CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,237
Total CVEs
129
Critical
1,305
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,237)

CVE-2025-11399
6.3

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the '...

Oct 7, 2025
CVE-2025-11400
6.3

This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID...

Oct 7, 2025
CVE-2025-11358
6.3

CVE-2025-11358 is a SQL injection vulnerability in Simple Banking System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID...

Oct 7, 2025
CVE-2025-11344
6.3

This vulnerability in ILIAS learning management system allows remote attackers to execute arbitrary code through the Certificate Import Handler compon...

Oct 6, 2025
CVE-2025-11330
6.3

This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the fromda...

Oct 6, 2025
CVE-2025-11303
6.3

This CVE describes a command injection vulnerability in Belkin F9K1015 routers. Attackers can remotely execute arbitrary commands by manipulating the ...

Oct 5, 2025
CVE-2025-11113
6.3

This SQL injection vulnerability in CodeAstro Online Leave Application 1.0 allows attackers to manipulate database queries through the 'city' paramete...

Sep 28, 2025
CVE-2025-11114
6.3

This SQL injection vulnerability in CodeAstro Online Leave Application 1.0 allows attackers to manipulate database queries through the absence[] param...

Sep 28, 2025
CVE-2025-11104
6.3

This SQL injection vulnerability in CodeAstro Electricity Billing System 1.0 allows attackers to manipulate database queries through the uid parameter...

Sep 28, 2025
CVE-2025-11100
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by exploiting a command injection flaw in the uci_...

Sep 28, 2025
CVE-2025-11098
6.3

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected...

Sep 28, 2025
CVE-2025-11099
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers through command injection in the uci_del function....

Sep 28, 2025
CVE-2025-11097
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by injecting malicious commands into the mac param...

Sep 28, 2025
CVE-2025-11096
6.3

This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected...

Sep 28, 2025
CVE-2025-11088
6.3

CVE-2025-11088 is an SQL injection vulnerability in itsourcecode Open Source Job Portal 1.0 that allows attackers to manipulate database queries throu...

Sep 28, 2025
CVE-2025-11038
6.3

CVE-2025-11038 is a SQL injection vulnerability in itsourcecode Online Clinic Management System 1.0 that allows attackers to manipulate database queri...

Sep 26, 2025
CVE-2025-11041
6.3

CVE-2025-11041 is an SQL injection vulnerability in itsourcecode Open Source Job Portal 1.0 that allows attackers to manipulate database queries throu...

Sep 26, 2025
CVE-2025-10964
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 devices by exploiting a command injection flaw in the fire...

Sep 25, 2025
CVE-2025-10962
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious input into the mac_5g param...

Sep 25, 2025
CVE-2025-10963
6.3

This CVE describes a command injection vulnerability in Wavlink NU516U1 routers running firmware version M16U1_V240425. Attackers can remotely execute...

Sep 25, 2025
CVE-2025-10959
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by exploiting a command injection flaw in the fire...

Sep 25, 2025
CVE-2025-10960
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious input into the DeleteMac pa...

Sep 25, 2025
CVE-2025-10958
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious commands through the macAdd...

Sep 25, 2025
CVE-2025-10848
6.3

Campcodes Society Membership Information System 1.0 contains a SQL injection vulnerability in the /check_student.php file via the student_id parameter...

Sep 23, 2025
CVE-2025-10844
6.3

This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands through the /module/Cadastro/aluno endpoint...

Sep 23, 2025
CVE-2025-10845
6.3

This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands by manipulating the ID parameter in the /mo...

Sep 23, 2025
CVE-2025-10846
6.3

This SQL injection vulnerability in Portabilis i-Educar allows attackers to manipulate database queries through the /module/ComponenteCurricular/edit ...

Sep 23, 2025
CVE-2025-10840
6.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries via the sql111...

Sep 23, 2025
CVE-2025-10828
6.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software allows attackers to manipulate database queries through the ID par...

Sep 23, 2025
CVE-2025-10825
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands through the viewid parameter in the /admin/view-appointment.php file of C...

Sep 23, 2025
CVE-2025-10826
6.3

Campcodes Online Beauty Parlor Management System 1.0 contains a SQL injection vulnerability in the /admin/sales-reports-detail.php file through the fr...

Sep 23, 2025
CVE-2025-10806
6.3

This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the f...

Sep 22, 2025
CVE-2025-10807
6.3

This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the e...

Sep 22, 2025
CVE-2025-10804
6.3

This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the m...

Sep 22, 2025
CVE-2025-10805
6.3

This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the '...

Sep 22, 2025
CVE-2025-10762
6.3

This CVE describes a SQL injection vulnerability in kuaifan DooTask's UsersController.php file. Attackers can remotely exploit this by manipulating th...

Sep 21, 2025
CVE-2025-10689
6.3

This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-645 routers by exploiting a command injection flaw in the SOAP ...

Sep 18, 2025
CVE-2025-10617
6.3

This CVE describes a SQL injection vulnerability in SourceCodester Online Polling System 1.0, specifically in the /admin/positions.php file's ID param...

Sep 17, 2025
CVE-2025-10618
6.3

This SQL injection vulnerability in itsourcecode Online Clinic Management System 1.0 allows attackers to manipulate database queries through the first...

Sep 17, 2025
CVE-2025-10613
6.3

This SQL injection vulnerability in itsourcecode Student Information System 1.0 allows attackers to manipulate database queries through the level_id p...

Sep 17, 2025
CVE-2025-10595
6.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via th...

Sep 17, 2025
CVE-2025-10593
6.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...

Sep 17, 2025
CVE-2025-10594
6.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...

Sep 17, 2025
CVE-2025-10592
6.3

CVE-2025-10592 is an SQL injection vulnerability in itsourcecode Online Public Access Catalog OPAC 1.0 that allows attackers to execute arbitrary SQL ...

Sep 17, 2025
CVE-2025-10483
6.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...

Sep 15, 2025
CVE-2025-10481
6.3

This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...

Sep 15, 2025
CVE-2025-10473
6.3

This SQL injection vulnerability in RuoYi's blacklist handler allows attackers to execute arbitrary SQL commands on affected systems. It affects RuoYi...

Sep 15, 2025
CVE-2025-10430
6.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the /a...

Sep 15, 2025
CVE-2025-10431
6.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries via the ID par...

Sep 15, 2025
CVE-2025-10429
6.3

This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Sep 15, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,237 CVEs classified as CWE-74, with 129 rated critical and 1,305 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free