-2025-13585 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows attackers to execute arbitrary SQL commands via ...
Nov 24, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Question Paper Generator 1.0 by manipulating the Fname parameter i...
Nov 24, 2025CVE-2025-13582 is a SQL injection vulnerability in Jonnys Liquor 1.0 that allows attackers to execute arbitrary SQL commands through the Product param...
Nov 24, 2025CVE-2025-13578 is an SQL injection vulnerability in code-projects Library System 1.0 that allows attackers to manipulate database queries through the ...
Nov 24, 2025This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the admin_id parame...
Nov 23, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Company Website CMS 1.0 through the Username parame...
Nov 23, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-852 routers by exploiting a command injection flaw in the /gena...
Nov 23, 2025Campcodes Online Polling System 1.0 contains a SQL injection vulnerability in the /registeracc.php file's email parameter. This allows remote attacker...
Nov 23, 2025This SQL injection vulnerability in SourceCodester Company Website CMS 1.0 allows attackers to manipulate database queries through the email parameter...
Nov 23, 2025CVE-2025-13556 is an SQL injection vulnerability in Campcodes Online Polling System 1.0 that allows remote attackers to execute arbitrary SQL commands...
Nov 23, 2025Campcodes School File Management System 1.0 contains a SQL injection vulnerability in the login component's stud_no parameter. Attackers can remotely ...
Nov 23, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the login component's username parameter. Attackers can remotely ex...
Nov 23, 2025CVE-2025-13485 is an SQL injection vulnerability in itsourcecode Online File Management System 1.0 that allows attackers to execute arbitrary SQL comm...
Nov 21, 2025This SQL injection vulnerability in SourceCodester Online Shop Project 1.0 allows attackers to manipulate database queries through the Search paramete...
Nov 20, 2025This CVE describes a command injection vulnerability in UTT θΏε 750W devices up to version 3.2.2-191225. Attackers can remotely execute arbitrary c...
Nov 20, 2025This SQL injection vulnerability in code-projects Online Shop Project 1.0 allows attackers to manipulate database queries through the password paramet...
Nov 20, 2025This is an SQL injection vulnerability in freeprojectscodes Sports Club Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Nov 20, 2025This is an SQL injection vulnerability in itsourcecode Human Resource Management System 1.0 that allows attackers to execute arbitrary SQL commands th...
Nov 19, 2025CVE-2025-13420 is a SQL injection vulnerability in itsourcecode Human Resource Management System 1.0 that allows remote attackers to execute arbitrary...
Nov 19, 2025This SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Nov 19, 2025This CVE describes a SQL injection vulnerability in the Login function of codehub666 94list software. Attackers can remotely exploit this flaw to exec...
Nov 19, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the Username parameter in the /ajax.php?action=login endpoint of Sour...
Nov 18, 2025This SQL injection vulnerability in Simple Pizza Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in...
Nov 18, 2025This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows attackers to execute arbitrary SQL command...
Nov 17, 2025This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows remote attackers to execute arbitrary SQL ...
Nov 17, 2025CVE-2025-13298 is a SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 that allows remote attackers to ex...
Nov 17, 2025This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Web-Based Internet Laboratory Management System 1.0 t...
Nov 17, 2025This SQL injection vulnerability in itsourcecode Web-Based Internet Laboratory Management System 1.0 allows remote attackers to execute arbitrary SQL ...
Nov 17, 2025CVE-2025-13291 is a SQL injection vulnerability in Campcodes Supplier Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Nov 17, 2025CVE-2025-13285 is an SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to manipulate database queries via the...
Nov 17, 2025CVE-2025-13280 is an SQL injection vulnerability in CodeAstro Simple Inventory System 1.0 that allows attackers to manipulate database queries through...
Nov 17, 2025CVE-2025-13277 is a SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via ...
Nov 17, 2025This SQL injection vulnerability in g33kyrash Online-Banking-System allows attackers to manipulate database queries through the Username parameter in ...
Nov 17, 2025This SQL injection vulnerability in Campcodes School Fees Payment Management System 1.0 allows attackers to execute arbitrary SQL commands through the...
Nov 17, 2025Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the login function via the Username parameter. This allo...
Nov 17, 2025This SQL injection vulnerability in itsourcecode Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands through the...
Nov 17, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free