CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,231)
This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows remote attackers to execute arbitrary SQL commands ...
Mar 4, 2025This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to manipulate database queries through th...
Mar 4, 2025CVE-2025-1903 is a critical SQL injection vulnerability in Codezips Online Shopping Website 1.0 that allows remote attackers to execute arbitrary SQL ...
Mar 4, 2025This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to execute arbitrary SQL commands via the...
Mar 4, 2025A critical SQL injection vulnerability exists in PHPGurukul News Portal 4.1's login.php file, allowing attackers to manipulate database queries via th...
Mar 3, 2025A critical SQL injection vulnerability exists in PHPGurukul Nipah Virus Testing Management System 1.0, specifically in the /check_availability.php fil...
Mar 3, 2025This critical SQL injection vulnerability in ESAFENET CDG allows remote attackers to execute arbitrary SQL commands by manipulating the flowId paramet...
Mar 3, 2025This critical SQL injection vulnerability in AT Software Solutions ATSVD allows attackers to execute arbitrary SQL commands via the txtUsuario paramet...
Mar 2, 2025This critical SQL injection vulnerability in Pixsoft Sol allows attackers to execute arbitrary SQL commands via the txtUsuario parameter in the login ...
Mar 2, 2025This critical SQL injection vulnerability in Pixsoft E-Saphira 1.7.24 allows attackers to manipulate database queries through the login endpoint. Remo...
Mar 2, 2025This critical SQL injection vulnerability in Benner ModernaNet allows attackers to execute arbitrary SQL commands through the /Home/JS_CarregaCombo en...
Feb 25, 2025This critical SQL injection vulnerability in Benner ModernaNet allows remote attackers to execute arbitrary SQL commands through the /AGE0000700/GetHo...
Feb 25, 2025This critical SQL injection vulnerability in Baiyi Cloud Asset Management System allows remote attackers to execute arbitrary SQL commands by manipula...
Feb 21, 2025This critical SQL injection vulnerability in Baiyi Cloud Asset Management System allows remote attackers to execute arbitrary SQL commands via the pro...
Feb 19, 2025This critical vulnerability in Synway SMG Gateway Management Software allows remote attackers to execute arbitrary commands via command injection in t...
Feb 19, 2025This critical vulnerability in NUUO Camera software allows remote attackers to execute arbitrary commands on affected systems through command injectio...
Feb 16, 2025This critical SQL injection vulnerability in CoinRemitter OpenCart plugin allows remote attackers to execute arbitrary SQL commands by manipulating th...
Feb 8, 2025This critical SQL injection vulnerability in Dreamvention Live AJAX Search Free for OpenCart allows remote attackers to execute arbitrary SQL commands...
Feb 8, 2025A critical SQL injection vulnerability in 1000 Projects Employee Task Management System 1.0 allows remote attackers to execute arbitrary SQL commands ...
Jan 30, 2025This critical SQL injection vulnerability in 1000 Projects Employee Task Management System 1.0 allows remote attackers to execute arbitrary SQL comman...
Jan 30, 2025CVE-2025-0843 is a critical SQL injection vulnerability in the needyamin Library Card System 1.0 admin panel. Attackers can exploit this by manipulati...
Jan 29, 2025This critical SQL injection vulnerability in needyamin Library Card System 1.0 allows attackers to bypass authentication and potentially execute arbit...
Jan 29, 2025A critical SQL injection vulnerability in Codezips Gym Management System 1.0 allows attackers to manipulate database queries through the planid parame...
Jan 29, 2025This critical SQL injection vulnerability in Shiprocket Module for OpenCart allows remote attackers to execute arbitrary SQL commands via the x-userna...
Jan 20, 2025CVE-2025-0565 is a critical SQL injection vulnerability in ZZCMS 2023 that allows remote attackers to execute arbitrary SQL commands via the 'id' para...
Jan 19, 2025CVE-2025-0564 is a critical SQL injection vulnerability in Fantasy-Cricket 1.0's authentication component that allows remote attackers to execute arbi...
Jan 19, 2025This critical SQL injection vulnerability in the 1000 Projects Campaign Management System Platform for Women 1.0 allows attackers to execute arbitrary...
Jan 17, 2025This critical SQL injection vulnerability in the 1000 Projects Campaign Management System Platform for Women 1.0 allows remote attackers to execute ar...
Jan 17, 2025This critical vulnerability in code-projects Admission Management System 1.0 allows remote attackers to execute SQL injection via the in_eml parameter...
Jan 17, 2025This critical SQL injection vulnerability in Cinema Seat Reservation System 1.0 allows attackers to execute arbitrary SQL commands via the 'id' parame...
Jan 9, 2025This critical vulnerability allows remote attackers to execute arbitrary commands on KaiYuanTong ECT Platform servers through command injection in the...
Jan 9, 2025This critical SQL injection vulnerability in Codezips Project Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
Jan 5, 2025This critical SQL injection vulnerability in Campcodes School Faculty Scheduling System 1.0 allows attackers to execute arbitrary SQL commands via the...
Jan 4, 2025This critical SQL injection vulnerability in Online Shoe Store 1.0 allows attackers to manipulate database queries through the password parameter in l...
Jan 4, 2025This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows attackers to manipulate database queries through the username pa...
Dec 31, 2024This critical SQL injection vulnerability in CodeAstro Simple Loan Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Dec 30, 2024This critical SQL injection vulnerability in 1000 Projects Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via...
Dec 29, 2024This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Dec 29, 2024This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands via the jid/limit parameter...
Dec 27, 2024This critical SQL injection vulnerability in Hospital Management System 1.0 allows attackers to execute arbitrary SQL commands through the login page....
Dec 26, 2024A critical SQL injection vulnerability in code-projects Job Recruitment 1.0 allows attackers to manipulate database queries through the fname/lname pa...
Dec 26, 2024This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the cname/u...
Dec 26, 2024This critical SQL injection vulnerability in Daily College Class Work Report Book 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Dec 26, 2024This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL commands via the 'q'...
Dec 26, 2024This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL commands via the 'q'...
Dec 26, 2024A critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands via the email/pass parameter...
Dec 26, 2024This critical SQL injection vulnerability in CodeAstro House Rental Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Dec 26, 2024This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows attackers to execute arbitrary SQL commands via the admin logi...
Dec 26, 2024This critical SQL injection vulnerability in the Attendance Tracking Management System allows attackers to execute arbitrary SQL commands by manipulat...
Dec 26, 2024This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows attackers to execute arbitrary SQL command...
Dec 25, 2024About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free