CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,228)
This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
May 15, 2025A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the /pages/transaction_del.php file's ID pa...
May 15, 2025This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
May 15, 2025A critical SQL injection vulnerability exists in Campcodes Sales and Inventory System 1.0, specifically in the discount parameter of the /pages/sales_...
May 15, 2025This critical SQL injection vulnerability in Projectworlds Online Examination System 1.0 allows attackers to manipulate database queries through the V...
May 15, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System 1.13 allows remote attackers to execute arbitrary SQL comman...
May 15, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...
May 15, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows attackers to execute arbitrary SQL commands by manipu...
May 15, 2025A critical SQL injection vulnerability in PHPGurukul Directory Management System 2.0 allows remote attackers to execute arbitrary SQL commands via the...
May 15, 2025A critical SQL injection vulnerability exists in PHPGurukul Directory Management System 2.0, specifically in the /admin/edit-directory.php file via th...
May 15, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the fromdate/todate parameters in the /admin/bwdates-reports-details....
May 12, 2025This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to manipulate database queries throu...
May 11, 2025A critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
May 11, 2025This critical SQL injection vulnerability in LyLme Spage 2.1 allows remote attackers to execute arbitrary SQL commands via the 'sort' parameter in adm...
May 11, 2025A critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the f...
May 10, 2025This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
May 10, 2025This critical SQL injection vulnerability in SourceCodester Online College Library System 1.0 allows attackers to manipulate database queries through ...
May 10, 2025This critical SQL injection vulnerability in Campcodes Sales and Inventory System 1.0 allows remote attackers to manipulate database queries via the I...
May 10, 2025This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
May 9, 2025This critical SQL injection vulnerability in Campcodes Online Food Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
May 9, 2025This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
May 9, 2025CVE-2025-4488 is a critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 that allows remote attackers to execute arbitrary SQ...
May 9, 2025This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
May 9, 2025A critical SQL injection vulnerability in Project Worlds Student Project Allocation System 1.0 allows remote attackers to execute arbitrary SQL comman...
May 9, 2025This critical SQL injection vulnerability in SourceCodester Apartment Visitor Management System 1.0 allows remote attackers to execute arbitrary SQL c...
May 9, 2025This critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows attackers to execute arbitrary SQL commands through the /aj...
May 9, 2025CVE-2025-4466 is a critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 that allows remote attackers to execute arbitrary SQ...
May 9, 2025A critical SQL injection vulnerability exists in Project Worlds Car Rental Project 1.0, specifically in the /admin/approve.php file's ID parameter. Th...
May 9, 2025A critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'ri...
May 6, 2025A critical SQL injection vulnerability in itsourcecode Gym Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the mem...
May 6, 2025A critical SQL injection vulnerability exists in itsourcecode Gym Management System 1.0 through the /view_member.php file's ID parameter. Attackers ca...
May 6, 2025A critical SQL injection vulnerability in PHPGurukul Company Visitor Management System 2.0 allows remote attackers to execute arbitrary SQL commands v...
May 6, 2025This critical SQL injection vulnerability in SourceCodester Online Student Clearance System 1.0 allows attackers to execute arbitrary SQL commands via...
May 6, 2025CVE-2025-4314 is a critical SQL injection vulnerability in SourceCodester Advanced Web Store 1.0 that allows attackers to execute arbitrary SQL comman...
May 6, 2025This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows attackers to manipulate database queries through the ...
May 6, 2025A critical SQL injection vulnerability in itsourcecode Content Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
May 6, 2025This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute arbitrary SQL commands vi...
May 6, 2025This critical SQL injection vulnerability in PHPGurukul Cyber Cafe Management System 1.0 allows attackers to manipulate database queries through the m...
May 6, 2025A critical SQL injection vulnerability in itsourcecode Content Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
May 6, 2025This critical SQL injection vulnerability in PHPGurukul Men Salon Management System 2.0 allows attackers to execute arbitrary SQL commands via the /ad...
May 5, 2025This critical SQL injection vulnerability in PHPGurukul Notice Board System 1.0 allows attackers to execute arbitrary SQL commands via the fromdate/to...
May 5, 2025A critical SQL injection vulnerability exists in PHPGurukul Emergency Ambulance Hiring Portal 1.0, specifically in the /admin/edit-ambulance.php file ...
May 5, 2025This critical SQL injection vulnerability in PHPGurukul Online DJ Booking Management System 1.0 allows remote attackers to execute arbitrary SQL comma...
May 5, 2025This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the /man...
May 4, 2025This critical SQL injection vulnerability in PHPGurukul Online Birth Certificate System 2.0 allows attackers to manipulate database queries through th...
May 3, 2025This critical SQL injection vulnerability in PHPGurukul/Campcodes Cyber Cafe Management System 1.0 allows remote attackers to execute arbitrary SQL co...
May 3, 2025This critical SQL injection vulnerability in PHPGuruku Online DJ Booking Management System 1.0 allows remote attackers to execute arbitrary SQL comman...
May 2, 2025This critical SQL injection vulnerability in PHPGurukul Online Birth Certificate System 1.0 allows attackers to execute arbitrary SQL commands via the...
May 2, 2025This critical vulnerability allows remote attackers to execute SQL injection attacks through the Username parameter in the /login.php file of PHPGuruk...
May 1, 2025This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries via the ...
May 1, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,228 CVEs classified as CWE-74, with 122 rated critical and 1,303 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free