CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,234
Total CVEs
127
Critical
1,304
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,234)

CVE-2026-0582
6.3

CVE-2026-0582 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to manipulate database queries thr...

Jan 5, 2026
CVE-2026-0581
6.3

This CVE describes a command injection vulnerability in Tenda AC1206 routers that allows remote attackers to execute arbitrary commands on affected de...

Jan 5, 2026
CVE-2025-15450
6.3

This CVE describes a SQL injection vulnerability in the sfturing hosp_order software's findOrderHosNum function. Attackers can exploit this by manipul...

Jan 5, 2026
CVE-2025-15439
6.3

This SQL injection vulnerability in Daptin's Aggregate API allows remote attackers to execute arbitrary SQL commands by manipulating column/group/orde...

Jan 2, 2026
CVE-2025-15393
6.3

This vulnerability allows remote attackers to execute arbitrary code on Kohana KodiCMS systems through code injection in the Layout API Endpoint's Sav...

Dec 31, 2025
CVE-2025-15391
6.3

This CVE describes a remote command injection vulnerability in D-Link DIR-806A routers via the SSDP request handler. Attackers can execute arbitrary c...

Dec 31, 2025
CVE-2025-15392
6.3

This CVE describes a SQL injection vulnerability in Kohana KodiCMS's Search API Endpoint. Attackers can remotely exploit this by manipulating the 'key...

Dec 31, 2025
CVE-2025-15357
6.3

This CVE describes a command injection vulnerability in D-Link DI-7400G+ routers that allows remote attackers to execute arbitrary commands on affecte...

Dec 30, 2025
CVE-2025-15212
6.3

This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the 'a' parameter in /h...

Dec 30, 2025
CVE-2025-15211
6.3

This CVE describes a SQL injection vulnerability in the Refugee Food Management System 1.0. Attackers can manipulate parameters in the /home/refugee.p...

Dec 30, 2025
CVE-2025-15210
6.3

This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the /home/editrefugee.p...

Dec 30, 2025
CVE-2025-15209
6.3

CVE-2025-15209 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows remote attackers to execute arbitrary SQL comman...

Dec 29, 2025
CVE-2025-15205
6.3

CVE-2025-15205 is an SQL injection vulnerability in code-projects Student File Management System 1.0 affecting the /download.php file via the istore_i...

Dec 29, 2025
CVE-2025-15192
6.3

This CVE describes a command injection vulnerability in D-Link DWR-M920 routers that allows remote attackers to execute arbitrary commands by manipula...

Dec 29, 2025
CVE-2025-15191
6.3

This CVE describes a command injection vulnerability in D-Link DWR-M920 routers that allows remote attackers to execute arbitrary commands by manipula...

Dec 29, 2025
CVE-2025-15139
6.3

This CVE describes a command injection vulnerability in TRENDnet TEW-822DRE routers that allows remote attackers to execute arbitrary commands on affe...

Dec 28, 2025
CVE-2025-15133
6.3

This vulnerability allows remote attackers to execute arbitrary commands on ZSPACE Z4Pro+ devices through command injection in the HTTP POST request h...

Dec 28, 2025
CVE-2025-15132
6.3

This CVE describes a command injection vulnerability in ZSPACE Z4Pro+ devices that allows remote attackers to execute arbitrary commands on affected s...

Dec 28, 2025
CVE-2025-15131
6.3

This vulnerability allows remote attackers to execute arbitrary commands on ZSPACE Z4Pro+ devices through command injection in the HTTP POST request h...

Dec 28, 2025
CVE-2025-15129
6.3

This vulnerability allows remote attackers to execute arbitrary code through a file upload manipulation in ChenJinchuang Lin-CMS-TP5. Attackers can ex...

Dec 28, 2025
CVE-2025-15088
6.3

This SQL injection vulnerability in ketr JEPaaS allows attackers to execute arbitrary SQL commands by manipulating the 'keyWord' parameter in the post...

Dec 25, 2025
CVE-2025-15081
6.3

This vulnerability allows remote attackers to execute arbitrary commands on JD Cloud BE6500 routers by exploiting a command injection flaw in the ddns...

Dec 25, 2025
CVE-2025-15014
6.3

This CVE describes a SQL injection vulnerability in the loganhong php loganSite software's article handler component. Attackers can remotely exploit t...

Dec 22, 2025
CVE-2025-15004
6.3

This SQL injection vulnerability in DedeCMS allows attackers to manipulate database queries through the orderby parameter in /freelist_main.php. Attac...

Dec 22, 2025
CVE-2025-14856
6.3

This vulnerability allows remote attackers to execute arbitrary code on RuoYi systems up to version 4.8.1 through code injection in the /monitor/cache...

Dec 18, 2025
CVE-2025-14834
6.3

CVE-2025-14834 is an SQL injection vulnerability in Simple Stock System 1.0 that allows attackers to manipulate database queries via the Username para...

Dec 17, 2025
CVE-2025-14780
6.3

This SQL injection vulnerability in Xiongwei Smart Catering Cloud Platform allows remote attackers to execute arbitrary SQL commands through the filte...

Dec 16, 2025
CVE-2025-14674
6.3

This vulnerability allows remote attackers to execute arbitrary code through injection in the QLExpressEngine.doEval function in aizuda snail-job. Aff...

Dec 14, 2025
CVE-2025-14589
6.3

This CVE describes a SQL injection vulnerability in code-projects Prison Management System 2.0 affecting the /admin/search.php file. Attackers can man...

Dec 13, 2025
CVE-2025-14568
6.3

This CVE describes a SQL injection vulnerability in haxxorsid Stock-Management-System that allows remote attackers to execute arbitrary SQL commands v...

Dec 12, 2025
CVE-2025-14259
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against Jihai Jshop MiniProgram Mall System 2.9.0 by manipulating the cat_...

Dec 8, 2025
CVE-2025-14247
6.3

CVE-2025-14247 is an SQL injection vulnerability in Simple Shopping Cart 1.0's /Admin/additems.php file, allowing remote attackers to manipulate datab...

Dec 8, 2025
CVE-2025-14246
6.3

This SQL injection vulnerability in Simple Shopping Cart 1.0 allows attackers to manipulate database queries through the user_id parameter in /Custome...

Dec 8, 2025
CVE-2025-14230
6.3

This SQL injection vulnerability in Daily Time Recording System 4.5.0 allows attackers to manipulate database queries through the detail_Id parameter ...

Dec 8, 2025
CVE-2025-14227
6.3

This CVE describes a SQL injection vulnerability in Philipinho Simple-PHP-Blog's edit.php file that allows attackers to execute arbitrary SQL commands...

Dec 8, 2025
CVE-2025-14225
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DCS-930L IP cameras via command injection in the /setSystemAdmin en...

Dec 8, 2025
CVE-2025-14222
6.3

CVE-2025-14222 is a SQL injection vulnerability in code-projects Employee Profile Management System 1.0 that allows attackers to manipulate database q...

Dec 8, 2025
CVE-2025-14214
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in /section_edit1.php in itsourcecode Student Inform...

Dec 8, 2025
CVE-2025-14208
6.3

This CVE describes a command injection vulnerability in D-Link DIR-823X routers where attackers can execute arbitrary commands by manipulating the ppp...

Dec 8, 2025
CVE-2025-14203
6.3

This SQL injection vulnerability in code-projects Question Paper Generator allows attackers to manipulate database queries through the 'subid' paramet...

Dec 7, 2025
CVE-2025-14193
6.3

This SQL injection vulnerability in Employee Profile Management System 1.0 allows attackers to manipulate database queries via the per_id parameter in...

Dec 7, 2025
CVE-2025-14185
6.3

This CVE describes a SQL injection vulnerability in Yonyou U8 Cloud enterprise software. Attackers can remotely exploit this by manipulating the 'user...

Dec 7, 2025
CVE-2025-14184
6.3

This vulnerability allows remote attackers to execute arbitrary commands on SGAI Space1 NAS N1211DS devices through command injection in the gsaiagent...

Dec 7, 2025
CVE-2025-13811
6.3

This CVE describes a SQL injection vulnerability in jsnjfz WebStack-Guns 1.0 that allows remote attackers to execute arbitrary SQL commands by manipul...

Dec 1, 2025
CVE-2025-13800
6.3

This vulnerability allows remote attackers to execute arbitrary commands on ADSLR NBR1005GPEV2 routers by injecting malicious input into the 'mac' par...

Dec 1, 2025
CVE-2025-13797
6.3

This CVE describes a command injection vulnerability in the ADSLR B-QE2W401 device's web interface. Attackers can remotely execute arbitrary commands ...

Dec 1, 2025
CVE-2025-13798
6.3

This vulnerability allows remote attackers to execute arbitrary commands on ADSLR NBR1005GPEV2 routers by injecting malicious commands into the 'mac' ...

Dec 1, 2025
CVE-2025-13799
6.3

This vulnerability allows remote attackers to execute arbitrary commands on ADSLR NBR1005GPEV2 routers by injecting malicious input into the 'mac' par...

Dec 1, 2025
CVE-2025-13783
6.3

This CVE describes a SQL injection vulnerability in taosir WTCMS's comment administration component. Attackers can remotely exploit this flaw by manip...

Nov 30, 2025
CVE-2025-13581
6.3

CVE-2025-13581 is an SQL injection vulnerability in itsourcecode Student Information System 1.0 that allows remote attackers to execute arbitrary SQL ...

Nov 24, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,234 CVEs classified as CWE-74, with 127 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free