CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,235)
CVE-2025-13581 is an SQL injection vulnerability in itsourcecode Student Information System 1.0 that allows remote attackers to execute arbitrary SQL ...
Nov 24, 2025This SQL injection vulnerability in code-projects Library System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter in...
Nov 24, 2025CVE-2025-13580 is a SQL injection vulnerability in code-projects Library System 1.0 affecting the /mail.php file. Attackers can remotely exploit this ...
Nov 24, 2025This SQL injection vulnerability in code-projects Blog Site 1.0 allows attackers to manipulate database queries through the category_exists function. ...
Nov 24, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Simple Food Ordering System 1.0 by manipulating the ID parameter i...
Nov 23, 2025This CVE describes a SQL injection vulnerability in the itsourcecode COVID Tracking System 1.0. Attackers can exploit this by manipulating the ID para...
Nov 23, 2025CVE-2025-13568 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...
Nov 23, 2025CVE-2025-13569 is an SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows attackers to manipulate database queries throug...
Nov 23, 2025CVE-2025-13567 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...
Nov 23, 2025This CVE describes a SQL injection vulnerability in the ashraf-kabir travel-agency software's search functionality. Attackers can remotely exploit the...
Nov 23, 2025CVE-2025-13396 is a SQL injection vulnerability in code-projects Courier Management System 1.0 that allows attackers to manipulate database queries th...
Nov 19, 2025This SQL injection vulnerability in SourceCodester Train Station Ticketing System 1.0 allows attackers to manipulate database queries via the /ajax.ph...
Nov 18, 2025This CVE describes a command injection vulnerability in D-Link routers that allows attackers to execute arbitrary commands on affected devices by mani...
Nov 18, 2025CVE-2025-13325 is a SQL injection vulnerability in itsourcecode Student Information System 1.0 that allows remote attackers to execute arbitrary SQL c...
Nov 18, 2025This CVE describes a SQL injection vulnerability in the Courier Management System 1.0 by code-projects. Attackers can remotely exploit the /search-edi...
Nov 17, 2025This SQL injection vulnerability in Simple Food Ordering System 1.0 allows attackers to manipulate database queries through the /saveorder.php endpoin...
Nov 17, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the SubCode parameter in the SubjectDetails.php file of the 1000proje...
Nov 17, 2025CVE-2025-13287 is a SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows remote attackers to execute arbitrary SQL command...
Nov 17, 2025CVE-2025-13286 is an SQL injection vulnerability in itsourcecode Online Voting System 1.0 that allows attackers to manipulate database queries through...
Nov 17, 2025CVE-2025-13279 is an SQL injection vulnerability in Nero Social Networking Site 1.0 that allows remote attackers to execute arbitrary SQL commands via...
Nov 17, 2025This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the datefrom/dateto...
Nov 17, 2025Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=delete_fees endpoint via the ID par...
Nov 17, 2025CVE-2025-13273 is a SQL injection vulnerability in Campcodes School Fees Payment Management System 1.0 that allows remote attackers to execute arbitra...
Nov 17, 2025This vulnerability allows remote attackers to execute injection attacks through the JDBC URL handler in Dromara dataCompare. The flaw exists in the Db...
Nov 17, 2025This vulnerability allows remote attackers to execute SQL injection attacks against Campcodes School Fees Payment Management System 1.0 via the /ajax....
Nov 17, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /ajax.php?action=save_course endpoint in Camp...
Nov 17, 2025This vulnerability allows remote attackers to execute SQL injection attacks against the Dental Clinic Appointment Reservation System 1.0 by manipulati...
Nov 17, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SourceCodester Online Magazine Management System 1.0 via the ID pa...
Nov 17, 2025This CVE describes an SQL injection vulnerability in SourceCodester Online Magazine Management System 1.0. Attackers can exploit the 'c' parameter in ...
Nov 17, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the manufacturer/edit_product.php file via the cmbProductUnit param...
Nov 17, 2025CVE-2025-13259 is a SQL injection vulnerability in Campcodes Supplier Management System 1.0 that allows attackers to execute arbitrary SQL commands vi...
Nov 17, 2025This CVE describes a SQL injection vulnerability in the Advanced Library Management System 1.0 by projectworlds. Attackers can exploit the roll_number...
Nov 17, 2025This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the roll_number par...
Nov 17, 2025This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the book_search.php...
Nov 17, 2025This SQL injection vulnerability in Advanced Library Management System 1.0 allows attackers to manipulate database queries through the Username parame...
Nov 17, 2025This CVE describes a SQL injection vulnerability in WeiYe-Jing datax-web versions up to 2.1.2. Attackers can execute arbitrary SQL commands remotely, ...
Nov 16, 2025This SQL injection vulnerability in code-projects Student Information System 2.0 allows attackers to execute arbitrary SQL commands through the /editp...
Nov 16, 2025This SQL injection vulnerability in itsourcecode Inventory Management System 1.0 allows attackers to manipulate database queries through the ID parame...
Nov 16, 2025This CVE describes a SQL injection vulnerability in itsourcecode Inventory Management System 1.0. Attackers can remotely exploit the /index.php?q=prod...
Nov 16, 2025This SQL injection vulnerability in ZZCMS 2023 allows remote attackers to execute arbitrary SQL commands through the 'keyword' parameter in /admin/wan...
Nov 14, 2025This CVE describes a SQL injection vulnerability in CodeAstro Gym Management System 1.0 that allows attackers to manipulate database queries through t...
Nov 14, 2025This SQL injection vulnerability in ury-erp allows attackers to manipulate database queries through the search_term parameter in the overrided_past_or...
Nov 14, 2025This CVE describes a SQL injection vulnerability in AMTT Hotel Broadband Operation System 1.0. Attackers can remotely exploit the /user/portal/get_fir...
Nov 13, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands on SourceCodester Alumni Management System 1.0 through SQL injection in t...
Nov 12, 2025Campcodes School Fees Payment Management System 1.0 contains a SQL injection vulnerability in the /ajax.php?action=save_student endpoint via the ID pa...
Nov 12, 2025This SQL injection vulnerability in SourceCodester Farm Management System 1.0 allows attackers to manipulate database queries through the /review.php ...
Nov 10, 2025This vulnerability allows remote attackers to execute arbitrary commands on Sangfor Operation and Maintenance Security Management System 3.0 through c...
Nov 9, 2025This CVE describes an SQL injection vulnerability in shawon100 RUET OJ's /details.php file through manipulation of the ID parameter. Remote attackers ...
Oct 27, 2025This SQL injection vulnerability in shawon100 RUET OJ allows attackers to manipulate database queries via the Name parameter in /contestproblem.php. A...
Oct 27, 2025This SQL injection vulnerability in RUET OJ's /description.php file allows remote attackers to manipulate database queries via the ID parameter. It af...
Oct 27, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,235 CVEs classified as CWE-74, with 128 rated critical and 1,304 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free