CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,259)
This critical SQL injection vulnerability in PHPGurukul Old Age Home Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Apr 4, 2025A critical SQL injection vulnerability in code-projects Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands...
Apr 4, 2025This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the it...
Apr 4, 2025This critical SQL injection vulnerability in Patient Record Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the bi...
Apr 4, 2025A critical SQL injection vulnerability in CodeAstro Student Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the stude...
Apr 4, 2025This critical SQL injection vulnerability in SourceCodester Apartment Visitor Management System 1.0 allows attackers to manipulate database queries th...
Apr 3, 2025This critical SQL injection vulnerability in SourceCodester Online Medicine Ordering System 1.0 allows remote attackers to execute arbitrary SQL comma...
Apr 3, 2025A critical SQL injection vulnerability in code-projects Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via th...
Apr 3, 2025This is a critical SQL injection vulnerability in SourceCodester Online Tutor Portal 1.0 that allows remote attackers to execute arbitrary SQL command...
Apr 2, 2025CVE-2025-3118 is a critical SQL injection vulnerability in SourceCodester Online Tutor Portal 1.0 that allows remote attackers to execute arbitrary SQ...
Apr 2, 2025This critical SQL injection vulnerability in Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the salary_ra...
Mar 31, 2025This critical SQL injection vulnerability in SourceCodester Online Eyewear Shop 1.0 allows attackers to manipulate database queries through the /class...
Mar 31, 2025This critical SQL injection vulnerability in Payroll Management System 1.0 allows attackers to manipulate database queries through the emp_id paramete...
Mar 31, 2025This critical vulnerability in Aishida Call Center System allows remote attackers to execute arbitrary commands on affected servers through command in...
Mar 28, 2025A critical SQL injection vulnerability exists in code-projects Payroll Management System 1.0 through the update_employee.php file's emp_type parameter...
Mar 27, 2025A critical SQL injection vulnerability exists in Codezips Gym Management System 1.0 through the /dashboard/admin/over_month.php file's 'mm' parameter....
Mar 27, 2025This critical SQL injection vulnerability in the mingyuefusu library management system allows remote attackers to execute arbitrary SQL commands via t...
Mar 27, 2025This critical SQL injection vulnerability in Payroll Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'bir' par...
Mar 23, 2025This critical SQL injection vulnerability in Project Worlds Online Time Table Generator 1.0 allows attackers to execute arbitrary SQL commands via the...
Mar 23, 2025This critical vulnerability in PHPGurukul Art Gallery Management System 1.1 allows remote attackers to execute SQL injection attacks via the 'eid' par...
Mar 22, 2025This critical SQL injection vulnerability in SourceCodester Kortex Lite Advocate Office Management System 1.0 allows remote attackers to execute arbit...
Mar 22, 2025CVE-2025-2624 is a critical SQL injection vulnerability in westboy CicadasCMS 1.0 that allows remote attackers to execute arbitrary SQL commands via t...
Mar 22, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in edit_act.php in SourceCodester Kortex Lite Advoca...
Mar 21, 2025This critical SQL injection vulnerability in SourceCodester Kortex Lite Advocate Office Management System 1.0 allows remote attackers to execute arbit...
Mar 21, 2025This critical SQL injection vulnerability in Jinher OA C6 allows remote attackers to execute arbitrary SQL commands by manipulating the httpOID parame...
Mar 21, 2025This is a critical SQL injection vulnerability in PHPGurukul Boat Booking System 1.0 that allows remote attackers to execute arbitrary SQL commands vi...
Mar 18, 2025This critical SQL injection vulnerability in Real Estate Property Management System 1.0 allows attackers to execute arbitrary SQL commands through the...
Mar 17, 2025A critical SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to execute arbitrary SQL commands via the /user_dashboard/...
Mar 17, 2025This critical SQL injection vulnerability in Real Estate Property Management System 1.0 allows remote attackers to execute arbitrary SQL commands thro...
Mar 17, 2025This critical SQL injection vulnerability in PHPGurukul Human Metapneumovirus Testing Management System 1.0 allows attackers to manipulate database qu...
Mar 17, 2025This critical SQL injection vulnerability in zzskzy Warehouse Refinement Management System 1.3 allows remote attackers to execute arbitrary SQL comman...
Mar 12, 2025This is a critical SQL injection vulnerability in the user-xiangpeng yaoqishan software that allows remote attackers to execute arbitrary SQL commands...
Mar 8, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands through the editid parameter in visitor-detail.php in PHPGurukul Apartmen...
Mar 7, 2025This critical SQL injection vulnerability in PHPGurukul Apartment Visitors Management System 1.0 allows attackers to execute arbitrary SQL commands vi...
Mar 7, 2025This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the reques...
Mar 6, 2025A critical SQL injection vulnerability exists in code-projects Blood Bank Management System 1.0, specifically in the /user_dashboard/view_donor.php fi...
Mar 6, 2025This critical SQL injection vulnerability in aaluoxiang oa_system 1.0 allows remote attackers to execute arbitrary SQL commands via the 'outtype' para...
Mar 4, 2025This critical vulnerability in hzmanyun Education and Training System 2.1 allows remote attackers to execute arbitrary commands via command injection ...
Mar 4, 2025This critical SQL injection vulnerability in PHPGurukul Online Shopping Portal 2.1 allows remote attackers to execute arbitrary SQL commands via the p...
Mar 3, 2025This critical vulnerability in ESAFENET DSM 3.1.2 allows remote attackers to execute arbitrary commands via command injection in the examExportPDF fun...
Mar 3, 2025This critical SQL injection vulnerability in Mini-Tmall allows remote attackers to execute arbitrary SQL commands by manipulating the 'orderBy' parame...
Mar 3, 2025This critical SQL injection vulnerability in zj1983 zz software allows remote attackers to execute arbitrary SQL commands via the user_id parameter in...
Mar 2, 2025This CVE describes a critical SQL injection vulnerability in the zj1983 zz software that allows attackers to execute arbitrary SQL commands by manipul...
Mar 2, 2025This critical SQL injection vulnerability in zj1983 zz software allows remote attackers to execute arbitrary SQL commands by manipulating the tableId ...
Mar 2, 2025This critical vulnerability in D-Link DAR-7000 allows remote attackers to execute arbitrary commands via command injection in the get_ip_addr_details ...
Mar 1, 2025This critical SQL injection vulnerability in Hunan Zhonghe Baiyi Information Technology's Baiyiyun Asset Management and Operations System allows remot...
Mar 1, 2025This critical SQL injection vulnerability in Harpia DiagSystem 12 allows remote attackers to execute arbitrary SQL commands via the 'codexame' paramet...
Feb 21, 2025This critical SQL injection vulnerability in needyamin Library Card System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' ...
Feb 16, 2025This critical SQL injection vulnerability in ywoa allows remote attackers to execute arbitrary SQL commands through manipulation of the 'sort' paramet...
Feb 12, 2025A critical SQL injection vulnerability exists in code-projects Wazifa System 1.0, specifically in the /controllers/control.php file. Attackers can rem...
Feb 12, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,259 CVEs classified as CWE-74, with 132 rated critical and 1,324 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free