CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,241)
This SQL injection vulnerability in Medical Store Management System 1.0 allows attackers to manipulate database queries through the productNameTxt par...
Aug 13, 2025This is a critical SQL injection vulnerability in zhilink ADP Application Developer Platform 1.0.0 that allows remote attackers to execute arbitrary S...
Aug 10, 2025This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows remote attackers to execute arbitra...
Aug 8, 2025This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows attackers to execute arbitrary SQL ...
Aug 8, 2025This critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 allows remote attackers to execute arbitra...
Aug 8, 2025CVE-2025-8701 is a critical SQL injection vulnerability in Wanzhou WOES Intelligent Optimization Energy Saving System 1.0. Attackers can exploit the /...
Aug 7, 2025This critical SQL injection vulnerability in Human Resource Integrated System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'c...
Aug 3, 2025This critical SQL injection vulnerability in Campcodes Online Hotel Reservation System 1.0 allows attackers to manipulate database queries via the roo...
Jul 31, 2025This critical SQL injection vulnerability in Kehua Charging Pile Cloud Platform 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
Jul 31, 2025This critical SQL injection vulnerability in Shanghai Lingdang Information Technology's Lingdang CRM allows remote attackers to execute arbitrary SQL ...
Jul 31, 2025This critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Jul 28, 2025A critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID...
Jul 27, 2025A critical SQL injection vulnerability exists in Jingmen Zeyou Large File Upload Control versions up to 6.3. Attackers can remotely exploit this vulne...
Jul 26, 2025This critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Jul 26, 2025A critical SQL injection vulnerability in Campcodes Courier Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID...
Jul 26, 2025CVE-2025-8186 is a critical SQL injection vulnerability in Campcodes Courier Management System 1.0 that allows remote attackers to execute arbitrary S...
Jul 26, 2025This critical SQL injection vulnerability in Food Review System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'occasion' param...
Jul 25, 2025This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] pa...
Jul 25, 2025A critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] param...
Jul 25, 2025This critical SQL injection vulnerability in PHPGurukul Login and User Management System 3.3 allows remote attackers to execute arbitrary SQL commands...
Jul 25, 2025This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management 3.3 allows remote attackers to execute arbitrary...
Jul 25, 2025A critical SQL injection vulnerability in itsourcecode Insurance Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
Jul 25, 2025A critical SQL injection vulnerability in PHPGurukul BP Monitoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Jul 25, 2025A critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] param...
Jul 25, 2025This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the params[dataScope] pa...
Jul 25, 2025This critical SQL injection vulnerability in deerwms deer-wms-2 allows remote attackers to execute arbitrary SQL commands via the 'ancestors' paramete...
Jul 24, 2025This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the MQTT packet hand...
Jul 22, 2025This critical SQL injection vulnerability in the fuyang_lipengjun platform allows remote attackers to execute arbitrary SQL commands via the beanName/...
Jul 21, 2025This CVE describes a critical SQL injection vulnerability in the fuyang_lipengjun platform's ScheduleJobController. Attackers can exploit this by mani...
Jul 21, 2025This critical vulnerability in D-Link DIR-817L routers allows remote attackers to execute arbitrary commands via command injection in the ssdpcgi comp...
Jul 21, 2025This critical SQL injection vulnerability in PHPGurukul Online Banquet Booking System 1.0 allows attackers to manipulate database queries through the ...
Jul 21, 2025This critical SQL injection vulnerability in Onyx's chat interface allows attackers to execute arbitrary SQL commands through the generate_simple_sql ...
Jul 20, 2025This critical SQL injection vulnerability in TDuckCloud tduck-platform allows remote attackers to execute arbitrary SQL commands by manipulating the f...
Jul 20, 2025This critical SQL injection vulnerability in Metasoft MetaCRM allows attackers to execute arbitrary SQL commands by manipulating the workerid paramete...
Jul 20, 2025A critical SQL injection vulnerability exists in Patient Record Management System 1.0 where attackers can manipulate the itr_no parameter in /xray_for...
Jul 17, 2025This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the delDevice functi...
Jul 14, 2025This critical SQL injection vulnerability in FoxCMS allows remote attackers to execute arbitrary SQL commands through the batchCope function in Video....
Jul 14, 2025A critical SQL injection vulnerability exists in PHPGurukul Online Fire Reporting System 1.2, specifically in the /admin/completed-requests.php file v...
Jul 14, 2025This critical SQL injection vulnerability in PHPGurukul Online Fire Reporting System 1.2 allows remote attackers to manipulate database queries via th...
Jul 14, 2025This critical SQL injection vulnerability in code-projects Voting System 1.0 allows remote attackers to execute arbitrary SQL commands via the firstna...
Jul 14, 2025This critical SQL injection vulnerability in code-projects Voting System 1.0 allows remote attackers to manipulate database queries through the ID par...
Jul 14, 2025This critical SQL injection vulnerability in PHPGurukul User Registration & Login and User Management System 3.3 allows remote attackers to manipulate...
Jul 13, 2025This critical vulnerability in TOTOLINK T6 routers allows remote attackers to execute arbitrary commands via command injection in the HTTP POST reques...
Jul 13, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...
Jul 13, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System 1.13 allows remote attackers to execute arbitrary SQL comman...
Jul 12, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows remote attackers to execute arbitrary SQL commands vi...
Jul 12, 2025This critical SQL injection vulnerability in PHPGurukul Vehicle Parking Management System allows attackers to manipulate database queries through the ...
Jul 12, 2025This critical vulnerability in Tenda O3V2 routers allows remote attackers to execute arbitrary commands via command injection in the httpd component. ...
Jul 10, 2025This critical SQL injection vulnerability in the Pharmacy Management System allows attackers to execute arbitrary SQL commands by manipulating med_nam...
Jul 8, 2025This critical vulnerability in D-Link DIR-645 routers allows remote attackers to execute arbitrary commands via command injection in the ssdpcgi compo...
Jul 8, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,241 CVEs classified as CWE-74, with 129 rated critical and 1,309 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free