CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,214)
This critical SQL injection vulnerability in CodeAstro Patient Record Management System 1.0 allows attackers to execute arbitrary SQL commands through...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL comma...
Jul 7, 2025A critical SQL injection vulnerability in Campcodes Online Recruitment Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jul 7, 2025Campcodes Payroll Management System 1.0 contains a critical SQL injection vulnerability in the /ajax.php?action=save_payroll endpoint via manipulation...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to manipulate database queries via the email p...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands via the User...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Jul 1, 2025A critical SQL injection vulnerability exists in Campcodes Employee Management System 1.0, specifically in the /mark.php file's ID parameter. This all...
Jul 1, 2025A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the I...
Jul 1, 2025CVE-2025-6958 is a critical SQL injection vulnerability in Campcodes Employee Management System 1.0 that allows remote attackers to execute arbitrary ...
Jul 1, 2025A critical SQL injection vulnerability in Campcodes Employee Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the '...
Jul 1, 2025CVE-2025-6938 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Jul 1, 2025CVE-2025-6936 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Jul 1, 2025CVE-2025-6917 is a critical SQL injection vulnerability in Online Hotel Booking 1.0 that allows remote attackers to execute arbitrary SQL commands via...
Jun 30, 2025A critical SQL injection vulnerability in code-projects Car Rental System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fname...
Jun 30, 2025A critical SQL injection vulnerability exists in code-projects Car Rental System 1.0 through the /signup.php file's fname parameter. Attackers can rem...
Jun 30, 2025This is a critical SQL injection vulnerability in code-projects Car Rental System 1.0 that allows remote attackers to execute arbitrary SQL commands v...
Jun 30, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 30, 2025A critical SQL injection vulnerability exists in code-projects Inventory Management System 1.0, specifically in the createUser.php file's Username par...
Jun 30, 2025This critical SQL injection vulnerability in code-projects Movie Ticketing System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Jun 30, 2025This critical SQL injection vulnerability in PHPGurukul Teachers Record Management System 2.1 allows attackers to manipulate database queries through ...
Jun 30, 2025A critical SQL injection vulnerability in SourceCodester Simple Company Website 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
Jun 29, 2025This critical SQL injection vulnerability in PHPGurukul Local Services Search Engine Management System allows remote attackers to execute arbitrary SQ...
Jun 29, 2025CVE-2025-6845 is a critical SQL injection vulnerability in Simple Forum 1.0 that allows remote attackers to execute arbitrary SQL commands via the Use...
Jun 29, 2025This critical SQL injection vulnerability in code-projects Product Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands thro...
Jun 29, 2025A critical SQL injection vulnerability in code-projects Library System 1.0 allows remote attackers to execute arbitrary SQL commands via the phone par...
Jun 29, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to manipulate database queries thro...
Jun 29, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows attackers to manipulate database queries through the...
Jun 28, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 28, 2025CVE-2025-6821 is a critical SQL injection vulnerability in code-projects Inventory Management System 1.0 that allows remote attackers to execute arbit...
Jun 28, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 28, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 25, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 25, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 25, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows attackers to manipulate database queries through the...
Jun 23, 2025This critical SQL injection vulnerability in code-projects Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 23, 2025This critical SQL injection vulnerability in Agri-Trading Online Shopping System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Jun 22, 2025CVE-2025-6483 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Jun 22, 2025CVE-2025-6481 is a critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Jun 22, 2025This critical SQL injection vulnerability in Simple Pizza Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'dayfr...
Jun 22, 2025CVE-2025-6474 is a critical SQL injection vulnerability in code-projects Inventory Management System 1.0 that allows remote attackers to execute arbit...
Jun 22, 2025A critical SQL injection vulnerability exists in code-projects Online Bidding System 1.0's administrator interface. Attackers can remotely exploit the...
Jun 22, 2025CVE-2025-6469 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary S...
Jun 22, 2025CVE-2025-6467 is a critical SQL injection vulnerability in code-projects Online Bidding System 1.0 that allows remote attackers to execute arbitrary S...
Jun 22, 2025This critical SQL injection vulnerability in code-projects Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL comman...
Jun 22, 2025A critical SQL injection vulnerability exists in code-projects Online Hotel Reservation System 1.0. Attackers can remotely exploit the /messageexec.ph...
Jun 22, 2025This critical SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Jun 22, 2025This critical SQL injection vulnerability in Simple Online Hotel Reservation System 1.0 allows attackers to manipulate database queries via the transa...
Jun 22, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,214 CVEs classified as CWE-74, with 117 rated critical and 1,295 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free