CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,231)

CVE-2025-14884
7.2

This CVE describes a command injection vulnerability in the firmware update service of D-Link DIR-605 routers with firmware version 202WWB03. Attacker...

Dec 18, 2025
CVE-2024-56838
7.2

A vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to execute arbitrary code as root via the SCEP client's lack of field validation dur...

Dec 9, 2025
CVE-2024-56839
7.2

A code injection vulnerability in Siemens RUGGEDCOM ROX devices allows attackers to execute arbitrary code as root when Virtual Routing and Forwarding...

Dec 9, 2025
CVE-2024-56840
7.2

A code injection vulnerability in IPsec implementation allows attackers to execute arbitrary code with root privileges on affected Siemens RUGGEDCOM R...

Dec 9, 2025
CVE-2025-14188
7.2

This CVE describes a command injection vulnerability in UGREEN DH2100+ NAS devices that allows remote attackers to execute arbitrary commands on affec...

Dec 7, 2025
CVE-2025-47286
7.2

This vulnerability allows administrators in Combodo iTop to execute arbitrary code on the server by editing the instance configuration. It affects iTo...

Nov 10, 2025
CVE-2025-24364
7.2

Authenticated attackers with admin panel access to vaultwarden can execute arbitrary system commands through a crafted favicon image when using sendma...

Jan 27, 2025
CVE-2025-0528
7.2

This critical vulnerability in Tenda AC8, AC10, and AC18 routers allows remote attackers to execute arbitrary commands via command injection in the HT...

Jan 17, 2025
CVE-2024-50572
7.2

This vulnerability affects multiple Siemens industrial network devices where improper input sanitization allows authenticated remote attackers with ad...

Nov 12, 2024
CVE-2023-46726
7.2

This vulnerability allows authenticated attackers to execute arbitrary code on GLPI servers running PHP 7.4 by exploiting the LDAP server configuratio...

Dec 13, 2023
CVE-2023-37897
7.2

Grav CMS versions 1.7.42 and later contain a server-side template injection vulnerability due to an incorrect security check that allows bypassing fun...

Jul 18, 2023
CVE-2023-33234
7.2

This vulnerability in Apache Airflow's CNCF Kubernetes provider allows authenticated users with elevated permissions (Operator or Admin roles) to modi...

May 30, 2023
CVE-2023-32679
7.2

This vulnerability in Craft CMS allows attackers with admin privileges to execute arbitrary code by uploading files with arbitrary extensions that get...

May 19, 2023
CVE-2023-22621
7.2

CVE-2023-22621 is a Server-Side Template Injection vulnerability in Strapi that allows authenticated attackers with admin panel access to execute arbi...

Apr 19, 2023
CVE-2023-26919
7.2

This vulnerability allows attackers to escape the JavaScript sandbox in delight-nashorn-sandbox versions 0.2.4 and 0.2.5, enabling them to invoke exit...

Apr 10, 2023
CVE-2022-21705
7.2

This CVE allows authenticated users with page management permissions in OctoberCMS to bypass safe mode restrictions and execute arbitrary code through...

Feb 23, 2022
CVE-2021-35450
7.2

CVE-2021-35450 is a Server-Side Template Injection vulnerability in Entando Admin Console that allows authenticated users with administrative privileg...

Aug 2, 2021
CVE-2020-14987
7.2

This vulnerability allows remote attackers to execute arbitrary code on Bloomreach Experience Manager (brXM) systems by exploiting a flaw in the Groov...

Mar 11, 2021
CVE-2021-21263
7.2

CVE-2021-21263 is a query binding vulnerability in Laravel and illuminate/database packages where unexpected array inputs can manipulate SQL queries. ...

Jan 19, 2021
CVE-2020-12736
7.2

CVE-2020-12736 is a server-side template injection vulnerability in Code42 on-premises servers that allows remote code execution. When administrators ...

Jul 7, 2020
CVE-2023-7114
7.1

Mattermost versions 2.10.0 and earlier contain a CSRF vulnerability due to improper sanitization of deeplink paths. This allows attackers to trick aut...

Dec 29, 2023
CVE-2023-6458
7.1

Mattermost web applications fail to properly validate route parameters in the team/channel URL path, allowing attackers to perform client-side path tr...

Dec 6, 2023
CVE-2021-45656
7.1

This CVE describes a server-side injection vulnerability in multiple NETGEAR router and WiFi system models, allowing attackers to execute arbitrary co...

Dec 26, 2021
CVE-2021-45658
7.1

This CVE describes a server-side injection vulnerability affecting multiple NETGEAR routers, extenders, and WiFi systems. Attackers can inject malicio...

Dec 26, 2021
CVE-2021-45660
7.1

This CVE describes a server-side injection vulnerability in certain NETGEAR Orbi WiFi systems. It allows attackers to inject malicious code that could...

Dec 26, 2021
CVE-2021-21381
7.1

Flatpak's file forwarding feature contains a vulnerability where malicious app publishers can embed special tokens (@@ or @@u) in .desktop files to tr...

Mar 11, 2021
CVE-2020-15238
7.1

CVE-2020-15238 is an argument injection vulnerability in Blueman's D-Bus interface that allows local attackers to execute arbitrary commands with elev...

Oct 27, 2020
CVE-2020-27212
7.0

This vulnerability allows attackers to bypass flash read-out protection on STM32L4 microcontrollers by injecting a fault during boot. It enables unaut...

May 21, 2021
CVE-2025-27794
6.8

This CVE describes a session hijacking vulnerability in Flarum forum software where an attacker controlling any subdomain under a parent domain can se...

Mar 12, 2025
CVE-2026-27022
6.5

A query injection vulnerability in @langchain/langgraph-checkpoint-redis allows attackers to manipulate RediSearch queries by injecting special syntax...

Feb 20, 2026
CVE-2025-20283
6.5

This vulnerability in Cisco ISE and ISE-PIC allows authenticated attackers with high-privileged credentials to execute arbitrary code as root on the u...

Jul 16, 2025
CVE-2025-20256
6.5

This vulnerability allows authenticated administrators on Cisco Secure Network Analytics Manager and Virtual Manager to execute arbitrary commands as ...

May 21, 2025
CVE-2024-38700
6.5

This vulnerability allows attackers to inject and execute arbitrary shortcodes in the WPCS WordPress Currency Switcher Professional plugin. Attackers ...

Jul 12, 2024
CVE-2026-3813
6.3

This CVE describes an injection vulnerability in opencc JFlow's Calculate function that allows remote attackers to execute malicious code or commands....

Mar 9, 2026
CVE-2026-3793
6.3

This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows attackers to manipulate database queries through the 'sellid'...

Mar 9, 2026
CVE-2026-3790
6.3

This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows remote attackers to execute arbitrary SQL commands via the st...

Mar 9, 2026
CVE-2026-3786
6.3

This SQL injection vulnerability in EasyCMS allows attackers to manipulate database queries through the _order parameter in RbacuserAction.class.php. ...

Mar 8, 2026
CVE-2026-3771
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against the Janobe Resort Reservation System 1.0 by manipulating the 'q' p...

Mar 8, 2026
CVE-2026-3767
6.3

This CVE describes a SQL injection vulnerability in itsourcecode's 'sanitize or validate this input 1.0' software. Attackers can exploit the teacher_i...

Mar 8, 2026
CVE-2026-3754
6.3

This SQL injection vulnerability in SourceCodester Sales and Inventory System 1.0 allows attackers to manipulate database queries via the 'cost' param...

Mar 8, 2026
CVE-2026-3756
6.3

This CVE describes a SQL injection vulnerability in SourceCodester Sales and Inventory System version 1.0. Attackers can exploit the 'stock_name1' par...

Mar 8, 2026
CVE-2026-3745
6.3

CVE-2026-3745 is an SQL injection vulnerability in code-projects Student Web Portal 1.0 that allows remote attackers to execute arbitrary SQL commands...

Mar 8, 2026
CVE-2026-3672
6.3

This SQL injection vulnerability in JeecgBoot allows attackers to execute arbitrary SQL commands through the isExistSqlInjectKeyword function in the /...

Mar 7, 2026
CVE-2026-3616
6.3

This CVE describes a SQL injection vulnerability in DefaultFuction Jeson Customer Relationship Management System 1.0.0 that allows remote attackers to...

Mar 6, 2026
CVE-2026-3484
6.3

This CVE describes a command injection vulnerability in PhialsBasement's nmap-mcp-server that allows attackers to execute arbitrary commands on the sy...

Mar 3, 2026
CVE-2026-3149
6.3

CVE-2026-3149 is a SQL injection vulnerability in itsourcecode College Management System 1.0 that allows remote attackers to execute arbitrary SQL com...

Feb 25, 2026
CVE-2026-3066
6.3

This CVE describes a command injection vulnerability in HummerRisk's Cloud Compliance Scanning component. Attackers can execute arbitrary commands on ...

Feb 24, 2026
CVE-2026-3064
6.3

This vulnerability allows remote attackers to execute arbitrary commands on HummerRisk systems by injecting malicious input into the regionId paramete...

Feb 24, 2026
CVE-2026-2956
6.3

This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of qinming99 dst-admin. The command in...

Feb 22, 2026
CVE-2026-2954
6.3

This vulnerability allows remote attackers to perform injection attacks via manipulated driverClassName/url parameters in Dromara UJCMS's importChanel...

Feb 22, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free