CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,173)
This SQL injection vulnerability in code-projects Online Event Judging System 1.0 allows attackers to manipulate database queries through the txtsearc...
Sep 8, 2025CVE-2025-10102 is a SQL injection vulnerability in code-projects Online Event Judging System 1.0 that allows remote attackers to execute arbitrary SQL...
Sep 8, 2025This SQL injection vulnerability in SourceCodester Simple Forum Discussion System 1.0 allows attackers to execute arbitrary SQL commands via the Usern...
Sep 8, 2025This CVE describes a SQL injection vulnerability in Jinher OA software up to version 1.2, specifically in the GetTreeDate.aspx file. Attackers can man...
Sep 8, 2025CVE-2025-10082 is an SQL injection vulnerability in SourceCodester Online Polling System 1.0 that allows remote attackers to execute arbitrary SQL com...
Sep 8, 2025This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the ID parameter ...
Sep 8, 2025This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the email paramet...
Sep 8, 2025CVE-2025-10068 is a SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows remote attackers to execute arbitrary SQL comm...
Sep 7, 2025CVE-2025-10062 is an SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows attackers to manipulate databas...
Sep 6, 2025CVE-2025-10033 is an SQL injection vulnerability in itsourcecode Online Discussion Forum 1.0 that allows attackers to manipulate database queries thro...
Sep 6, 2025CVE-2025-10030 is a SQL injection vulnerability in Campcodes Grocery Sales and Inventory System 1.0 that allows remote attackers to execute arbitrary ...
Sep 6, 2025This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the semester par...
Sep 5, 2025This vulnerability allows remote attackers to execute arbitrary commands on TOTOLINK N600R routers via command injection in the web interface. Attacke...
Sep 4, 2025This SQL injection vulnerability in Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the mobnumber paramet...
Sep 4, 2025This vulnerability allows remote attackers to execute SQL injection attacks against PHPGurukul Beauty Parlour Management System 1.1 by manipulating th...
Sep 4, 2025CVE-2025-9927 is a SQL injection vulnerability in projectworlds Travel Management System 1.0 that allows attackers to execute arbitrary SQL commands v...
Sep 3, 2025CVE-2025-9926 is a SQL injection vulnerability in the Travel Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via ...
Sep 3, 2025CVE-2025-9924 is an SQL injection vulnerability in Travel Management System 1.0's enquiry.php file that allows attackers to manipulate database querie...
Sep 3, 2025This SQL injection vulnerability in 1000projects Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the from...
Sep 3, 2025CVE-2025-9839 is a SQL injection vulnerability in itsourcecode Student Information Management System 1.0 that allows attackers to execute arbitrary SQ...
Sep 2, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the studentId parameter in the Student Information Management System ...
Sep 2, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'phone' parameter in the /routers/register-router.php file of Sou...
Sep 2, 2025This SQL injection vulnerability in Campcodes Farm Management System 1.0 allows attackers to manipulate database queries through the rating parameter ...
Sep 2, 2025Campcodes Computer Sales and Inventory System 1.0 contains a SQL injection vulnerability in the /pages/pos_transac.php endpoint that allows remote att...
Sep 1, 2025CVE-2025-9792 is an SQL injection vulnerability in itsourcecode Apartment Management System 1.0 that allows remote attackers to execute arbitrary SQL ...
Sep 1, 2025This CVE describes a SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0, specifically in the /admin/edituser.php file's...
Sep 1, 2025This SQL injection vulnerability in Campcodes Online Learning Management System 1.0 allows attackers to manipulate database queries through the firstn...
Sep 1, 2025CVE-2025-9770 is a SQL injection vulnerability in Campcodes Hospital Management System 1.0 that allows attackers to bypass authentication on the admin...
Sep 1, 2025CVE-2025-9767 is an SQL injection vulnerability in itsourcecode Sports Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Sep 1, 2025CVE-2025-9765 is an SQL injection vulnerability in itsourcecode Sports Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Sep 1, 2025Campcodes Online Feeds Product Inventory System 1.0 contains a SQL injection vulnerability in the login component's username parameter. This allows re...
Sep 1, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'lastname' parameter in the Signup function of Campcodes/SourceCo...
Sep 1, 2025This SQL injection vulnerability in Campcodes/SourceCodester Courier Management System 1.0 allows attackers to manipulate database queries through the...
Sep 1, 2025CVE-2025-9751 is a SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows remote attackers to execute arbitrary SQ...
Sep 1, 2025CVE-2025-9750 is an SQL injection vulnerability in Campcodes Online Learning Management System 1.0 that allows remote attackers to execute arbitrary S...
Aug 31, 2025This SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 allows attackers to manipulate database queries through the log...
Aug 31, 2025CVE-2025-9741 is an SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 affecting the /login_query12.php file. Attackers...
Aug 31, 2025Campcodes Online Water Billing System 1.0 contains a SQL injection vulnerability in the /process.php file's Username parameter. This allows remote att...
Aug 31, 2025CVE-2025-9733 is a SQL injection vulnerability in code-projects Human Resource Integrated System 1.0 affecting the /login_timeee.php file via the emp_...
Aug 31, 2025This SQL injection vulnerability in PHPGurukul Online Course Registration 3.1 allows attackers to manipulate database queries through the studentname ...
Aug 31, 2025Campcodes Farm Management System 1.0 contains a SQL injection vulnerability in the /review.php file via the pid parameter. This allows remote attacker...
Aug 31, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Water Billing System 1.0 via the /edit.php file's I...
Aug 30, 2025CVE-2025-9704 is a SQL injection vulnerability in SourceCodester Water Billing System 1.0 that allows remote attackers to execute arbitrary SQL comman...
Aug 30, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Simple Cafe Billing System 1.0 via the ID parameter...
Aug 30, 2025This SQL injection vulnerability in SourceCodester Online Polling System 1.0 allows attackers to manipulate database queries through the myusername pa...
Aug 30, 2025Campcodes Advanced Online Voting System 1.0 contains a SQL injection vulnerability in the admin login page that allows attackers to execute arbitrary ...
Aug 30, 2025Campcodes Online Shopping System 1.0 contains a SQL injection vulnerability in the login.php file's Password parameter. Attackers can remotely exploit...
Aug 30, 2025This SQL injection vulnerability in itsourcecode Student Information System 1.0 allows attackers to manipulate database queries through the ID paramet...
Aug 30, 2025Campcodes Online Loan Management System 1.0 contains a SQL injection vulnerability in the delete_borrower function via the /ajax.php endpoint. Attacke...
Aug 29, 2025CVE-2025-9669 is a SQL injection vulnerability in Jinher OA 1.0's GetTreeDate.aspx file that allows attackers to manipulate database queries via the I...
Aug 29, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,173 CVEs classified as CWE-74, with 106 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free