CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,231
Total CVEs
124
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,231)

CVE-2026-2824
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Comfast CF-E7 routers via command injection in the web management interfac...

Feb 20, 2026
CVE-2026-2823
6.3

This CVE describes a command injection vulnerability in Comfast CF-E7 routers version 2.6.0.9. Attackers can remotely execute arbitrary commands by ma...

Feb 20, 2026
CVE-2026-2706
6.3

This SQL injection vulnerability in code-projects Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Feb 19, 2026
CVE-2026-2663
6.3

This SQL injection vulnerability in Alixhan xh-admin-backend allows remote attackers to execute arbitrary SQL commands through the /frontend-api/syste...

Feb 18, 2026
CVE-2026-2548
6.3

This vulnerability allows remote attackers to execute arbitrary commands on WAYOS FBM-220G devices by manipulating specific parameters (upnp_waniface/...

Feb 16, 2026
CVE-2026-2535
6.3

This CVE describes a command injection vulnerability in Comfast CF-N1 V2 routers version 2.6.0.2. Attackers can remotely execute arbitrary commands by...

Feb 16, 2026
CVE-2026-2530
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-WN579A3 routers by exploiting command injection in the AddMac f...

Feb 16, 2026
CVE-2026-2529
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-WN579A3 routers by exploiting a command injection flaw in the D...

Feb 16, 2026
CVE-2026-2527
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-WN579A3 routers by manipulating the 'key' parameter in the logi...

Feb 16, 2026
CVE-2026-2218
6.3

This CVE describes a command injection vulnerability in D-Link DCS-933L IP cameras through the /setSystemAdmin endpoint. Attackers can execute arbitra...

Feb 9, 2026
CVE-2026-2194
6.3

This CVE describes a command injection vulnerability in D-Link DI-7100G C1 routers that allows remote attackers to execute arbitrary commands on affec...

Feb 9, 2026
CVE-2026-2193
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DI-7100G routers by injecting malicious input into the usb_username...

Feb 8, 2026
CVE-2026-2178
6.3

This CVE describes a command injection vulnerability in r-huijts xcode-mcp-server that allows remote attackers to execute arbitrary commands on affect...

Feb 8, 2026
CVE-2026-2176
6.3

This SQL injection vulnerability in code-projects Contact Management System 1.0 allows remote attackers to execute arbitrary SQL commands by manipulat...

Feb 8, 2026
CVE-2026-2168
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DWR-M921 routers by manipulating the fota_url parameter in the firm...

Feb 8, 2026
CVE-2026-2169
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DWR-M921 routers by injecting malicious commands into the fota_url ...

Feb 8, 2026
CVE-2026-2135
6.3

This vulnerability allows remote attackers to execute arbitrary commands on UTT HiPER 810 routers by injecting malicious input into the policyNames pa...

Feb 8, 2026
CVE-2026-2130
6.3

This CVE describes a command injection vulnerability in BurtTheCoder's mcp-maigret tool up to version 1.0.12. Attackers can execute arbitrary commands...

Feb 8, 2026
CVE-2026-2122
6.3

This SQL injection vulnerability in Xiaopi Panel's WAF Firewall component allows attackers to execute arbitrary SQL commands through the /demo.php end...

Feb 8, 2026
CVE-2026-2008
6.3

This CVE describes a code injection vulnerability in the abhiphile fermat-mcp project's eqn_chart function. Attackers can remotely exploit this by man...

Feb 6, 2026
CVE-2026-1977
6.3

This CVE describes a code injection vulnerability in the mcp-vegalite-server component that allows remote attackers to execute arbitrary code by manip...

Feb 6, 2026
CVE-2026-1746
6.3

This SQL injection vulnerability in JeecgBoot 3.9.0 allows remote attackers to execute arbitrary SQL commands through the Online Report API's loadDict...

Feb 2, 2026
CVE-2026-1638
6.3

This CVE describes a remote command injection vulnerability in Tenda AC21 routers. Attackers can execute arbitrary commands on affected devices by man...

Jan 30, 2026
CVE-2026-1625
6.3

This CVE describes a command injection vulnerability in D-Link DWR-M961 routers that allows remote attackers to execute arbitrary commands on affected...

Jan 29, 2026
CVE-2026-1624
6.3

This CVE describes a command injection vulnerability in D-Link DWR-M961 routers that allows remote attackers to execute arbitrary commands by manipula...

Jan 29, 2026
CVE-2026-1623
6.3

This CVE describes a remote command injection vulnerability in Totolink A7000R routers. Attackers can execute arbitrary commands by manipulating the F...

Jan 29, 2026
CVE-2026-1601
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Totolink A7000R routers by exploiting a command injection flaw in the setU...

Jan 29, 2026
CVE-2026-1596
6.3

This CVE describes a remote command injection vulnerability in D-Link DWR-M961 routers. Attackers can execute arbitrary commands on affected devices b...

Jan 29, 2026
CVE-2026-1552
6.3

This SQL injection vulnerability in SEMCMS 5.0 allows attackers to manipulate database queries through the searchml parameter in /SEMCMS_Info.php. Att...

Jan 29, 2026
CVE-2026-1551
6.3

CVE-2026-1551 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...

Jan 29, 2026
CVE-2026-1548
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Totolink A7000R routers by injecting malicious commands into the 'url' par...

Jan 28, 2026
CVE-2026-1546
6.3

This SQL injection vulnerability in jishenghua jshERP allows remote attackers to execute arbitrary SQL commands through the barCodes parameter in the ...

Jan 28, 2026
CVE-2026-1547
6.3

This CVE describes a remote command injection vulnerability in Totolink A7000R routers. Attackers can execute arbitrary commands on affected devices b...

Jan 28, 2026
CVE-2026-1414
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Sangfor Operation and Maintenance Security Management System installations...

Jan 26, 2026
CVE-2026-1413
6.3

This CVE describes a command injection vulnerability in Sangfor Operation and Maintenance Security Management System that allows remote attackers to e...

Jan 26, 2026
CVE-2026-1326
6.3

This CVE describes a command injection vulnerability in Totolink NR1800X routers that allows remote attackers to execute arbitrary commands on affecte...

Jan 22, 2026
CVE-2026-1327
6.3

This CVE describes a remote command injection vulnerability in Totolink NR1800X routers. Attackers can execute arbitrary commands on affected devices ...

Jan 22, 2026
CVE-2026-1118
6.3

This CVE describes a SQL injection vulnerability in itsourcecode Society Management System 1.0, specifically in the /admin/add_activity.php file's Tit...

Jan 18, 2026
CVE-2026-1066
6.3

This vulnerability allows remote attackers to execute arbitrary commands on systems running vulnerable versions of kalcaddle kodbox. The command injec...

Jan 17, 2026
CVE-2026-0843
6.3

This SQL injection vulnerability in jjjfood and jjjshop_food systems allows attackers to manipulate database queries via the latitude parameter in the...

Jan 11, 2026
CVE-2025-15494
6.3

This SQL injection vulnerability in RainyGao DocSys allows attackers to manipulate database queries via the Username parameter. Remote attackers can p...

Jan 9, 2026
CVE-2025-15496
6.3

This SQL injection vulnerability in guchengwuyue yshopmall allows attackers to manipulate database queries through the 'sort' parameter in the /api/jo...

Jan 9, 2026
CVE-2025-15493
6.3

This CVE describes a SQL injection vulnerability in RainyGao DocSys document management system up to version 2.02.36. Attackers can exploit this remot...

Jan 9, 2026
CVE-2026-0803
6.3

This CVE describes a SQL injection vulnerability in PHPGurukul Online Course Registration System that allows attackers to manipulate database queries ...

Jan 9, 2026
CVE-2025-15492
6.3

This CVE describes a SQL injection vulnerability in RainyGao DocSys up to version 2.02.36. Attackers can remotely exploit this by manipulating the sea...

Jan 9, 2026
CVE-2026-0641
6.3

This CVE describes a command injection vulnerability in TOTOLINK WA300 routers that allows remote attackers to execute arbitrary commands on affected ...

Jan 6, 2026
CVE-2026-0584
6.3

CVE-2026-0584 is a SQL injection vulnerability in code-projects Online Product Reservation System 1.0 that allows attackers to execute arbitrary SQL c...

Jan 5, 2026
CVE-2026-0582
6.3

CVE-2026-0582 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to manipulate database queries thr...

Jan 5, 2026
CVE-2026-0581
6.3

This CVE describes a command injection vulnerability in Tenda AC1206 routers that allows remote attackers to execute arbitrary commands on affected de...

Jan 5, 2026
CVE-2025-15450
6.3

This CVE describes a SQL injection vulnerability in the sfturing hosp_order software's findOrderHosNum function. Attackers can exploit this by manipul...

Jan 5, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,231 CVEs classified as CWE-74, with 124 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free