CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,259
Total CVEs
132
Critical
1,324
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,259)

CVE-2025-3235
6.3

This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Apr 4, 2025
CVE-2025-3211
6.3

A critical SQL injection vulnerability in code-projects Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands...

Apr 4, 2025
CVE-2025-3209
6.3

This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...

Apr 4, 2025
CVE-2025-3207
6.3

This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the bi...

Apr 4, 2025
CVE-2025-3205
6.3

A critical SQL injection vulnerability in CodeAstro Student Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the stude...

Apr 4, 2025
CVE-2025-3143
6.3

This critical SQL injection vulnerability in SourceCodester Apartment Visitor Management System 1.0 allows attackers to manipulate database queries th...

Apr 3, 2025
CVE-2025-3141
6.3

This critical SQL injection vulnerability in SourceCodester Online Medicine Ordering System 1.0 allows remote attackers to execute arbitrary SQL comma...

Apr 3, 2025
CVE-2025-3134
6.3

A critical SQL injection vulnerability in code-projects Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...

Apr 3, 2025
CVE-2025-3119
6.3

This is a critical SQL injection vulnerability in SourceCodester Online Tutor Portal 1.0 that allows remote attackers to execute arbitrary SQL command...

Apr 2, 2025
CVE-2025-3118
6.3

CVE-2025-3118 is a critical SQL injection vulnerability in SourceCodester Online Tutor Portal 1.0 that allows remote attackers to execute arbitrary SQ...

Apr 2, 2025
CVE-2025-3038
6.3

This critical SQL injection vulnerability in Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the salary_ra...

Mar 31, 2025
CVE-2025-3018
6.3

This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to manipulate database queries through the /class...

Mar 31, 2025
CVE-2025-2984
6.3

This critical SQL injection vulnerability in Payroll Management System 1.0 allows attackers to manipulate database queries through the emp_id paramete...

Mar 31, 2025
CVE-2025-2916
6.3

This critical vulnerability in Aishida Call Center System allows remote attackers to execute arbitrary commands on affected servers through command in...

Mar 28, 2025
CVE-2025-2854
6.3

A critical SQL injection vulnerability exists in code-projects Payroll Management System 1.0 through the update_employee.php file's emp_type parameter...

Mar 27, 2025
CVE-2025-2847
6.3

A critical SQL injection vulnerability exists in Codezips Gym Management System 1.0 through the /dashboard/admin/over_month.php file's 'mm' parameter....

Mar 27, 2025
CVE-2025-2831
6.3

This critical SQL injection vulnerability in the mingyuefusu library management system allows remote attackers to execute arbitrary SQL commands via t...

Mar 27, 2025
CVE-2025-2672
6.3

This critical SQL injection vulnerability in Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'bir' par...

Mar 23, 2025
CVE-2025-2662
6.3

This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows attackers to execute arbitrary SQL commands via the...

Mar 23, 2025
CVE-2025-2628
6.3

This critical vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute SQL injection attacks via the 'eid' par...

Mar 22, 2025
CVE-2025-2626
6.3

This critical SQL injection vulnerability in SourceCodester Kortex Lite Advocate Office Management System 1.0 allows remote attackers to execute arbit...

Mar 22, 2025
CVE-2025-2624
6.3

CVE-2025-2624 is a critical SQL injection vulnerability in westboy CicadasCMS 1.0 that allows remote attackers to execute arbitrary SQL commands via t...

Mar 22, 2025
CVE-2025-2604
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in edit_act.php in SourceCodester Kortex Lite Advoca...

Mar 21, 2025
CVE-2025-2602
6.3

This critical SQL injection vulnerability in SourceCodester Kortex Lite Advocate Office Management System 1.0 allows remote attackers to execute arbit...

Mar 21, 2025
CVE-2025-2587
6.3

This critical SQL injection vulnerability in Jinher OA C6 allows remote attackers to execute arbitrary SQL commands by manipulating the httpOID parame...

Mar 21, 2025
CVE-2025-2471
6.3

This is a critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 that allows remote attackers to execute arbitrary SQL commands vi...

Mar 18, 2025
CVE-2025-2419
6.3

This critical SQL injection vulnerability in Real Estate Property Management System 1.0 allows attackers to execute arbitrary SQL commands through the...

Mar 17, 2025
CVE-2025-2390
6.3

A critical SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to execute arbitrary SQL commands via the /user_dashboard/...

Mar 17, 2025
CVE-2025-2384
6.3

This critical SQL injection vulnerability in Real Estate Property Management System 1.0 allows remote attackers to execute arbitrary SQL commands thro...

Mar 17, 2025
CVE-2025-2373
6.3

This critical SQL injection vulnerability in PHPGurukul Human Metapneumovirus Testing Management System 1.0 allows attackers to manipulate database qu...

Mar 17, 2025
CVE-2025-2217
6.3

This critical SQL injection vulnerability in zzskzy Warehouse Refinement Management System 1.3 allows remote attackers to execute arbitrary SQL comman...

Mar 12, 2025
CVE-2025-2112
6.3

This is a critical SQL injection vulnerability in the user-xiangpeng yaoqishan software that allows remote attackers to execute arbitrary SQL commands...

Mar 8, 2025
CVE-2025-2053
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands through the editid parameter in visitor-detail.php in PHPGurukul Apartmen...

Mar 7, 2025
CVE-2025-2051
6.3

This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to execute arbitrary SQL commands vi...

Mar 7, 2025
CVE-2025-2037
6.3

This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the reques...

Mar 6, 2025
CVE-2025-2033
6.3

A critical SQL injection vulnerability exists in code-projects Blood Bank Management System 1.0, specifically in the /user_dashboard/view_donor.php fi...

Mar 6, 2025
CVE-2025-1958
6.3

This critical SQL injection vulnerability in aaluoxiang oa_system 1.0 allows remote attackers to execute arbitrary SQL commands via the 'outtype' para...

Mar 4, 2025
CVE-2025-1946
6.3

This critical vulnerability in hzmanyun Education and Training System 2.1 allows remote attackers to execute arbitrary commands via command injection ...

Mar 4, 2025
CVE-2025-1855
6.3

This critical SQL injection vulnerability in PHPGurukul Online Shopping Portal 2.1 allows remote attackers to execute arbitrary SQL commands via the p...

Mar 3, 2025
CVE-2025-1845
6.3

This critical vulnerability in ESAFENET DSM 3.1.2 allows remote attackers to execute arbitrary commands via command injection in the examExportPDF fun...

Mar 3, 2025
CVE-2025-1843
6.3

This critical SQL injection vulnerability in Mini-Tmall allows remote attackers to execute arbitrary SQL commands by manipulating the 'orderBy' parame...

Mar 3, 2025
CVE-2025-1831
6.3

This critical SQL injection vulnerability in zj1983 zz software allows remote attackers to execute arbitrary SQL commands via the user_id parameter in...

Mar 2, 2025
CVE-2025-1821
6.3

This CVE describes a critical SQL injection vulnerability in the zj1983 zz software that allows attackers to execute arbitrary SQL commands by manipul...

Mar 2, 2025
CVE-2025-1820
6.3

This critical SQL injection vulnerability in zj1983 zz software allows remote attackers to execute arbitrary SQL commands by manipulating the tableId ...

Mar 2, 2025
CVE-2025-1800
6.3

This critical vulnerability in D-Link DAR-7000 allows remote attackers to execute arbitrary commands via command injection in the get_ip_addr_details ...

Mar 1, 2025
CVE-2025-1797
6.3

This critical SQL injection vulnerability in Hunan Zhonghe Baiyi Information Technology's Baiyiyun Asset Management and Operations System allows remot...

Mar 1, 2025
CVE-2025-1537
6.3

This critical SQL injection vulnerability in Harpia DiagSystem 12 allows remote attackers to execute arbitrary SQL commands via the 'codexame' paramet...

Feb 21, 2025
CVE-2025-1356
6.3

This critical SQL injection vulnerability in needyamin Library Card System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' ...

Feb 16, 2025
CVE-2025-1216
6.3

This critical SQL injection vulnerability in ywoa allows remote attackers to execute arbitrary SQL commands through manipulation of the 'sort' paramet...

Feb 12, 2025
CVE-2025-1210
6.3

A critical SQL injection vulnerability exists in code-projects Wazifa System 1.0, specifically in the /controllers/control.php file. Attackers can rem...

Feb 12, 2025

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,259 CVEs classified as CWE-74, with 132 rated critical and 1,324 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free