CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,170)
This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'prodcode' parameter in the /pages/pro_edit1.php file in Campcode...
Sep 23, 2025This SQL injection vulnerability in Hostel Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in the...
Sep 22, 2025CVE-2025-10811 is a SQL injection vulnerability in code-projects Hostel Management System 1.0 that allows attackers to manipulate database queries thr...
Sep 22, 2025Campcodes Farm Management System 1.0 contains a SQL injection vulnerability in the /uploadProduct.php file via the Type parameter. This allows remote ...
Sep 22, 2025CVE-2025-10802 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Sep 22, 2025CVE-2025-10800 is a SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL comm...
Sep 22, 2025This SQL injection vulnerability in code-projects Hostel Management System 1.0 allows attackers to manipulate database queries through the ID paramete...
Sep 22, 2025This SQL injection vulnerability in Hostel Management System 1.0 allows attackers to manipulate database queries through the email parameter in the ad...
Sep 22, 2025CVE-2025-10795 is an SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Sep 22, 2025CVE-2025-10791 is a SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary SQL comma...
Sep 22, 2025This vulnerability allows remote attackers to execute SQL injection attacks on SourceCodester Online Hotel Reservation System 1.0 via the deleteroomin...
Sep 22, 2025This SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 allows attackers to execute arbitrary SQL commands via the ID par...
Sep 22, 2025Campcodes Online Learning Management System 1.0 contains a SQL injection vulnerability in the /admin/edit_subject.php file via the subject_code parame...
Sep 22, 2025Campcodes Online Learning Management System 1.0 contains a SQL injection vulnerability in the /admin/class.php file via the class_name parameter. This...
Sep 22, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes Online Learning Management System 1.0 through the /admin...
Sep 22, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Sep 18, 2025This SQL injection vulnerability in SourceCodester Responsive E-Learning System 1.0 allows attackers to manipulate database queries through the Userna...
Sep 18, 2025This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode E-Logbook with Health Monitoring System for COVID-19 ...
Sep 18, 2025CVE-2025-10668 is an SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL com...
Sep 18, 2025CVE-2025-10664 is a SQL injection vulnerability in PHPGurukul Small CRM 4.0 that allows remote attackers to execute arbitrary SQL commands via the 'su...
Sep 18, 2025This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the 'cgpa' param...
Sep 18, 2025This SQL injection vulnerability in SourceCodester Online Exam Form Submission 1.0 allows attackers to manipulate database queries via the email param...
Sep 17, 2025This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Online Discussion Forum 1.0 through the search function...
Sep 17, 2025This SQL injection vulnerability in kidaze CourseSelectionSystem allows remote attackers to execute arbitrary SQL commands by manipulating the 'cname'...
Sep 17, 2025This CVE describes an SQL injection vulnerability in the itsourcecode Web-Based Internet Laboratory Management System 1.0. Attackers can manipulate th...
Sep 17, 2025This CVE describes a SQL injection vulnerability in SourceCodester Online Exam Form Submission 1.0, specifically in the 'usn' parameter of /index.php....
Sep 17, 2025Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_receiving endpoint via manipula...
Sep 16, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=save_product endpoint in Cam...
Sep 16, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via th...
Sep 15, 2025CVE-2025-10479 is an SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 that allows remote attackers to execute a...
Sep 15, 2025This SQL injection vulnerability in Campcodes Computer Sales and Inventory System 1.0 allows attackers to manipulate database queries through the /pag...
Sep 15, 2025CVE-2025-10435 is a SQL injection vulnerability in Campcodes Computer Sales and Inventory System 1.0 that allows attackers to execute arbitrary SQL co...
Sep 15, 2025CVE-2025-10426 is a SQL injection vulnerability in itsourcecode Online Laundry Management System 1.0 that allows remote attackers to execute arbitrary...
Sep 15, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=delete_supplier endpoint in ...
Sep 15, 2025Campcodes Grocery Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=save_supplier endpoint via manipulatio...
Sep 14, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes Grocery Sales and Inventory System 1.0 via the /ajax.php...
Sep 14, 2025CVE-2025-10405 is a SQL injection vulnerability in itsourcecode Baptism Information Management System 1.0 that allows remote attackers to execute arbi...
Sep 14, 2025This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 by manipulating th...
Sep 14, 2025This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 through the delid ...
Sep 14, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the ID...
Sep 14, 2025This CVE describes a command injection vulnerability in Wavlink WL-WN578W2 routers that allows remote attackers to execute arbitrary commands on affec...
Sep 12, 2025This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands by manipula...
Sep 9, 2025This CVE describes a SQL injection vulnerability in the itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0. Attackers can exploit t...
Sep 9, 2025CVE-2025-10115 is a SQL injection vulnerability in SiempreCMS that allows attackers to execute arbitrary SQL commands via the name/userName parameter ...
Sep 9, 2025CVE-2025-10112 is a SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows remote attackers to execute arbi...
Sep 9, 2025Campcodes Online Loan Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_payment endpoint via manipulation of...
Sep 8, 2025This SQL injection vulnerability in itsourcecode Student Information Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Sep 8, 2025CVE-2025-10108 is an SQL injection vulnerability in Campcodes Online Loan Management System 1.0 that allows attackers to manipulate database queries v...
Sep 8, 2025This SQL injection vulnerability in code-projects Online Event Judging System 1.0 allows attackers to manipulate database queries through the txtsearc...
Sep 8, 2025CVE-2025-10102 is a SQL injection vulnerability in code-projects Online Event Judging System 1.0 that allows remote attackers to execute arbitrary SQL...
Sep 8, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free