CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,231)
This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System 1.0 allows remote attackers to execute arbitrary ...
Dec 23, 2024This critical SQL injection vulnerability in Codezips E-Commerce Website 1.0 allows remote attackers to manipulate the email parameter in /login.php, ...
Dec 21, 2024This critical SQL injection vulnerability in Codezips E-Commerce Site 1.0 allows attackers to manipulate database queries through the email parameter ...
Dec 19, 2024CVE-2024-12788 is a critical SQL injection vulnerability in Codezips Technical Discussion Forum 1.0 that allows remote attackers to execute arbitrary ...
Dec 19, 2024This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows attackers to execute arbitrary SQL command...
Dec 19, 2024This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System 1.0 allows attackers to manipulate database queri...
Dec 12, 2024This critical SQL injection vulnerability in Codezips Technical Discussion Forum 1.0 allows attackers to manipulate database queries through the Usern...
Dec 12, 2024This critical SQL injection vulnerability in CodeZips Project Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
Dec 5, 2024This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows attackers to execute arbitrary SQL commands through the...
Dec 5, 2024This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows attackers to manipulate database queries through the se...
Dec 5, 2024This critical SQL injection vulnerability in 1000 Projects Library Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Dec 5, 2024This critical SQL injection vulnerability in Concert Ticket Ordering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'mai...
Nov 28, 2024This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Nov 28, 2024This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Nov 28, 2024This critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands through the uname paramet...
Nov 28, 2024This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System 1.0 allows remote attackers to execute ar...
Nov 27, 2024This critical SQL injection vulnerability in 1000 Projects Portfolio Management System MCA 1.0 allows remote attackers to execute arbitrary SQL comman...
Nov 26, 2024A critical SQL injection vulnerability in Codezips E-Commerce Site 1.0 allows attackers to execute arbitrary SQL commands via the keywords parameter i...
Nov 25, 2024This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'n...
Nov 25, 2024This critical SQL injection vulnerability in Simple Car Rental System 1.0 allows attackers to execute arbitrary SQL commands by manipulating parameter...
Nov 23, 2024This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the pa...
Nov 21, 2024This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 's...
Nov 21, 2024This critical SQL injection vulnerability in Bookstore Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'unm' paramete...
Nov 21, 2024This critical SQL injection vulnerability in the Beauty Parlour Management System 1.0 allows attackers to manipulate database queries via the email pa...
Nov 15, 2024This critical SQL injection vulnerability in Job Recruitment 1.0 allows remote attackers to execute arbitrary SQL commands via the 'e' parameter in re...
Nov 15, 2024This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'n...
Nov 12, 2024This critical SQL injection vulnerability in Job Recruitment 1.0 allows attackers to manipulate database queries through the email parameter in /login...
Nov 12, 2024This critical SQL injection vulnerability in Job Recruitment 1.0 allows attackers to manipulate database queries through the email parameter in /index...
Nov 11, 2024This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Nov 8, 2024CVE-2024-10995 is a critical SQL injection vulnerability in Codezips Hospital Appointment System 1.0 that allows remote attackers to execute arbitrary...
Nov 8, 2024This critical SQL injection vulnerability in Codezips Hospital Appointment System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Nov 8, 2024This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands via the email paramete...
Nov 8, 2024This critical SQL injection vulnerability in the Bookstore Management System 1.0 allows attackers to manipulate login credentials to execute arbitrary...
Nov 7, 2024This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'i...
Nov 7, 2024This vulnerability in Symfony's runtime component allows attackers to manipulate the application's environment or debug mode by sending specially craf...
Nov 6, 2024This critical SQL injection vulnerability in Bookstore Management System 1.0 allows attackers to execute arbitrary SQL commands through the search.php...
Nov 5, 2024A critical SQL injection vulnerability exists in Codezips Hospital Appointment System 1.0 through the /doctorAction.php file's Name parameter. This al...
Nov 4, 2024This critical SQL injection vulnerability in Codezips Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Nov 4, 2024This CVE describes an SQL injection vulnerability in the School Log Management System 1.0 by SourceCodester/Campcodes. Attackers can exploit the login...
Jul 30, 2024CVE-2023-51664 is a command injection vulnerability in the tj-actions/changed-files GitHub Action that allows attackers to execute arbitrary commands ...
Dec 27, 2023This is a cross-site scripting (XSS) vulnerability in Go's html/template package where angle brackets in CSS contexts aren't properly escaped. It affe...
May 11, 2023This vulnerability allows a malicious app to bypass device admin settings through unclear UI in Android's AppSwitchPreference component. It enables lo...
Jun 22, 2021CVE-2021-29502 is an injection vulnerability in the WarnSystem plugin for Red Discord bot that allows any user to access sensitive information by craf...
May 10, 2021This CVE allows malicious or compromised Flatpak applications to escape their sandbox and execute arbitrary code on the host Linux system. The vulnera...
Jan 14, 2021This CVE describes a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on affec...
Mar 6, 2026This CVE-2026-2615 is a command injection vulnerability in Wavlink WL-NU516U1 routers that allows remote attackers to execute arbitrary commands on af...
Feb 17, 2026This vulnerability allows remote attackers to execute arbitrary commands on UTT θΏε 521G devices by injecting malicious input into the password par...
Feb 8, 2026This vulnerability allows remote attackers to execute arbitrary commands on UTT HiPER 810 routers by injecting malicious input into the Isp_Name param...
Feb 8, 2026This CVE describes a command injection vulnerability in D-Link DWR-M921 routers via the USSD configuration endpoint. Attackers can execute arbitrary c...
Feb 7, 2026This vulnerability allows remote attackers to execute arbitrary commands on UTT HiPER 810 routers by injecting malicious input into the password param...
Feb 7, 2026About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free