CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,237)
This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to manipulate database queries through the '...
Oct 7, 2025This SQL injection vulnerability in SourceCodester Hotel and Lodge Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID...
Oct 7, 2025CVE-2025-11358 is a SQL injection vulnerability in Simple Banking System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ID...
Oct 7, 2025This vulnerability in ILIAS learning management system allows remote attackers to execute arbitrary code through the Certificate Import Handler compon...
Oct 6, 2025This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the fromda...
Oct 6, 2025This CVE describes a command injection vulnerability in Belkin F9K1015 routers. Attackers can remotely execute arbitrary commands by manipulating the ...
Oct 5, 2025This SQL injection vulnerability in CodeAstro Online Leave Application 1.0 allows attackers to manipulate database queries through the 'city' paramete...
Sep 28, 2025This SQL injection vulnerability in CodeAstro Online Leave Application 1.0 allows attackers to manipulate database queries through the absence[] param...
Sep 28, 2025This SQL injection vulnerability in CodeAstro Electricity Billing System 1.0 allows attackers to manipulate database queries through the uid parameter...
Sep 28, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by exploiting a command injection flaw in the uci_...
Sep 28, 2025This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected...
Sep 28, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers through command injection in the uci_del function....
Sep 28, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-823X routers by injecting malicious commands into the mac param...
Sep 28, 2025This CVE describes a command injection vulnerability in D-Link DIR-823X routers that allows remote attackers to execute arbitrary commands on affected...
Sep 28, 2025CVE-2025-11088 is an SQL injection vulnerability in itsourcecode Open Source Job Portal 1.0 that allows attackers to manipulate database queries throu...
Sep 28, 2025CVE-2025-11038 is a SQL injection vulnerability in itsourcecode Online Clinic Management System 1.0 that allows attackers to manipulate database queri...
Sep 26, 2025CVE-2025-11041 is an SQL injection vulnerability in itsourcecode Open Source Job Portal 1.0 that allows attackers to manipulate database queries throu...
Sep 26, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 devices by exploiting a command injection flaw in the fire...
Sep 25, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious input into the mac_5g param...
Sep 25, 2025This CVE describes a command injection vulnerability in Wavlink NU516U1 routers running firmware version M16U1_V240425. Attackers can remotely execute...
Sep 25, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by exploiting a command injection flaw in the fire...
Sep 25, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious input into the DeleteMac pa...
Sep 25, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by injecting malicious commands through the macAdd...
Sep 25, 2025Campcodes Society Membership Information System 1.0 contains a SQL injection vulnerability in the /check_student.php file via the student_id parameter...
Sep 23, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands through the /module/Cadastro/aluno endpoint...
Sep 23, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to execute arbitrary SQL commands by manipulating the ID parameter in the /mo...
Sep 23, 2025This SQL injection vulnerability in Portabilis i-Educar allows attackers to manipulate database queries through the /module/ComponenteCurricular/edit ...
Sep 23, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries via the sql111...
Sep 23, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software allows attackers to manipulate database queries through the ID par...
Sep 23, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands through the viewid parameter in the /admin/view-appointment.php file of C...
Sep 23, 2025Campcodes Online Beauty Parlor Management System 1.0 contains a SQL injection vulnerability in the /admin/sales-reports-detail.php file through the fr...
Sep 23, 2025This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the f...
Sep 22, 2025This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the e...
Sep 22, 2025This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the m...
Sep 22, 2025This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the '...
Sep 22, 2025This CVE describes a SQL injection vulnerability in kuaifan DooTask's UsersController.php file. Attackers can remotely exploit this by manipulating th...
Sep 21, 2025This vulnerability allows remote attackers to execute arbitrary commands on D-Link DIR-645 routers by exploiting a command injection flaw in the SOAP ...
Sep 18, 2025This CVE describes a SQL injection vulnerability in SourceCodester Online Polling System 1.0, specifically in the /admin/positions.php file's ID param...
Sep 17, 2025This SQL injection vulnerability in itsourcecode Online Clinic Management System 1.0 allows attackers to manipulate database queries through the first...
Sep 17, 2025This SQL injection vulnerability in itsourcecode Student Information System 1.0 allows attackers to manipulate database queries through the level_id p...
Sep 17, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via th...
Sep 17, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...
Sep 17, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...
Sep 17, 2025CVE-2025-10592 is an SQL injection vulnerability in itsourcecode Online Public Access Catalog OPAC 1.0 that allows attackers to execute arbitrary SQL ...
Sep 17, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...
Sep 15, 2025This SQL injection vulnerability in SourceCodester Online Student File Management System 1.0 allows attackers to manipulate database queries through t...
Sep 15, 2025This SQL injection vulnerability in RuoYi's blacklist handler allows attackers to execute arbitrary SQL commands on affected systems. It affects RuoYi...
Sep 15, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the /a...
Sep 15, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries via the ID par...
Sep 15, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Sep 15, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,237 CVEs classified as CWE-74, with 129 rated critical and 1,305 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free