CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,170)
This CVE describes a SQL injection vulnerability in SourceCodester Patients Waiting Area Queue Management System 1.0. Attackers can remotely exploit t...
Nov 16, 2025This SQL injection vulnerability in PHPGurukul Tourism Management System 1.0 allows attackers to manipulate database queries through the uid parameter...
Nov 16, 2025This SQL injection vulnerability in Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /register.php endpoi...
Nov 16, 2025CVE-2025-13241 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows remote attackers to execute arbitrary SQL...
Nov 16, 2025CVE-2025-13240 is an SQL injection vulnerability in code-projects Student Information System 2.0 that allows attackers to manipulate database queries ...
Nov 16, 2025CVE-2025-13237 is an SQL injection vulnerability in itsourcecode Inventory Management System 1.0 that allows remote attackers to execute arbitrary SQL...
Nov 16, 2025CVE-2025-13235 is an SQL injection vulnerability in itsourcecode Inventory Management System 1.0 that allows attackers to manipulate database queries ...
Nov 16, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands through the /index.php?q=single-item endpoint in itsourcecode Inventory M...
Nov 16, 2025This SQL injection vulnerability in Simple Cafe Ordering System 1.0 allows attackers to manipulate database queries through the studentnum parameter i...
Nov 15, 2025CVE-2025-13201 is an SQL injection vulnerability in code-projects Simple Cafe Ordering System 1.0 that allows attackers to execute arbitrary SQL comma...
Nov 15, 2025CVE-2025-13169 is an SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 that allows remote attackers to execute arbitrary SQL c...
Nov 14, 2025CVE-2025-13170 is an SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 that allows attackers to manipulate database queries vi...
Nov 14, 2025This SQL injection vulnerability in SourceCodester Patients Waiting Area Queue Management System 1.0 allows attackers to manipulate database queries t...
Nov 13, 2025CVE-2025-13121 is an SQL injection vulnerability in the Liketea 1.0.0 API endpoint that allows remote attackers to execute arbitrary SQL commands by m...
Nov 13, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Survey Application System 1.0 via the ID parameter ...
Nov 12, 2025This SQL injection vulnerability in SourceCodester Survey Application System 1.0 allows attackers to manipulate database queries through the fullname ...
Nov 10, 2025CVE-2025-12617 is a SQL injection vulnerability in itsourcecode Billing System 1.0 that allows remote attackers to execute arbitrary SQL commands via ...
Nov 3, 2025CVE-2025-12337 is a SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 that allows remote attackers to execute arbitrary...
Oct 28, 2025This SQL injection vulnerability in Campcodes Retro Basketball Shoes Online Store 1.0 allows attackers to manipulate database queries through the /adm...
Oct 28, 2025This SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through the email ...
Oct 27, 2025This SQL injection vulnerability in code-projects Courier Management System 1.0 allows attackers to manipulate database queries through the OfficeName...
Oct 27, 2025This CVE describes a SQL injection vulnerability in Nero Social Networking Site 1.0's deletemessage.php file. Attackers can manipulate the message_id ...
Oct 27, 2025CVE-2025-12306 is a SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via ...
Oct 27, 2025CVE-2025-12292 is an SQL injection vulnerability in SourceCodester Point of Sales 1.0 that allows remote attackers to execute arbitrary SQL commands v...
Oct 27, 2025This SQL injection vulnerability in SourceCodester Point of Sales 1.0 allows remote attackers to manipulate database queries through the Category para...
Oct 27, 2025This CVE describes a SQL injection vulnerability in Abdullah-Hasan-Sajjad Online-School's studentLogin.php file, specifically in the Email parameter. ...
Oct 27, 2025This SQL injection vulnerability in SourceCodester Online Student Result System 1.0 allows attackers to manipulate database queries through the ID par...
Oct 27, 2025This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0 affecting the /user/portal/get_expiredtime.php endpoint ...
Oct 27, 2025This SQL injection vulnerability in Projectworlds Online Shopping System 1.0 allows attackers to execute arbitrary SQL commands via the 'keywords' par...
Oct 27, 2025This SQL injection vulnerability in SourceCodester Best House Rental Management System 1.0 allows attackers to manipulate database queries through the...
Oct 27, 2025CVE-2025-11736 is an SQL injection vulnerability in itsourcecode Online Examination System 1.0 that allows remote attackers to execute arbitrary SQL c...
Oct 14, 2025This CVE describes a SQL injection vulnerability in SourceCodester Best Salon Management System 1.0. Attackers can manipulate the serv_id parameter in...
Oct 13, 2025This CVE describes an SQL injection vulnerability in the Inferno Online Clothing Store's /log.php file, specifically in the cemail/password parameters...
Oct 13, 2025This SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through the editid...
Oct 11, 2025CVE-2025-11608 is an SQL injection vulnerability in code-projects E-Banking System 1.0 that allows remote attackers to execute arbitrary SQL commands ...
Oct 11, 2025CVE-2025-11604 is a SQL injection vulnerability in projectworlds Online Ordering Food System 1.0 that allows attackers to manipulate database queries ...
Oct 11, 2025This SQL injection vulnerability in SourceCodester Online Student Result System 1.0 allows attackers to manipulate database queries through the Userna...
Oct 11, 2025CVE-2025-11599 is a SQL injection vulnerability in Campcodes Online Apartment Visitor Management System 1.0 that allows remote attackers to execute ar...
Oct 11, 2025This vulnerability allows remote attackers to execute SQL injection attacks against code-projects E-Commerce Website 1.0 by manipulating the order_id ...
Oct 11, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Project Monitoring System 1.0 through the uid parameter in /usered...
Oct 10, 2025This vulnerability allows attackers to execute arbitrary SQL commands through the txtspecialization parameter in the searchjob.php file of Online Job ...
Oct 10, 2025CVE-2025-11582 is an SQL injection vulnerability in code-projects Online Job Search Engine 1.0 that allows remote attackers to execute arbitrary SQL c...
Oct 10, 2025This SQL injection vulnerability in Gate Pass Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fullname' param...
Oct 9, 2025This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows remote attackers to execute arbitrary SQL commands via the Search para...
Oct 9, 2025CVE-2025-11555 is an SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows attackers to manipulate database queri...
Oct 9, 2025This SQL injection vulnerability in code-projects E-Commerce Website 1.0 allows attackers to manipulate database queries through the supp_id parameter...
Oct 9, 2025This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows remote attackers to execute arbitrary SQL commands through ...
Oct 8, 2025This vulnerability allows remote attackers to execute SQL injection attacks via the 'delid' parameter in the /admin/new-appointment.php file of PHPGur...
Oct 8, 2025This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the 'delid...
Oct 8, 2025This CVE describes a command injection vulnerability in D-Link DIR-852 routers that allows remote attackers to execute arbitrary commands on affected ...
Oct 8, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free