CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,231)

CVE-2025-1952
7.3

This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows remote attackers to execute arbitrary SQL commands ...

Mar 4, 2025
CVE-2025-1901
7.3

This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to manipulate database queries through th...

Mar 4, 2025
CVE-2025-1903
7.3

CVE-2025-1903 is a critical SQL injection vulnerability in Codezips Online Shopping Website 1.0 that allows remote attackers to execute arbitrary SQL ...

Mar 4, 2025
CVE-2025-1894
7.3

This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to execute arbitrary SQL commands via the...

Mar 4, 2025
CVE-2025-1859
7.3

A critical SQL injection vulnerability exists in PHPGurukul News Portal 4.1's login.php file, allowing attackers to manipulate database queries via th...

Mar 3, 2025
CVE-2025-1857
7.3

A critical SQL injection vulnerability exists in PHPGurukul Nipah Virus Testing Management System 1.0, specifically in the /check_availability.php fil...

Mar 3, 2025
CVE-2025-1840
7.3

This critical SQL injection vulnerability in ESAFENET CDG allows remote attackers to execute arbitrary SQL commands by manipulating the flowId paramet...

Mar 3, 2025
CVE-2025-1811
7.3

This critical SQL injection vulnerability in AT Software Solutions ATSVD allows attackers to execute arbitrary SQL commands via the txtUsuario paramet...

Mar 2, 2025
CVE-2025-1809
7.3

This critical SQL injection vulnerability in Pixsoft Sol allows attackers to execute arbitrary SQL commands via the txtUsuario parameter in the login ...

Mar 2, 2025
CVE-2025-1808
7.3

This critical SQL injection vulnerability in Pixsoft E-Saphira 1.7.24 allows attackers to manipulate database queries through the login endpoint. Remo...

Mar 2, 2025
CVE-2025-1640
7.3

This critical SQL injection vulnerability in Benner ModernaNet allows attackers to execute arbitrary SQL commands through the /Home/JS_CarregaCombo en...

Feb 25, 2025
CVE-2025-1641
7.3

This critical SQL injection vulnerability in Benner ModernaNet allows remote attackers to execute arbitrary SQL commands through the /AGE0000700/GetHo...

Feb 25, 2025
CVE-2025-1535
7.3

This critical SQL injection vulnerability in Baiyi Cloud Asset Management System allows remote attackers to execute arbitrary SQL commands by manipula...

Feb 21, 2025
CVE-2025-1464
7.3

This critical SQL injection vulnerability in Baiyi Cloud Asset Management System allows remote attackers to execute arbitrary SQL commands via the pro...

Feb 19, 2025
CVE-2025-1448
7.3

This critical vulnerability in Synway SMG Gateway Management Software allows remote attackers to execute arbitrary commands via command injection in t...

Feb 19, 2025
CVE-2025-1338
7.3

This critical vulnerability in NUUO Camera software allows remote attackers to execute arbitrary commands on affected systems through command injectio...

Feb 16, 2025
CVE-2025-1117
7.3

This critical SQL injection vulnerability in CoinRemitter OpenCart plugin allows remote attackers to execute arbitrary SQL commands by manipulating th...

Feb 8, 2025
CVE-2025-1116
7.3

This critical SQL injection vulnerability in Dreamvention Live AJAX Search Free for OpenCart allows remote attackers to execute arbitrary SQL commands...

Feb 8, 2025
CVE-2025-0847
7.3

A critical SQL injection vulnerability in 1000 Projects Employee Task Management System 1.0 allows remote attackers to execute arbitrary SQL commands ...

Jan 30, 2025
CVE-2025-0846
7.3

This critical SQL injection vulnerability in 1000 Projects Employee Task Management System 1.0 allows remote attackers to execute arbitrary SQL comman...

Jan 30, 2025
CVE-2025-0843
7.3

CVE-2025-0843 is a critical SQL injection vulnerability in the needyamin Library Card System 1.0 admin panel. Attackers can exploit this by manipulati...

Jan 29, 2025
CVE-2025-0842
7.3

This critical SQL injection vulnerability in needyamin Library Card System 1.0 allows attackers to bypass authentication and potentially execute arbit...

Jan 29, 2025
CVE-2025-0803
7.3

A critical SQL injection vulnerability in Codezips Gym Management System 1.0 allows attackers to manipulate database queries through the planid parame...

Jan 29, 2025
CVE-2025-0579
7.3

This critical SQL injection vulnerability in Shiprocket Module for OpenCart allows remote attackers to execute arbitrary SQL commands via the x-userna...

Jan 20, 2025
CVE-2025-0565
7.3

CVE-2025-0565 is a critical SQL injection vulnerability in ZZCMS 2023 that allows remote attackers to execute arbitrary SQL commands via the 'id' para...

Jan 19, 2025
CVE-2025-0564
7.3

CVE-2025-0564 is a critical SQL injection vulnerability in Fantasy-Cricket 1.0's authentication component that allows remote attackers to execute arbi...

Jan 19, 2025
CVE-2025-0534
7.3

This critical SQL injection vulnerability in the 1000 Projects Campaign Management System Platform for Women 1.0 allows attackers to execute arbitrary...

Jan 17, 2025
CVE-2025-0533
7.3

This critical SQL injection vulnerability in the 1000 Projects Campaign Management System Platform for Women 1.0 allows remote attackers to execute ar...

Jan 17, 2025
CVE-2025-0527
7.3

This critical vulnerability in code-projects Admission Management System 1.0 allows remote attackers to execute SQL injection via the in_eml parameter...

Jan 17, 2025
CVE-2025-0340
7.3

This critical SQL injection vulnerability in Cinema Seat Reservation System 1.0 allows attackers to execute arbitrary SQL commands via the 'id' parame...

Jan 9, 2025
CVE-2025-0328
7.3

This critical vulnerability allows remote attackers to execute arbitrary commands on KaiYuanTong ECT Platform servers through command injection in the...

Jan 9, 2025
CVE-2025-0233
7.3

This critical SQL injection vulnerability in Codezips Project Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Jan 5, 2025
CVE-2025-0210
7.3

This critical SQL injection vulnerability in Campcodes School Faculty Scheduling System 1.0 allows attackers to execute arbitrary SQL commands via the...

Jan 4, 2025
CVE-2025-0207
7.3

This critical SQL injection vulnerability in Online Shoe Store 1.0 allows attackers to manipulate database queries through the password parameter in l...

Jan 4, 2025
CVE-2024-13085
7.3

This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows attackers to manipulate database queries through the username pa...

Dec 31, 2024
CVE-2024-13038
7.3

This critical SQL injection vulnerability in CodeAstro Simple Loan Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Dec 30, 2024
CVE-2024-13006
7.3

This critical SQL injection vulnerability in 1000 Projects Human Resource Management System 1.0 allows attackers to execute arbitrary SQL commands via...

Dec 29, 2024
CVE-2024-13002
7.3

This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Dec 29, 2024
CVE-2024-12978
7.3

This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands via the jid/limit parameter...

Dec 27, 2024
CVE-2024-12969
7.3

This critical SQL injection vulnerability in Hospital Management System 1.0 allows attackers to execute arbitrary SQL commands through the login page....

Dec 26, 2024
CVE-2024-12967
7.3

A critical SQL injection vulnerability in code-projects Job Recruitment 1.0 allows attackers to manipulate database queries through the fname/lname pa...

Dec 26, 2024
CVE-2024-12966
7.3

This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the cname/u...

Dec 26, 2024
CVE-2024-12964
7.3

This critical SQL injection vulnerability in Daily College Class Work Report Book 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Dec 26, 2024
CVE-2024-12961
7.3

This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL commands via the 'q'...

Dec 26, 2024
CVE-2024-12958
7.3

This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL commands via the 'q'...

Dec 26, 2024
CVE-2024-12945
7.3

A critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands via the email/pass parameter...

Dec 26, 2024
CVE-2024-12943
7.3

This critical SQL injection vulnerability in CodeAstro House Rental Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Dec 26, 2024
CVE-2024-12942
7.3

This critical SQL injection vulnerability in Portfolio Management System MCA 1.0 allows attackers to execute arbitrary SQL commands via the admin logi...

Dec 26, 2024
CVE-2024-12940
7.3

This critical SQL injection vulnerability in the Attendance Tracking Management System allows attackers to execute arbitrary SQL commands by manipulat...

Dec 26, 2024
CVE-2024-12927
7.3

This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows attackers to execute arbitrary SQL command...

Dec 25, 2024

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free