CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,231)
This CVE describes a command injection vulnerability in the firmware update service of D-Link DIR-605 routers with firmware version 202WWB03. Attacker...
Dec 18, 2025A vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to execute arbitrary code as root via the SCEP client's lack of field validation dur...
Dec 9, 2025A code injection vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to execute arbitrary code as root when Virtual Routing and Forwarding...
Dec 9, 2025A code injection vulnerability in IPsec implementation allows attackers to execute arbitrary code with root privileges on affected Siemens RUGGEDCOM R...
Dec 9, 2025This CVE describes a command injection vulnerability in UGREEN DH2100+ NAS devices that allows remote attackers to execute arbitrary commands on affec...
Dec 7, 2025This vulnerability allows administrators in Combodo iTop to execute arbitrary code on the server by editing the instance configuration. It affects iTo...
Nov 10, 2025Authenticated attackers with admin panel access to vaultwarden can execute arbitrary system commands through a crafted favicon image when using sendma...
Jan 27, 2025This critical vulnerability in Tenda AC8, AC10, and AC18 routers allows remote attackers to execute arbitrary commands via command injection in the HT...
Jan 17, 2025This vulnerability affects multiple Siemens industrial network devices where improper input sanitization allows authenticated remote attackers with ad...
Nov 12, 2024This vulnerability allows authenticated attackers to execute arbitrary code on GLPI servers running PHP 7.4 by exploiting the LDAP server configuratio...
Dec 13, 2023Grav CMS versions 1.7.42 and later contain a server-side template injection vulnerability due to an incorrect security check that allows bypassing fun...
Jul 18, 2023This vulnerability in Apache Airflow's CNCF Kubernetes provider allows authenticated users with elevated permissions (Operator or Admin roles) to modi...
May 30, 2023This vulnerability in Craft CMS allows attackers with admin privileges to execute arbitrary code by uploading files with arbitrary extensions that get...
May 19, 2023CVE-2023-22621 is a Server-Side Template Injection vulnerability in Strapi that allows authenticated attackers with admin panel access to execute arbi...
Apr 19, 2023This vulnerability allows attackers to escape the JavaScript sandbox in delight-nashorn-sandbox versions 0.2.4 and 0.2.5, enabling them to invoke exit...
Apr 10, 2023This CVE allows authenticated users with page management permissions in OctoberCMS to bypass safe mode restrictions and execute arbitrary code through...
Feb 23, 2022CVE-2021-35450 is a Server-Side Template Injection vulnerability in Entando Admin Console that allows authenticated users with administrative privileg...
Aug 2, 2021This vulnerability allows remote attackers to execute arbitrary code on Bloomreach Experience Manager (brXM) systems by exploiting a flaw in the Groov...
Mar 11, 2021CVE-2021-21263 is a query binding vulnerability in Laravel and illuminate/database packages where unexpected array inputs can manipulate SQL queries. ...
Jan 19, 2021CVE-2020-12736 is a server-side template injection vulnerability in Code42 on-premises servers that allows remote code execution. When administrators ...
Jul 7, 2020Mattermost versions 2.10.0 and earlier contain a CSRF vulnerability due to improper sanitization of deeplink paths. This allows attackers to trick aut...
Dec 29, 2023Mattermost web applications fail to properly validate route parameters in the team/channel URL path, allowing attackers to perform client-side path tr...
Dec 6, 2023This CVE describes a server-side injection vulnerability in multiple NETGEAR router and WiFi system models, allowing attackers to execute arbitrary co...
Dec 26, 2021This CVE describes a server-side injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Attackers can inject malicio...
Dec 26, 2021This CVE describes a server-side injection vulnerability in certain NETGEAR Orbi WiFi systems. It allows attackers to inject malicious code that could...
Dec 26, 2021Flatpak's file forwarding feature contains a vulnerability where malicious app publishers can embed special tokens (@@ or @@u) in .desktop files to tr...
Mar 11, 2021CVE-2020-15238 is an argument injection vulnerability in Blueman's D-Bus interface that allows local attackers to execute arbitrary commands with elev...
Oct 27, 2020This vulnerability allows attackers to bypass flash read-out protection on STM32L4 microcontrollers by injecting a fault during boot. It enables unaut...
May 21, 2021This CVE describes a session hijacking vulnerability in Flarum forum software where an attacker controlling any subdomain under a parent domain can se...
Mar 12, 2025A query injection vulnerability in @langchain/langgraph-checkpoint-redis allows attackers to manipulate RediSearch queries by injecting special syntax...
Feb 20, 2026This vulnerability in Cisco ISE and ISE-PIC allows authenticated attackers with high-privileged credentials to execute arbitrary code as root on the u...
Jul 16, 2025This vulnerability allows authenticated administrators on Cisco Secure Network Analytics Manager and Virtual Manager to execute arbitrary commands as ...
May 21, 2025This vulnerability allows attackers to inject and execute arbitrary shortcodes in the WPCS WordPress Currency Switcher Professional plugin. Attackers ...
Jul 12, 2024This CVE describes an injection vulnerability in opencc JFlow's Calculate function that allows remote attackers to execute malicious code or commands....
Mar 9, 2026This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows attackers to manipulate database queries through the 'sellid'...
Mar 9, 2026This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the st...
Mar 9, 2026This SQL injection vulnerability in EasyCMS allows attackers to manipulate database queries through the _order parameter in RbacuserAction.class.php. ...
Mar 8, 2026This vulnerability allows remote attackers to execute SQL injection attacks against the Janobe Resort Reservation System 1.0 by manipulating the 'q' p...
Mar 8, 2026This CVE describes a SQL injection vulnerability in itsourcecode's 'sanitize or validate this input 1.0' software. Attackers can exploit the teacher_i...
Mar 8, 2026This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows attackers to manipulate database queries via the 'cost' param...
Mar 8, 2026This CVE describes a SQL injection vulnerability in SourceCodester Sales and Inventory System version 1.0. Attackers can exploit the 'stock_name1' par...
Mar 8, 2026CVE-2026-3745 is an SQL injection vulnerability in code-projects Student Web Portal 1.0 that allows remote attackers to execute arbitrary SQL commands...
Mar 8, 2026This SQL injection vulnerability in JeecgBoot allows attackers to execute arbitrary SQL commands through the isExistSqlInjectKeyword function in the /...
Mar 7, 2026This CVE describes a SQL injection vulnerability in DefaultFuction Jeson Customer Relationship Management System 1.0.0 that allows remote attackers to...
Mar 6, 2026This CVE describes a command injection vulnerability in PhialsBasement's nmap-mcp-server that allows attackers to execute arbitrary commands on the sy...
Mar 3, 2026CVE-2026-3149 is a SQL injection vulnerability in itsourcecode College Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Feb 25, 2026This CVE describes a command injection vulnerability in HummerRisk's Cloud Compliance Scanning component. Attackers can execute arbitrary commands on ...
Feb 24, 2026This vulnerability allows remote attackers to execute arbitrary commands on HummerRisk systems by injecting malicious input into the regionId paramete...
Feb 24, 2026This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of qinming99 dst-admin. The command in...
Feb 22, 2026This vulnerability allows remote attackers to perform injection attacks via manipulated driverClassName/url parameters in Dromara UJCMS's importChanel...
Feb 22, 2026About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free