CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,264)
This critical SQL injection vulnerability in Travel Management System 1.0 allows remote attackers to execute arbitrary SQL commands via manipulated pa...
Jan 5, 2025This critical SQL injection vulnerability in Campcodes Student Grading System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'i...
Jan 4, 2025CVE-2025-0208 is a critical SQL injection vulnerability in code-projects Online Shoe Store 1.0 that allows remote attackers to execute arbitrary SQL c...
Jan 4, 2025CVE-2025-0204 is a critical SQL injection vulnerability in code-projects Online Shoe Store 1.0 that allows remote attackers to execute arbitrary SQL c...
Jan 4, 2025This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...
Jan 4, 2025This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...
Jan 3, 2025This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows attackers to execute arbitrary SQ...
Jan 3, 2025This critical SQL injection vulnerability in Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbitrary SQL comma...
Jan 3, 2025This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...
Jan 3, 2025This critical SQL injection vulnerability in code-projects Point of Sales and Inventory Management System 1.0 allows remote attackers to execute arbit...
Jan 3, 2025CVE-2025-0172 is a critical SQL injection vulnerability in code-projects Chat System 1.0 that allows remote attackers to execute arbitrary SQL command...
Jan 2, 2025This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows attackers to execute arbitrary SQL commands via the searchdata p...
Dec 31, 2024This critical SQL injection vulnerability in PHPGurukul Land Record System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sear...
Dec 31, 2024This critical SQL injection vulnerability in Beauty Parlour Management System 1.0 allows attackers to manipulate database queries through the customer...
Dec 31, 2024This critical SQL injection vulnerability in 1000 Projects Attendance Tracking Management System 1.0 allows remote attackers to execute arbitrary SQL ...
Dec 30, 2024This critical SQL injection vulnerability in code-projects Chat System 1.0 allows remote attackers to manipulate database queries through the /admin/u...
Dec 30, 2024This vulnerability allows remote attackers to execute SQL injection attacks via the 'cname' parameter in the /campaign.php file of Codezips Blood Bank...
Dec 29, 2024This critical SQL injection vulnerability in code-projects Chat System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' para...
Dec 29, 2024This critical SQL injection vulnerability in PHPGurukul Maid Hiring Management System 1.0 allows remote attackers to execute arbitrary SQL commands vi...
Dec 29, 2024This critical SQL injection vulnerability in PHPGurukul Maid Hiring Management System 1.0 allows attackers to execute arbitrary SQL commands via the s...
Dec 29, 2024This critical SQL injection vulnerability in the 1000 Projects Attendance Tracking Management System allows remote attackers to execute arbitrary SQL ...
Dec 29, 2024This vulnerability allows remote attackers to execute SQL injection attacks via the email parameter in PHPGurukul Small CRM 1.0's admin/index.php file...
Dec 29, 2024This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /admin/edit-user.php file in PHPGurukul Sma...
Dec 29, 2024This critical SQL injection vulnerability in PHPGurukul Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Dec 27, 2024This critical vulnerability in melMass comfy_mtb allows remote attackers to execute arbitrary code through command injection in the Dependency Handler...
Dec 26, 2024This critical SQL injection vulnerability in Travel Management System 1.0 allows remote attackers to manipulate database queries via the subcatid para...
Dec 26, 2024This critical SQL injection vulnerability in Codezips Hospital Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'dname...
Dec 26, 2024CVE-2024-12938 is a critical SQL injection vulnerability in Simple Admin Panel 1.0 that allows remote attackers to execute arbitrary SQL commands via ...
Dec 26, 2024This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands via the record parameter...
Dec 26, 2024This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands via the p_desk parameter...
Dec 26, 2024This critical SQL injection vulnerability in Simple Admin Panel 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'siz...
Dec 26, 2024This critical SQL injection vulnerability in Student Management System 1.0.00 allows remote attackers to manipulate database queries via the 'size' pa...
Dec 26, 2024This critical SQL injection vulnerability in Codezips Project Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'name' ...
Dec 25, 2024This critical SQL injection vulnerability in TreasureHuntGame's TreasureHunt software allows attackers to execute arbitrary SQL commands by manipulati...
Dec 22, 2024This critical SQL injection vulnerability in Online Exam Mastering System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'eid' ...
Dec 22, 2024This critical SQL injection vulnerability in itsourcecode Vehicle Management System 1.0 allows remote attackers to execute arbitrary SQL commands via ...
Dec 19, 2024This critical SQL injection vulnerability in Vehicle Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' para...
Dec 19, 2024This critical SQL injection vulnerability in Farmacia 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in /visuali...
Dec 12, 2024This critical vulnerability allows remote attackers to execute SQL injection attacks against the Online Class and Exam Scheduling System 1.0 by manipu...
Dec 12, 2024This vulnerability allows remote attackers to execute SQL injection attacks via the 'id' parameter in the /pages/subject_update.php file in code-proje...
Dec 12, 2024This is a critical SQL injection vulnerability in cjbi wetech-cms versions 1.0-1.2 that allows remote attackers to execute arbitrary SQL commands thro...
Dec 12, 2024This critical SQL injection vulnerability in Online Class and Exam Scheduling System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Dec 9, 2024This critical SQL injection vulnerability in JFinalCMS 1.0 allows remote attackers to execute arbitrary SQL commands by manipulating the 'name' parame...
Dec 9, 2024This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /visualizer-forneccedor.chp file in Farmaci...
Nov 30, 2024This is a critical SQL injection vulnerability in Tailoring Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via t...
Nov 23, 2024This critical SQL injection vulnerability in Tailoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' pa...
Nov 21, 2024This critical SQL injection vulnerability in Code4Berry Decoration Management System 1.0 allows remote attackers to execute arbitrary SQL commands via...
Nov 20, 2024This critical SQL injection vulnerability in code-projects Inventory Management allows authenticated attackers to manipulate database queries through ...
Nov 15, 2024This critical SQL injection vulnerability in Farmacia 1.0 allows remote attackers to execute arbitrary SQL commands via the 'id' parameter in the /edi...
Nov 15, 2024This critical SQL injection vulnerability in Job Recruitment software allows attackers to execute arbitrary SQL commands via the userid parameter in a...
Nov 12, 2024About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free