CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,180)
This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows remote attackers to execute arbitrary SQL command...
Aug 14, 2025This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the payment_t...
Aug 14, 2025This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through ...
Aug 14, 2025This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via t...
Aug 14, 2025This SQL injection vulnerability in Online Tour and Travel Management System 1.0 allows attackers to manipulate database queries through the /admin/ap...
Aug 14, 2025This SQL injection vulnerability in itsourcecode Online Tour and Travel Management System 1.0 allows attackers to execute arbitrary SQL commands via t...
Aug 14, 2025This SQL injection vulnerability in PHPGurukul Hospital Management System 4.0 allows attackers to manipulate database queries through the docfees para...
Aug 14, 2025This SQL injection vulnerability in PHPGurukul Hospital Management System 4.0 allows remote attackers to execute arbitrary SQL commands via the doctor...
Aug 14, 2025This SQL injection vulnerability in Campcodes Online Flight Booking Management System 1.0 allows attackers to execute arbitrary SQL commands via the l...
Aug 14, 2025CVE-2025-8950 is an SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 that allows remote attackers to execute arbitrar...
Aug 14, 2025CVE-2025-8948 is an SQL injection vulnerability in Projectworlds Visitor Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Aug 14, 2025CVE-2025-8946 is an SQL injection vulnerability in the Online Notes Sharing Platform 1.0 login.php file that allows attackers to manipulate database q...
Aug 14, 2025CVE-2025-8936 is an SQL injection vulnerability in 1000 Projects Sales Management System 1.0 that allows attackers to execute arbitrary SQL commands v...
Aug 14, 2025CVE-2025-8935 is an SQL injection vulnerability in 1000 Projects Sales Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Aug 14, 2025This SQL injection vulnerability in 1000 Projects Sales Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'ssalescat' p...
Aug 14, 2025A critical SQL injection vulnerability exists in Simple Art Gallery 1.0's /Admin/registration.php file, specifically in the 'fname' parameter. This al...
Aug 10, 2025A critical SQL injection vulnerability in code-projects Online Medicine Guide 1.0 allows remote attackers to execute arbitrary SQL commands via the 'd...
Aug 10, 2025This critical SQL injection vulnerability in Dinstar Monitoring Platform allows attackers to execute arbitrary SQL commands by manipulating the userBe...
Aug 9, 2025This critical vulnerability in wangzhixuan's spring-shiro-training allows remote attackers to execute arbitrary commands through command injection in ...
Aug 9, 2025A critical SQL injection vulnerability exists in the Online Medicine Guide 1.0 software, specifically in the /changepass.php file's 'ups' parameter. T...
Aug 3, 2025CVE-2025-8498 is a SQL injection vulnerability in code-projects Online Medicine Guide 1.0 that allows remote attackers to execute arbitrary SQL comman...
Aug 3, 2025This critical SQL injection vulnerability in projectworlds Online Admission System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
Aug 3, 2025This critical SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Aug 3, 2025This critical SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Aug 2, 2025This critical SQL injection vulnerability in projectworlds Online Admission System 1.0 allows attackers to manipulate database queries through the a_i...
Aug 2, 2025A critical SQL injection vulnerability in SourceCodester Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands...
Aug 2, 2025CVE-2025-8467 is a critical SQL injection vulnerability in Wazifa System 1.0 that allows remote attackers to execute arbitrary SQL commands via the Us...
Aug 2, 2025CVE-2025-8466 is a critical SQL injection vulnerability in code-projects Online Farm System 1.0 that allows remote attackers to execute arbitrary SQL ...
Aug 2, 2025CVE-2025-8443 is a critical SQL injection vulnerability in the Online Medicine Guide 1.0 software that allows attackers to execute arbitrary SQL comma...
Aug 1, 2025CVE-2025-8442 is a critical SQL injection vulnerability in Online Medicine Guide 1.0 that allows remote attackers to execute arbitrary SQL commands vi...
Aug 1, 2025CVE-2025-8437 is a critical SQL injection vulnerability in Kitchen Treasure 1.0's userregistration.php file that allows remote attackers to manipulate...
Aug 1, 2025A critical SQL injection vulnerability in code-projects Wazifa System 1.0 allows remote attackers to execute arbitrary SQL commands via the Password p...
Aug 1, 2025CVE-2025-8436 is a critical SQL injection vulnerability in projectworlds Online Admission System 1.0 that allows remote attackers to execute arbitrary...
Aug 1, 2025This critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'boa...
Aug 1, 2025CVE-2025-8407 is a critical SQL injection vulnerability in code-projects Vehicle Management 1.0 that allows remote attackers to execute arbitrary SQL ...
Jul 31, 2025This critical SQL injection vulnerability in Campcodes Online Hotel Reservation System 1.0 allows attackers to manipulate database queries through the...
Jul 31, 2025This critical SQL injection vulnerability in Vehicle Management 1.0 allows remote attackers to execute arbitrary SQL commands via the 'company' parame...
Jul 31, 2025This is a critical SQL injection vulnerability in Exam Form Submission 1.0 that allows attackers to manipulate database queries through the 'credits' ...
Jul 31, 2025This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the 'credits' para...
Jul 31, 2025CVE-2025-8338 is a critical SQL injection vulnerability in projectworlds Online Admission System 1.0 that allows remote attackers to execute arbitrary...
Jul 31, 2025A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jul 30, 2025This critical SQL injection vulnerability in Online Farm System 1.0 allows remote attackers to execute arbitrary SQL commands via the Username paramet...
Jul 30, 2025CVE-2025-8330 is a critical SQL injection vulnerability in Vehicle Management 1.0 that allows remote attackers to execute arbitrary SQL commands via t...
Jul 30, 2025A critical SQL injection vulnerability exists in code-projects Vehicle Management 1.0 through the 'company' parameter in /filter3.php. Attackers can r...
Jul 30, 2025This critical SQL injection vulnerability in Exam Form Submission 1.0 allows attackers to manipulate database queries through the /admin/delete_s8.php...
Jul 30, 2025This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...
Jul 30, 2025A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jul 28, 2025A critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the 'credits' paramet...
Jul 28, 2025This critical SQL injection vulnerability in Exam Form Submission 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...
Jul 28, 2025This critical SQL injection vulnerability in Exam Form Submission 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /admi...
Jul 28, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,180 CVEs classified as CWE-74, with 107 rated critical and 1,281 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free