CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,241
Total CVEs
129
Critical
1,309
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,241)

CVE-2025-8928
6.3

This SQL injection vulnerability in Medical Store Management System 1.0 allows attackers to manipulate database queries through the productNameTxt par...

Aug 13, 2025
CVE-2025-8806
6.3

This is a critical SQL injection vulnerability in zhilink ADP Application Developer Platform 1.0.0 that allows remote attackers to execute arbitrary S...

Aug 10, 2025
CVE-2025-8706
6.3

This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows remote attackers to execute arbitra...

Aug 8, 2025
CVE-2025-8704
6.3

This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows attackers to execute arbitrary SQL ...

Aug 8, 2025
CVE-2025-8705
6.3

This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows remote attackers to execute arbitra...

Aug 8, 2025
CVE-2025-8701
6.3

CVE-2025-8701 is a critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Attackers can exploit the /...

Aug 7, 2025
CVE-2025-8500
6.3

This critical SQL injection vulnerability in Human Resource Integrated System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'c...

Aug 3, 2025
CVE-2025-8381
6.3

This critical SQL injection vulnerability in Campcodes Online Hotel Reservation System 1.0 allows attackers to manipulate database queries via the roo...

Jul 31, 2025
CVE-2025-8347
6.3

This critical SQL injection vulnerability in Kehua Charging Pile Cloud Platform 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Jul 31, 2025
CVE-2025-8345
6.3

This critical SQL injection vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM allows remote attackers to execute arbitrary SQL ...

Jul 31, 2025
CVE-2025-8254
6.3

This critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 28, 2025
CVE-2025-8230
6.3

A critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID...

Jul 27, 2025
CVE-2025-8203
6.3

A critical SQL injection vulnerability exists in Jingmen Zeyou Large File Upload Control versions up to 6.3. Attackers can remotely exploit this vulne...

Jul 26, 2025
CVE-2025-8190
6.3

This critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...

Jul 26, 2025
CVE-2025-8188
6.3

A critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID...

Jul 26, 2025
CVE-2025-8186
6.3

CVE-2025-8186 is a critical SQL injection vulnerability in Campcodes Courier Management System 1.0 that allows remote attackers to execute arbitrary S...

Jul 26, 2025
CVE-2025-8165
6.3

This critical SQL injection vulnerability in Food Review System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'occasion' param...

Jul 25, 2025
CVE-2025-8163
6.3

This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] pa...

Jul 25, 2025
CVE-2025-8161
6.3

A critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] param...

Jul 25, 2025
CVE-2025-8158
6.3

This critical SQL injection vulnerability in PHPGurukul Login and User Management System 3.3 allows remote attackers to execute arbitrary SQL commands...

Jul 25, 2025
CVE-2025-8157
6.3

This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management 3.3 allows remote attackers to execute arbitrary...

Jul 25, 2025
CVE-2025-8135
6.3

A critical SQL injection vulnerability in itsourcecode Insurance Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...

Jul 25, 2025
CVE-2025-8134
6.3

A critical SQL injection vulnerability in PHPGurukul BP Monitoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Jul 25, 2025
CVE-2025-8127
6.3

A critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] param...

Jul 25, 2025
CVE-2025-8124
6.3

This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] pa...

Jul 25, 2025
CVE-2025-8123
6.3

This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the 'ancestors' paramete...

Jul 24, 2025
CVE-2025-7952
6.3

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the MQTT packet hand...

Jul 22, 2025
CVE-2025-7936
6.3

This critical SQL injection vulnerability in the fuyang_lipengjun platform allows remote attackers to execute arbitrary SQL commands via the beanName/...

Jul 21, 2025
CVE-2025-7934
6.3

This CVE describes a critical SQL injection vulnerability in the fuyang_lipengjun platform's ScheduleJobController. Attackers can exploit this by mani...

Jul 21, 2025
CVE-2025-7932
6.3

This critical vulnerability in D-Link DIR-817L routers allows remote attackers to execute arbitrary commands via command injection in the ssdpcgi comp...

Jul 21, 2025
CVE-2025-7927
6.3

This critical SQL injection vulnerability in PHPGurukul Online Banquet Booking System 1.0 allows attackers to manipulate database queries through the ...

Jul 21, 2025
CVE-2025-7894
6.3

This critical SQL injection vulnerability in Onyx's chat interface allows attackers to execute arbitrary SQL commands through the generate_simple_sql ...

Jul 20, 2025
CVE-2025-7888
6.3

This critical SQL injection vulnerability in TDuckCloud tduck-platform allows remote attackers to execute arbitrary SQL commands by manipulating the f...

Jul 20, 2025
CVE-2025-7873
6.3

This critical SQL injection vulnerability in Metasoft MetaCRM allows attackers to execute arbitrary SQL commands by manipulating the workerid paramete...

Jul 20, 2025
CVE-2025-7754
6.3

A critical SQL injection vulnerability exists in Patient Record Management System 1.0 where attackers can manipulate the itr_no parameter in /xray_for...

Jul 17, 2025
CVE-2025-7614
6.3

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the delDevice functi...

Jul 14, 2025
CVE-2025-7568
6.3

This critical SQL injection vulnerability in FoxCMS allows remote attackers to execute arbitrary SQL commands through the batchCope function in Video....

Jul 14, 2025
CVE-2025-7563
6.3

A critical SQL injection vulnerability exists in PHPGurukul Online Fire Reporting System 1.2, specifically in the /admin/completed-requests.php file v...

Jul 14, 2025
CVE-2025-7560
6.3

This critical SQL injection vulnerability in PHPGurukul Online Fire Reporting System 1.2 allows remote attackers to manipulate database queries via th...

Jul 14, 2025
CVE-2025-7555
6.3

This critical SQL injection vulnerability in code-projects Voting System 1.0 allows remote attackers to execute arbitrary SQL commands via the firstna...

Jul 14, 2025
CVE-2025-7557
6.3

This critical SQL injection vulnerability in code-projects Voting System 1.0 allows remote attackers to manipulate database queries through the ID par...

Jul 14, 2025
CVE-2025-7543
6.3

This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System 3.3 allows remote attackers to manipulate...

Jul 13, 2025
CVE-2025-7524
6.3

This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP POST reques...

Jul 13, 2025
CVE-2025-7520
6.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...

Jul 13, 2025
CVE-2025-7491
6.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System 1.13 allows remote attackers to execute arbitrary SQL comman...

Jul 12, 2025
CVE-2025-7489
6.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...

Jul 12, 2025
CVE-2025-7481
6.3

This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows attackers to manipulate database queries through the ...

Jul 12, 2025
CVE-2025-7415
6.3

This critical vulnerability in Tenda O3V2 routers allows remote attackers to execute arbitrary commands via command injection in the httpd component. ...

Jul 10, 2025
CVE-2025-7200
6.3

This critical SQL injection vulnerability in the Pharmacy Management System allows attackers to execute arbitrary SQL commands by manipulating med_nam...

Jul 8, 2025
CVE-2025-7192
6.3

This critical vulnerability in D-Link DIR-645 routers allows remote attackers to execute arbitrary commands via command injection in the ssdpcgi compo...

Jul 8, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,241 CVEs classified as CWE-74, with 129 rated critical and 1,309 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free