CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,231)
CVE-2025-3309 is a critical SQL injection vulnerability in the Blood Bank Management System 1.0 that allows remote attackers to execute arbitrary SQL ...
Apr 6, 2025This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the userem...
Apr 6, 2025This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'fulln...
Apr 6, 2025This critical SQL injection vulnerability in PHPGurukul Men Salon Management System 1.0 allows attackers to execute arbitrary SQL commands via the Nam...
Apr 5, 2025A critical SQL injection vulnerability exists in PHPGurukul Old Age Home Management System 1.0 through the /search.php file's searchdata parameter. At...
Apr 4, 2025This critical SQL injection vulnerability in PHPGurukul Online Fire Reporting System 1.2 allows remote attackers to execute arbitrary SQL commands via...
Apr 4, 2025A critical SQL injection vulnerability exists in PHPGurukul Online Fire Reporting System 1.2, specifically in the /search-request.php file's searchdat...
Apr 4, 2025This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows remote attackers to execute arbitrary SQL commands via the pa...
Apr 4, 2025This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Apr 4, 2025CVE-2025-3216 is a critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 that allows remote attackers to execute arbitrary ...
Apr 4, 2025This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the rema...
Apr 4, 2025A critical SQL injection vulnerability in itsourcecode Online Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL comman...
Apr 4, 2025This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the Cate...
Apr 4, 2025This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows remote attackers to manipulate database queries throu...
Apr 4, 2025This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Apr 3, 2025This critical SQL injection vulnerability in Online Doctor Appointment Booking System 1.0 allows attackers to execute arbitrary SQL commands via the '...
Apr 3, 2025A critical SQL injection vulnerability exists in the Online Doctor Appointment Booking System 1.0, specifically in the /doctor/deletepatient.php file'...
Apr 3, 2025This critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows attackers to execute arbitrary SQL commands by ...
Apr 3, 2025This critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows remote attackers to execute arbitrary SQL comma...
Apr 3, 2025A critical SQL injection vulnerability in Project Worlds Online Lawyer Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Apr 3, 2025A critical SQL injection vulnerability exists in Project Worlds Online Lawyer Management System 1.0 via the unblock_id parameter in lawyer_booking.php...
Apr 3, 2025This critical SQL injection vulnerability in PHPGurukul Time Table Generator System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Apr 3, 2025This critical SQL injection vulnerability in SourceCodester Gym Management System 1.0 allows attackers to manipulate database queries through the user...
Apr 3, 2025This critical SQL injection vulnerability in PHPGurukul Bus Pass Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'vie...
Apr 3, 2025This critical SQL injection vulnerability in PHPGurukul Online Security Guards Hiring System 1.0 allows remote attackers to execute arbitrary SQL comm...
Apr 3, 2025This critical SQL injection vulnerability in PHPGurukul e-Diary Management System 1.0 allows attackers to manipulate database queries through the Cate...
Mar 31, 2025This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to execute arbitrary SQL commands through the reg...
Mar 27, 2025A critical SQL injection vulnerability exists in PHPGurukul Old Age Home Management System 1.0, specifically in the /admin/eligibility.php file's page...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows attackers to manipulate database queries through the...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows remote attackers to execute arbitrary SQL commands via t...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows attackers to execute arbitrary SQL commands through the ...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System allows attackers to manipulate database queries via the 'fromda...
Mar 25, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries via the mobi...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to manipulate database queries throu...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to execute arbitrary SQL commands via the l...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to manipulate database queries through the ...
Mar 24, 2025This critical SQL injection vulnerability in PHPGurukul Online Security Guards Hiring System 1.0 allows remote attackers to execute arbitrary SQL comm...
Mar 23, 2025This critical SQL injection vulnerability in PHPGurukul Bank Locker Management System 1.0 allows attackers to execute arbitrary SQL commands via the s...
Mar 23, 2025This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...
Mar 23, 2025This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...
Mar 23, 2025This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows remote attackers to execute arbitrary SQL commands ...
Mar 23, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free