CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,231)

CVE-2024-12899
7.3

This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System 1.0 allows remote attackers to execute arbitrary ...

Dec 23, 2024
CVE-2024-12884
7.3

This critical SQL injection vulnerability in Codezips E-Commerce Website 1.0 allows remote attackers to manipulate the email parameter in /login.php, ...

Dec 21, 2024
CVE-2024-12791
7.3

This critical SQL injection vulnerability in Codezips E-Commerce Site 1.0 allows attackers to manipulate database queries through the email parameter ...

Dec 19, 2024
CVE-2024-12788
7.3

CVE-2024-12788 is a critical SQL injection vulnerability in Codezips Technical Discussion Forum 1.0 that allows remote attackers to execute arbitrary ...

Dec 19, 2024
CVE-2024-12787
7.3

This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows attackers to execute arbitrary SQL command...

Dec 19, 2024
CVE-2024-12497
7.3

This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System 1.0 allows attackers to manipulate database queri...

Dec 12, 2024
CVE-2024-12484
7.3

This critical SQL injection vulnerability in Codezips Technical Discussion Forum 1.0 allows attackers to manipulate database queries through the Usern...

Dec 12, 2024
CVE-2024-12231
7.3

This critical SQL injection vulnerability in CodeZips Project Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Dec 5, 2024
CVE-2024-12229
7.3

This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands through the...

Dec 5, 2024
CVE-2024-12228
7.3

This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows attackers to manipulate database queries through the se...

Dec 5, 2024
CVE-2024-12188
7.3

This critical SQL injection vulnerability in 1000 Projects Library Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Dec 5, 2024
CVE-2024-11970
7.3

This critical SQL injection vulnerability in Concert Ticket Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'mai...

Nov 28, 2024
CVE-2024-11967
7.3

This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Nov 28, 2024
CVE-2024-11965
7.3

This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Nov 28, 2024
CVE-2024-11962
7.3

This critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands through the uname paramet...

Nov 28, 2024
CVE-2024-11818
7.3

This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System 1.0 allows remote attackers to execute ar...

Nov 27, 2024
CVE-2024-11744
7.3

This critical SQL injection vulnerability in 1000 Projects Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL comman...

Nov 26, 2024
CVE-2024-11663
7.3

A critical SQL injection vulnerability in Codezips E-Commerce Site 1.0 allows attackers to execute arbitrary SQL commands via the keywords parameter i...

Nov 25, 2024
CVE-2024-11648
7.3

This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'n...

Nov 25, 2024
CVE-2024-11632
7.3

This critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands by manipulating parameter...

Nov 23, 2024
CVE-2024-11592
7.3

This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the pa...

Nov 21, 2024
CVE-2024-11591
7.3

This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 's...

Nov 21, 2024
CVE-2024-11590
7.3

This critical SQL injection vulnerability in Bookstore Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'unm' paramete...

Nov 21, 2024
CVE-2024-11257
7.3

This critical SQL injection vulnerability in the Beauty Parlour Management System 1.0 allows attackers to manipulate database queries via the email pa...

Nov 15, 2024
CVE-2024-11241
7.3

This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands via the 'e' parameter in re...

Nov 15, 2024
CVE-2024-11100
7.3

This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'n...

Nov 12, 2024
CVE-2024-11099
7.3

This critical SQL injection vulnerability in Job Recruitment 1.0 allows attackers to manipulate database queries through the email parameter in /login...

Nov 12, 2024
CVE-2024-11077
7.3

This critical SQL injection vulnerability in Job Recruitment 1.0 allows attackers to manipulate database queries through the email parameter in /index...

Nov 11, 2024
CVE-2024-10998
7.3

This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Nov 8, 2024
CVE-2024-10995
7.3

CVE-2024-10995 is a critical SQL injection vulnerability in Codezips Hospital Appointment System 1.0 that allows remote attackers to execute arbitrary...

Nov 8, 2024
CVE-2024-10991
7.3

This critical SQL injection vulnerability in Codezips Hospital Appointment System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Nov 8, 2024
CVE-2024-10988
7.3

This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands via the email paramete...

Nov 8, 2024
CVE-2024-10969
7.3

This critical SQL injection vulnerability in the Bookstore Management System 1.0 allows attackers to manipulate login credentials to execute arbitrary...

Nov 7, 2024
CVE-2024-10967
7.3

This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'i...

Nov 7, 2024
CVE-2024-50340
7.3

This vulnerability in Symfony's runtime component allows attackers to manipulate the application's environment or debug mode by sending specially craf...

Nov 6, 2024
CVE-2024-10844
7.3

This critical SQL injection vulnerability in Bookstore Management System 1.0 allows attackers to execute arbitrary SQL commands through the search.php...

Nov 5, 2024
CVE-2024-10791
7.3

A critical SQL injection vulnerability exists in Codezips Hospital Appointment System 1.0 through the /doctorAction.php file's Name parameter. This al...

Nov 4, 2024
CVE-2024-10752
7.3

This critical SQL injection vulnerability in Codezips Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Nov 4, 2024
CVE-2024-7219
7.3

This CVE describes an SQL injection vulnerability in the School Log Management System 1.0 by SourceCodester/Campcodes. Attackers can exploit the login...

Jul 30, 2024
CVE-2023-51664
7.3

CVE-2023-51664 is a command injection vulnerability in the tj-actions/changed-files GitHub Action that allows attackers to execute arbitrary commands ...

Dec 27, 2023
CVE-2023-24539
7.3

This is a cross-site scripting (XSS) vulnerability in Go's html/template package where angle brackets in CSS contexts aren't properly escaped. It affe...

May 11, 2023
CVE-2021-0553
7.3

This vulnerability allows a malicious app to bypass device admin settings through unclear UI in Android's AppSwitchPreference component. It enables lo...

Jun 22, 2021
CVE-2021-29502
7.3

CVE-2021-29502 is an injection vulnerability in the WarnSystem plugin for Red Discord bot that allows any user to access sensitive information by craf...

May 10, 2021
CVE-2021-21261
7.3

This CVE allows malicious or compromised Flatpak applications to escape their sandbox and execute arbitrary code on the host Linux system. The vulnera...

Jan 14, 2021
CVE-2026-3612
7.2

This CVE describes a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on affec...

Mar 6, 2026
CVE-2026-2615
7.2

This CVE-2026-2615 is a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on af...

Feb 17, 2026
CVE-2026-2182
7.2

This vulnerability allows remote attackers to execute arbitrary commands on UTT 进取 521G devices by injecting malicious input into the password par...

Feb 8, 2026
CVE-2026-2118
7.2

This vulnerability allows remote attackers to execute arbitrary commands on UTT HiPER 810 routers by injecting malicious input into the Isp_Name param...

Feb 8, 2026
CVE-2026-2085
7.2

This CVE describes a command injection vulnerability in D-Link DWR-M921 routers via the USSD configuration endpoint. Attackers can execute arbitrary c...

Feb 7, 2026
CVE-2026-2080
7.2

This vulnerability allows remote attackers to execute arbitrary commands on UTT HiPER 810 routers by injecting malicious input into the password param...

Feb 7, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free