CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,241)
A critical SQL injection vulnerability exists in code-projects Chat System 1.0 through the /user/send_message.php file's msg parameter. Attackers can ...
Jul 8, 2025CVE-2025-7187 is a critical SQL injection vulnerability in code-projects Chat System 1.0 that allows remote attackers to execute arbitrary SQL command...
Jul 8, 2025This critical SQL injection vulnerability in Responsive Blog Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter i...
Jul 8, 2025This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows remote attackers to execute arbitrary SQL commands via the 'c...
Jul 8, 2025This critical SQL injection vulnerability in PHPGurukul Zoo Management System 2.1 allows attackers to manipulate database queries through the ID param...
Jul 8, 2025CVE-2025-7156 is a critical SQL injection vulnerability in hitsz-ids airda version 0.0.3 that allows remote attackers to execute arbitrary SQL command...
Jul 8, 2025This critical SQL injection vulnerability in Campcodes Advanced Online Voting System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Jul 7, 2025A critical SQL injection vulnerability exists in the itsourcecode Employee Management System up to version 1.0. Attackers can remotely exploit this vu...
Jul 7, 2025This critical vulnerability in BoyunCMS allows remote attackers to execute arbitrary code by manipulating the db_pass parameter during installation. I...
Jul 7, 2025A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2's /register.php file, allowing remote attackers to manipulate da...
Jun 30, 2025A critical SQL injection vulnerability exists in PHPGurukul Student Record System 3.2 through the /admin-profile.php file's aemailid parameter. This a...
Jun 30, 2025This critical SQL injection vulnerability in PHPGurukul Student Record System 3.2 allows attackers to execute arbitrary SQL commands via the 'del' par...
Jun 30, 2025This CVE describes a critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0. Attackers can remotely exploit the /admin/...
Jun 30, 2025A critical SQL injection vulnerability exists in code-projects Staff Audit System 1.0 through the /search_index.php file's Search parameter. This allo...
Jun 30, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through t...
Jun 30, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jun 30, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jun 29, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jun 29, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jun 29, 2025CVE-2025-6850 is a critical SQL injection vulnerability in Simple Forum 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'Fi...
Jun 29, 2025A critical SQL injection vulnerability exists in Simple Forum 1.0's /forum_edit.php file, allowing remote attackers to manipulate database queries via...
Jun 29, 2025This critical SQL injection vulnerability in sfturing hosp_order allows remote attackers to execute arbitrary SQL commands by manipulating the hospita...
Jun 27, 2025This critical SQL injection vulnerability in sfturing hosp_order allows remote attackers to execute arbitrary SQL commands by manipulating the offices...
Jun 27, 2025This critical SQL injection vulnerability in huija bicycleSharingServer 1.0 allows remote attackers to execute arbitrary SQL commands through the sele...
Jun 27, 2025This critical SQL injection vulnerability in huija bicycleSharingServer allows attackers to execute arbitrary SQL commands through the Title parameter...
Jun 27, 2025This is a critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0. Attackers can remotely exploit the /panel/bwdates-r...
Jun 25, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Jun 25, 2025This critical SQL injection vulnerability in SourceCodester Best Salon Management System 1.0 allows attackers to manipulate database queries through t...
Jun 25, 2025This CVE describes a critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1. Attackers can exploit the 'awarddetails' pa...
Jun 21, 2025This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System allows remote attackers to execute arbitrary SQL commands via th...
Jun 21, 2025This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System allows remote attackers to execute arbitrary SQL commands via th...
Jun 21, 2025This critical SQL injection vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute arbitrary SQL commands vi...
Jun 21, 2025A critical SQL injection vulnerability exists in itsourcecode Employee Record Management System 1.0 through the /editprofile.php file. Attackers can r...
Jun 20, 2025This vulnerability allows remote attackers to execute SQL injection attacks against the Advance Charity Management System 1.0 by manipulating the 'm06...
Jun 20, 2025This critical SQL injection vulnerability in PHPGurukul Directory Management System 2.0 allows remote attackers to execute arbitrary SQL commands via ...
Jun 20, 2025This critical SQL injection vulnerability in PHPGurukul Pre-School Enrollment System 1.0 allows attackers to manipulate database queries through the c...
Jun 20, 2025A critical SQL injection vulnerability exists in PHPGurukul Pre-School Enrollment System 1.0, specifically in the /admin/add-teacher.php file's tsubje...
Jun 20, 2025A critical SQL injection vulnerability in PHPGurukul Emergency Ambulance Hiring Portal 1.0 allows remote attackers to execute arbitrary SQL commands v...
Jun 20, 2025This CVE describes a critical SQL injection vulnerability in the Brilliance Golden Link Secondary System. Attackers can exploit the 'custTradeName' pa...
Jun 19, 2025This critical SQL injection vulnerability in zhilink ADP Application Developer Platform 1.0.0 allows remote attackers to execute arbitrary SQL command...
Jun 19, 2025This critical SQL injection vulnerability in Projectworlds Life Insurance Management System 1.0 allows attackers to manipulate database queries throug...
Jun 16, 2025This critical SQL injection vulnerability in Projectworlds Life Insurance Management System 1.0 allows attackers to execute arbitrary SQL commands via...
Jun 16, 2025This critical SQL injection vulnerability in realguoshuai open-video-cms 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sort' ...
Jun 16, 2025This critical SQL injection vulnerability in PHPGurukul Nipah Virus Testing Management System 1.0 allows remote attackers to execute arbitrary SQL com...
Jun 9, 2025This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...
Jun 9, 2025A critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL commands v...
Jun 7, 2025This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows remote attackers to execute arbitrary SQL command...
Jun 6, 2025This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...
Jun 6, 2025This critical SQL injection vulnerability in PHPGurukul Employee Record Management System 1.3 allows attackers to manipulate database queries through ...
Jun 6, 2025A critical SQL injection vulnerability exists in code-projects Patient Record Management System 1.0, specifically in the view_hematology.php file's it...
Jun 6, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,241 CVEs classified as CWE-74, with 129 rated critical and 1,309 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free