CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,264
Total CVEs
133
Critical
1,328
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,264)

CVE-2025-0229
6.3

This critical SQL injection vulnerability in Travel Management System 1.0 allows remote attackers to execute arbitrary SQL commands via manipulated pa...

Jan 5, 2025
CVE-2025-0212
6.3

This critical SQL injection vulnerability in Campcodes Student Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'i...

Jan 4, 2025
CVE-2025-0208
6.3

CVE-2025-0208 is a critical SQL injection vulnerability in code-projects Online Shoe Store 1.0 that allows remote attackers to execute arbitrary SQL c...

Jan 4, 2025
CVE-2025-0204
6.3

CVE-2025-0204 is a critical SQL injection vulnerability in code-projects Online Shoe Store 1.0 that allows remote attackers to execute arbitrary SQL c...

Jan 4, 2025
CVE-2025-0200
6.3

This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...

Jan 4, 2025
CVE-2025-0198
6.3

This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...

Jan 3, 2025
CVE-2025-0197
6.3

This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows attackers to execute arbitrary SQ...

Jan 3, 2025
CVE-2025-0195
6.3

This critical SQL injection vulnerability in Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL comma...

Jan 3, 2025
CVE-2025-0176
6.3

This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...

Jan 3, 2025
CVE-2025-0174
6.3

This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...

Jan 3, 2025
CVE-2025-0172
6.3

CVE-2025-0172 is a critical SQL injection vulnerability in code-projects Chat System 1.0 that allows remote attackers to execute arbitrary SQL command...

Jan 2, 2025
CVE-2024-13084
6.3

This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows attackers to execute arbitrary SQL commands via the searchdata p...

Dec 31, 2024
CVE-2024-13078
6.3

This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sear...

Dec 31, 2024
CVE-2024-13072
6.3

This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the customer...

Dec 31, 2024
CVE-2024-13037
6.3

This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows remote attackers to execute arbitrary SQL ...

Dec 30, 2024
CVE-2024-13035
6.3

This critical SQL injection vulnerability in code-projects Chat System 1.0 allows remote attackers to manipulate database queries through the /admin/u...

Dec 30, 2024
CVE-2024-13024
6.3

This vulnerability allows remote attackers to execute SQL injection attacks via the 'cname' parameter in the /campaign.php file of Codezips Blood Bank...

Dec 29, 2024
CVE-2024-13020
6.3

This critical SQL injection vulnerability in code-projects Chat System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' para...

Dec 29, 2024
CVE-2024-13016
6.3

This critical SQL injection vulnerability in PHPGurukul Maid Hiring Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...

Dec 29, 2024
CVE-2024-13014
6.3

This critical SQL injection vulnerability in PHPGurukul Maid Hiring Management System 1.0 allows attackers to execute arbitrary SQL commands via the s...

Dec 29, 2024
CVE-2024-13005
6.3

This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System allows remote attackers to execute arbitrary SQL ...

Dec 29, 2024
CVE-2024-13001
6.3

This vulnerability allows remote attackers to execute SQL injection attacks via the email parameter in PHPGurukul Small CRM 1.0's admin/index.php file...

Dec 29, 2024
CVE-2024-12999
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /admin/edit-user.php file in PHPGurukul Sma...

Dec 29, 2024
CVE-2024-12977
6.3

This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Dec 27, 2024
CVE-2024-12952
6.3

This critical vulnerability in melMass comfy_mtb allows remote attackers to execute arbitrary code through command injection in the Dependency Handler...

Dec 26, 2024
CVE-2024-12949
6.3

This critical SQL injection vulnerability in Travel Management System 1.0 allows remote attackers to manipulate database queries via the subcatid para...

Dec 26, 2024
CVE-2024-12947
6.3

This critical SQL injection vulnerability in Codezips Hospital Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'dname...

Dec 26, 2024
CVE-2024-12938
6.3

CVE-2024-12938 is a critical SQL injection vulnerability in Simple Admin Panel 1.0 that allows remote attackers to execute arbitrary SQL commands via ...

Dec 26, 2024
CVE-2024-12936
6.3

This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands via the record parameter...

Dec 26, 2024
CVE-2024-12934
6.3

This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands via the p_desk parameter...

Dec 26, 2024
CVE-2024-12931
6.3

This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'siz...

Dec 26, 2024
CVE-2024-12929
6.3

This critical SQL injection vulnerability in Student Management System 1.0.00 allows remote attackers to manipulate database queries via the 'size' pa...

Dec 26, 2024
CVE-2024-12926
6.3

This critical SQL injection vulnerability in Codezips Project Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'name' ...

Dec 25, 2024
CVE-2024-12894
6.3

This critical SQL injection vulnerability in TreasureHuntGame's TreasureHunt software allows attackers to execute arbitrary SQL commands by manipulati...

Dec 22, 2024
CVE-2024-12890
6.3

This critical SQL injection vulnerability in Online Exam Mastering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'eid' ...

Dec 22, 2024
CVE-2024-12785
6.3

This critical SQL injection vulnerability in itsourcecode Vehicle Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...

Dec 19, 2024
CVE-2024-12784
6.3

This critical SQL injection vulnerability in Vehicle Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' para...

Dec 19, 2024
CVE-2024-12492
6.3

This critical SQL injection vulnerability in Farmacia 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in /visuali...

Dec 12, 2024
CVE-2024-12486
6.3

This critical vulnerability allows remote attackers to execute SQL injection attacks against the Online Class and Exam Scheduling System 1.0 by manipu...

Dec 12, 2024
CVE-2024-12488
6.3

This vulnerability allows remote attackers to execute SQL injection attacks via the 'id' parameter in the /pages/subject_update.php file in code-proje...

Dec 12, 2024
CVE-2024-12480
6.3

This is a critical SQL injection vulnerability in cjbi wetech-cms versions 1.0-1.2 that allows remote attackers to execute arbitrary SQL commands thro...

Dec 12, 2024
CVE-2024-12360
6.3

This critical SQL injection vulnerability in Online Class and Exam Scheduling System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Dec 9, 2024
CVE-2024-12351
6.3

This critical SQL injection vulnerability in JFinalCMS 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'name' parame...

Dec 9, 2024
CVE-2024-11998
6.3

This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /visualizer-forneccedor.chp file in Farmaci...

Nov 30, 2024
CVE-2024-11631
6.3

This is a critical SQL injection vulnerability in Tailoring Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via t...

Nov 23, 2024
CVE-2024-11589
6.3

This critical SQL injection vulnerability in Tailoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' pa...

Nov 21, 2024
CVE-2024-11487
6.3

This critical SQL injection vulnerability in Code4Berry Decoration Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...

Nov 20, 2024
CVE-2024-11250
6.3

This critical SQL injection vulnerability in code-projects Inventory Management allows authenticated attackers to manipulate database queries through ...

Nov 15, 2024
CVE-2024-11244
6.3

This critical SQL injection vulnerability in Farmacia 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /edi...

Nov 15, 2024
CVE-2024-11127
6.3

This critical SQL injection vulnerability in Job Recruitment software allows attackers to execute arbitrary SQL commands via the userid parameter in a...

Nov 12, 2024

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free