CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,264)
This critical SQL injection vulnerability in code-projects Task Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the projectN...
Nov 12, 2024This critical SQL injection vulnerability in Tailoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands through the /in...
Nov 11, 2024This CVE describes a critical SQL injection vulnerability in Project Worlds Free Download Online Shopping System. Attackers can remotely exploit the /...
Nov 11, 2024This critical SQL injection vulnerability in AMTT Hotel Broadband Operation System allows attackers to manipulate database queries via the AccountID p...
Nov 10, 2024This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Nov 8, 2024This critical SQL injection vulnerability in SourceCodester Online Veterinary Appointment System 1.0 allows remote attackers to execute arbitrary SQL ...
Nov 8, 2024This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands via manipulated parame...
Nov 8, 2024This critical SQL injection vulnerability in University Event Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...
Nov 4, 2024This critical SQL injection vulnerability in University Event Management System 1.0 allows attackers to manipulate database queries through the submit...
Nov 2, 2024This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC6 routers by injecting malicious commands into the 'mac' parameter...
Nov 2, 2024This vulnerability allows remote attackers to execute SQL injection attacks on PHPGurukul Boat Booking System 1.0 by manipulating bookingdatefrom/nope...
Oct 19, 2024This critical vulnerability in Intelbras InControl allows remote attackers to execute arbitrary code through code injection in the Relatório de Opera...
Sep 29, 2024This vulnerability allows remote attackers to execute SQL injection attacks against the School Log Management System 1.0 by manipulating the ID parame...
Jul 30, 2024This CVE describes a SQL injection vulnerability in LimeSurvey's survey general settings handler. Attackers can remotely exploit this flaw by manipula...
Jul 21, 2024This vulnerability in EJBCA Enterprise 8.0 allows attackers to manipulate HTTP Host headers to redirect clients to malicious servers. By exploiting th...
Mar 31, 2025In Roo Code versions before 3.20.3, the AI agent's search_files tool could read sensitive files outside the VS Code workspace when disabled reads were...
Jun 27, 2025This CVE describes a command injection vulnerability in Ilevia EVE X1 Server's leaf_search.php file, allowing remote attackers to execute arbitrary co...
Dec 8, 2025This critical vulnerability in Qualitor 8.20/8.24 allows remote attackers to execute arbitrary commands through command injection in the Office 365 co...
May 25, 2025This CSV injection vulnerability in Axosoft Scrum and Bug Tracking allows attackers to inject malicious formulas into the Title field when adding work...
Oct 5, 2025This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by manipulating the delete_list parameter in the D...
Sep 25, 2025This critical SQL injection vulnerability in WEB-Sekolah 1.0 allows remote attackers to execute arbitrary SQL commands via the Name parameter in /Pros...
Nov 5, 2024This vulnerability in jsPDF allows attackers to inject arbitrary XML metadata into generated PDFs by controlling the first argument of the addMetadata...
Feb 2, 2026This CVE describes a SQL injection vulnerability in bluelabsio records-mover up to version 1.5.4, specifically in the Table Object Handler component. ...
Jan 7, 2026CVE-2025-5151 is a critical code injection vulnerability in defog-ai introspect's execute_analysis_code_safely function that allows attackers to execu...
May 25, 2025This CVE describes an injection vulnerability in Hubble CLI where network attackers can inject malicious control characters into terminal output when ...
May 20, 2025A critical code injection vulnerability exists in handrew browserpilot's GPTSeleniumAgent function where malicious instructions can execute arbitrary ...
May 2, 2025This critical vulnerability in thautwarm's vscode-diana extension allows injection attacks through the Jinja2 template handler. Attackers with local a...
Apr 19, 2025This critical vulnerability in InternLM LMDeploy allows code injection through manipulation of the Open function in the configuration file. Attackers ...
Apr 3, 2025PowerCMS versions before 6.6.1, 5.2.8, and 4.5.9 contain an HTTP header injection vulnerability (CWE-74) that allows attackers to manipulate email con...
Mar 27, 2025This vulnerability in Telstra Smart Modem Gen 2 allows remote attackers to inject malicious content via manipulated HTTP Content-Disposition headers. ...
Jan 24, 2025This CVE describes a code injection vulnerability in the PPOM for WooCommerce WordPress plugin. Attackers can inject malicious code that gets executed...
Jun 10, 2024This CVE describes a CRLF injection vulnerability in Ritlabs TinyWeb Server 1.94 that allows attackers to inject arbitrary HTTP headers or split respo...
May 22, 2024Pega Platform versions 8.1 through Infinity 24.1.2 contain an HTML injection vulnerability in the Stage component that allows attackers to inject mali...
Sep 12, 2024This CVE describes a command injection vulnerability in the EFM ipTIME A3004T router's administrator password handler. Attackers can execute arbitrary...
Dec 11, 2025This critical vulnerability in Apereo CAS 5.2.6 allows remote attackers to execute arbitrary code through the Groovy Code Handler component. The vulne...
Apr 27, 2025This CVE describes a command injection vulnerability in Comfast CF-AC100 routers version 2.6.0.8. Attackers can execute arbitrary commands remotely by...
Mar 9, 2026This vulnerability allows remote attackers to execute SQL injection attacks via the Date parameter in the /daily-task-report.php file of SourceCodeste...
Mar 8, 2026This SQL injection vulnerability in Simple Flight Ticket Booking System 1.0 allows attackers to execute arbitrary SQL commands through the /Adminupdat...
Mar 8, 2026This CVE describes a command injection vulnerability in Wavlink NU516U1 routers affecting the firewall.cgi component. Attackers can remotely execute a...
Mar 8, 2026This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-NU516U1 routers by exploiting a command injection flaw in the f...
Mar 7, 2026This SQL injection vulnerability in itsourcecode College Management System 1.0 allows attackers to manipulate database queries through the course_code...
Mar 3, 2026This CVE describes a command injection vulnerability in D-Link DCS-931L IP cameras. Attackers can remotely execute arbitrary commands by manipulating ...
Feb 9, 2026This CVE describes a SQL injection vulnerability in PHPGurukul Hospital Management System 4.0, specifically in the /admin/manage-users.php file's ID p...
Feb 8, 2026This CVE describes a command injection vulnerability in D-Link DIR-600 routers affecting the ssdp.cgi component. Attackers can remotely execute arbitr...
Feb 8, 2026CVE-2026-2162 is an SQL injection vulnerability in itsourcecode News Portal Project 1.0 that allows attackers to manipulate database queries through t...
Feb 8, 2026This CVE describes a SQL injection vulnerability in PHPGurukul Hospital Management System 4.0, specifically in the /hms/admin/manage-doctors.php file ...
Feb 8, 2026This vulnerability allows remote attackers to execute arbitrary commands on DCN DCME-320 devices through command injection in the Web Management Backe...
Feb 6, 2026This SQL injection vulnerability in iomad's Company Admin Block allows remote attackers to execute arbitrary SQL commands on affected systems. Organiz...
Feb 5, 2026This CVE describes a command injection vulnerability in Tenda HG10 routers affecting the /boaform/formSysCmd endpoint. Attackers can execute arbitrary...
Jan 30, 2026This vulnerability allows remote attackers to execute arbitrary SQL commands through the AdminAddCategory.php file in code-projects Online Music Site ...
Jan 28, 2026About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free