CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,264
Total CVEs
133
Critical
1,328
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
245
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 87
6 Projectworlds 64
7 Carmelo 58
8 Anisha 53
9 Oretnom23 46
10 1000projects 45

All Injection CVEs (2,264)

CVE-2024-11096
6.3

This critical SQL injection vulnerability in code-projects Task Manager 1.0 allows remote attackers to execute arbitrary SQL commands via the projectN...

Nov 12, 2024
CVE-2024-11074
6.3

This critical SQL injection vulnerability in Tailoring Management System 1.0 allows remote attackers to execute arbitrary SQL commands through the /in...

Nov 11, 2024
CVE-2024-11059
6.3

This CVE describes a critical SQL injection vulnerability in Project Worlds Free Download Online Shopping System. Attackers can remotely exploit the /...

Nov 11, 2024
CVE-2024-11051
6.3

This critical SQL injection vulnerability in AMTT Hotel Broadband Operation System allows attackers to manipulate database queries via the AccountID p...

Nov 10, 2024
CVE-2024-10997
6.3

This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...

Nov 8, 2024
CVE-2024-10990
6.3

This critical SQL injection vulnerability in SourceCodester Online Veterinary Appointment System 1.0 allows remote attackers to execute arbitrary SQL ...

Nov 8, 2024
CVE-2024-10987
6.3

This critical SQL injection vulnerability in E-Health Care System 1.0 allows remote attackers to execute arbitrary SQL commands via manipulated parame...

Nov 8, 2024
CVE-2024-10805
6.3

This critical SQL injection vulnerability in University Event Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ...

Nov 4, 2024
CVE-2024-10700
6.3

This critical SQL injection vulnerability in University Event Management System 1.0 allows attackers to manipulate database queries through the submit...

Nov 2, 2024
CVE-2024-10697
6.3

This vulnerability allows remote attackers to execute arbitrary commands on Tenda AC6 routers by injecting malicious commands into the 'mac' parameter...

Nov 2, 2024
CVE-2024-10153
6.3

This vulnerability allows remote attackers to execute SQL injection attacks on PHPGurukul Boat Booking System 1.0 by manipulating bookingdatefrom/nope...

Oct 19, 2024
CVE-2024-9324
6.3

This critical vulnerability in Intelbras InControl allows remote attackers to execute arbitrary code through code injection in the Relatório de Opera...

Sep 29, 2024
CVE-2024-7221
6.3

This vulnerability allows remote attackers to execute SQL injection attacks against the School Log Management System 1.0 by manipulating the ID parame...

Jul 30, 2024
CVE-2024-6933
6.3

This CVE describes a SQL injection vulnerability in LimeSurvey's survey general settings handler. Attackers can remotely exploit this flaw by manipula...

Jul 21, 2024
CVE-2025-3026
6.1

This vulnerability in EJBCA Enterprise 8.0 allows attackers to manipulate HTTP Host headers to redirect clients to malicious servers. By exploiting th...

Mar 31, 2025
CVE-2025-53097
5.9

In Roo Code versions before 3.20.3, the AI agent's search_files tool could read sensitive files outside the VS Code workspace when disabled reads were...

Jun 27, 2025
CVE-2025-14276
5.6

This CVE describes a command injection vulnerability in Ilevia EVE X1 Server's leaf_search.php file, allowing remote attackers to execute arbitrary co...

Dec 8, 2025
CVE-2025-5139
5.6

This critical vulnerability in Qualitor 8.20/8.24 allows remote attackers to execute arbitrary commands through command injection in the Office 365 co...

May 25, 2025
CVE-2025-11279
5.5

This CSV injection vulnerability in Axosoft Scrum and Bug Tracking allows attackers to inject malicious formulas into the Title field when adding work...

Oct 5, 2025
CVE-2025-10961
5.5

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink NU516U1 routers by manipulating the delete_list parameter in the D...

Sep 25, 2025
CVE-2024-10841
5.5

This critical SQL injection vulnerability in WEB-Sekolah 1.0 allows remote attackers to execute arbitrary SQL commands via the Name parameter in /Pros...

Nov 5, 2024
CVE-2026-24043
5.4

This vulnerability in jsPDF allows attackers to inject arbitrary XML metadata into generated PDFs by controlling the first argument of the addMetadata...

Feb 2, 2026
CVE-2023-7333
5.3

This CVE describes a SQL injection vulnerability in bluelabsio records-mover up to version 1.5.4, specifically in the Table Object Handler component. ...

Jan 7, 2026
CVE-2025-5151
5.3

CVE-2025-5151 is a critical code injection vulnerability in defog-ai introspect's execute_analysis_code_safely function that allows attackers to execu...

May 25, 2025
CVE-2025-48056
5.3

This CVE describes an injection vulnerability in Hubble CLI where network attackers can inject malicious control characters into terminal output when ...

May 20, 2025
CVE-2025-4218
5.3

A critical code injection vulnerability exists in handrew browserpilot's GPTSeleniumAgent function where malicious instructions can execute arbitrary ...

May 2, 2025
CVE-2025-3804
5.3

This critical vulnerability in thautwarm's vscode-diana extension allows injection attacks through the Jinja2 template handler. Attackers with local a...

Apr 19, 2025
CVE-2025-3163
5.3

This critical vulnerability in InternLM LMDeploy allows code injection through manipulation of the Open function in the configuration file. Attackers ...

Apr 3, 2025
CVE-2025-29993
5.3

PowerCMS versions before 6.6.1, 5.2.8, and 4.5.9 contain an HTTP header injection vulnerability (CWE-74) that allows attackers to manipulate email con...

Mar 27, 2025
CVE-2025-0697
5.3

This vulnerability in Telstra Smart Modem Gen 2 allows remote attackers to inject malicious content via manipulated HTTP Content-Disposition headers. ...

Jan 24, 2025
CVE-2024-35728
5.3

This CVE describes a code injection vulnerability in the PPOM for WooCommerce WordPress plugin. Attackers can inject malicious code that gets executed...

Jun 10, 2024
CVE-2024-5193
5.3

This CVE describes a CRLF injection vulnerability in Ritlabs TinyWeb Server 1.94 that allows attackers to inject arbitrary HTTP headers or split respo...

May 22, 2024
CVE-2024-6702
5.2

Pega Platform versions 8.1 through Infinity 24.1.2 contain an HTML injection vulnerability in the Stage component that allows attackers to inject mali...

Sep 12, 2024
CVE-2025-14485
5.0

This CVE describes a command injection vulnerability in the EFM ipTIME A3004T router's administrator password handler. Attackers can execute arbitrary...

Dec 11, 2025
CVE-2025-3984
5.0

This critical vulnerability in Apereo CAS 5.2.6 allows remote attackers to execute arbitrary code through the Groovy Code Handler component. The vulne...

Apr 27, 2025
CVE-2026-3798
4.7

This CVE describes a command injection vulnerability in Comfast CF-AC100 routers version 2.6.0.8. Attackers can execute arbitrary commands remotely by...

Mar 9, 2026
CVE-2026-3752
4.7

This vulnerability allows remote attackers to execute SQL injection attacks via the Date parameter in the /daily-task-report.php file of SourceCodeste...

Mar 8, 2026
CVE-2026-3711
4.7

This SQL injection vulnerability in Simple Flight Ticket Booking System 1.0 allows attackers to execute arbitrary SQL commands through the /Adminupdat...

Mar 8, 2026
CVE-2026-3704
4.7

This CVE describes a command injection vulnerability in Wavlink NU516U1 routers affecting the firewall.cgi component. Attackers can remotely execute a...

Mar 8, 2026
CVE-2026-3661
4.7

This vulnerability allows remote attackers to execute arbitrary commands on Wavlink WL-NU516U1 routers by exploiting a command injection flaw in the f...

Mar 7, 2026
CVE-2026-3487
4.7

This SQL injection vulnerability in itsourcecode College Management System 1.0 allows attackers to manipulate database queries through the course_code...

Mar 3, 2026
CVE-2026-2227
4.7

This CVE describes a command injection vulnerability in D-Link DCS-931L IP cameras. Attackers can remotely execute arbitrary commands by manipulating ...

Feb 9, 2026
CVE-2026-2179
4.7

This CVE describes a SQL injection vulnerability in PHPGurukul Hospital Management System 4.0, specifically in the /admin/manage-users.php file's ID p...

Feb 8, 2026
CVE-2026-2163
4.7

This CVE describes a command injection vulnerability in D-Link DIR-600 routers affecting the ssdp.cgi component. Attackers can remotely execute arbitr...

Feb 8, 2026
CVE-2026-2162
4.7

CVE-2026-2162 is an SQL injection vulnerability in itsourcecode News Portal Project 1.0 that allows attackers to manipulate database queries through t...

Feb 8, 2026
CVE-2026-2134
4.7

This CVE describes a SQL injection vulnerability in PHPGurukul Hospital Management System 4.0, specifically in the /hms/admin/manage-doctors.php file ...

Feb 8, 2026
CVE-2026-2000
4.7

This vulnerability allows remote attackers to execute arbitrary commands on DCN DCME-320 devices through command injection in the Web Management Backe...

Feb 6, 2026
CVE-2026-1517
4.7

This SQL injection vulnerability in iomad's Company Admin Block allows remote attackers to execute arbitrary SQL commands on affected systems. Organiz...

Feb 5, 2026
CVE-2026-1690
4.7

This CVE describes a command injection vulnerability in Tenda HG10 routers affecting the /boaform/formSysCmd endpoint. Attackers can execute arbitrary...

Jan 30, 2026
CVE-2026-1533
4.7

This vulnerability allows remote attackers to execute arbitrary SQL commands through the AdminAddCategory.php file in code-projects Online Music Site ...

Jan 28, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free