CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,264)
This CVE describes a command injection vulnerability in D-Link DCS700l IP cameras running firmware version 1.03.09. Attackers can remotely execute arb...
Jan 26, 2026This vulnerability allows remote attackers to execute arbitrary commands on Bastillion systems through command injection in the System Management Modu...
Jan 17, 2026This CVE describes a command injection vulnerability in Bastillion's Public Key Management System that allows remote attackers to execute arbitrary co...
Jan 17, 2026This CVE describes a SQL injection vulnerability in code-projects Intern Membership Management System 1.0. Attackers can exploit the activity_id param...
Jan 11, 2026This SQL injection vulnerability in Intern Membership Management System 1.0 allows attackers to manipulate database queries through the Username param...
Jan 8, 2026This SQL injection vulnerability in Intern Membership Management System 1.0 allows attackers to manipulate database queries through the activity_id pa...
Jan 8, 2026This SQL injection vulnerability in Intern Membership Management System 1.0 allows remote attackers to manipulate database queries via the admin_id pa...
Jan 8, 2026This CVE describes a SQL injection vulnerability in code-projects Intern Membership Management System 1.0. Attackers can remotely exploit the /intern/...
Jan 8, 2026This SQL injection vulnerability in CRMEB allows attackers to manipulate database queries through the cate_id parameter in the product export endpoint...
Jan 4, 2026This SQL injection vulnerability in CRMEB allows attackers to manipulate database queries through the cate_id parameter in the product export endpoint...
Jan 4, 2026This CVE describes a SQL injection vulnerability in the User Handler component of PKrystian Full-Stack-Bank. Attackers can remotely exploit this vulne...
Dec 31, 2025This vulnerability allows remote attackers to execute arbitrary code on iCMS systems through code injection in the configuration parameter handler. At...
Dec 31, 2025This vulnerability allows remote attackers to execute SQL injection attacks against BiggiDroid Simple PHP CMS 1.0 by manipulating the ID parameter in ...
Dec 29, 2025CVE-2025-15148 is a code injection vulnerability in CmsEasy's backend template management that allows attackers to execute arbitrary code by manipulat...
Dec 28, 2025This SQL injection vulnerability in EyouCMS allows attackers to manipulate database queries through the backend template management component. It affe...
Dec 28, 2025This vulnerability allows remote attackers to execute arbitrary code through the addPost function in SyCms's administrative panel. It affects all vers...
Dec 28, 2025This vulnerability allows remote attackers to execute SQL injection attacks against SeaCMS versions up to 13.3 through manipulation of the e_id parame...
Dec 22, 2025This SQL injection vulnerability in FastAdmin's Backend Controller allows attackers to execute arbitrary SQL commands by manipulating the custom/searc...
Dec 19, 2025This SQL injection vulnerability in Online Appointment Booking System 1.0 allows attackers to manipulate database queries through the managername para...
Dec 19, 2025This SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 allows attackers to manipulate database queries through the /admin/sta...
Dec 19, 2025CVE-2025-14900 is an SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 that allows attackers to manipulate database queries v...
Dec 19, 2025CVE-2025-14898 is an SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 that allows attackers to execute arbitrary SQL command...
Dec 19, 2025This SQL injection vulnerability in CodeAstro Real Estate Management System 1.0 allows attackers to execute arbitrary SQL commands via the /admin/user...
Dec 19, 2025This vulnerability in ZZCMS 2025 allows remote attackers to inject malicious code through the 'icp' parameter in the backend site configuration module...
Dec 18, 2025This vulnerability allows remote attackers to execute arbitrary code on CTCMS Content Management System installations through code injection in the ba...
Dec 15, 2025This vulnerability allows remote attackers to execute arbitrary code on CTCMS Content Management System installations up to version 2.1.2. The flaw ex...
Dec 15, 2025This CVE describes a SQL injection vulnerability in ketr JEPaaS versions up to 7.2.8. Attackers can remotely exploit the readAllPostil function by man...
Dec 15, 2025This vulnerability allows remote attackers to execute arbitrary commands on DedeBIZ systems through command injection in the catalog_add.php file. Att...
Dec 14, 2025This CSV injection vulnerability in SourceCodester Inventory Management System 1.0 allows attackers to inject malicious formulas into exported CSV fil...
Dec 8, 2025This vulnerability allows remote attackers to execute SQL injection attacks against AMTT Hotel Broadband Operation System 1.0 by manipulating the ID p...
Dec 5, 2025This SQL injection vulnerability in JIZHICMS allows remote attackers to manipulate database queries through the aid/tid parameters in the comment func...
Dec 4, 2025This SQL injection vulnerability in JIZHICMS allows attackers to execute arbitrary SQL commands through the batch comment deletion functionality. Atta...
Dec 4, 2025This SQL injection vulnerability in SourceCodester Online Student Clearance System 1.0 allows attackers to manipulate database queries through the pas...
Nov 24, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_product.php file via the txtProductName parameter. T...
Nov 20, 2025CVE-2025-13302 is an SQL injection vulnerability in code-projects Courier Management System 1.0 that allows attackers to manipulate database queries t...
Nov 17, 2025CVE-2025-13075 is an SQL injection vulnerability in Responsive Hotel Site 1.0's admin/usersettingdel.php file that allows attackers to manipulate data...
Nov 12, 2025CVE-2025-13076 is an SQL injection vulnerability in Responsive Hotel Site 1.0 that allows remote attackers to execute arbitrary SQL commands via the '...
Nov 12, 2025This SQL injection vulnerability in SourceCodester Baby Care System 1.0 allows attackers to manipulate database queries through the msgid parameter in...
Nov 10, 2025This SQL injection vulnerability in aaPanel BaoTa's backend allows attackers to manipulate database queries through the /database?action=GetDatabaseAc...
Nov 8, 2025CVE-2025-12913 is a SQL injection vulnerability in Responsive Hotel Site 1.0 that allows remote attackers to manipulate database queries through the I...
Nov 8, 2025This SQL injection vulnerability in Campcodes School File Management 1.0 allows attackers to manipulate database queries through the user_id parameter...
Nov 7, 2025This CVE describes an SQL injection vulnerability in DedeBIZ content management system. Attackers can manipulate the 'orderby' parameter in /admin/fre...
Nov 7, 2025This vulnerability allows remote attackers to execute SQL injection attacks against DedeBIZ content management systems through the /admin/templets_one...
Nov 7, 2025CVE-2025-12855 is an SQL injection vulnerability in Responsive Hotel Site 1.0's newsletterdel.php admin file. Attackers can manipulate the 'eid' param...
Nov 7, 2025CVE-2025-12856 is a SQL injection vulnerability in Responsive Hotel Site 1.0's reservation.php admin endpoint. Attackers can manipulate the email para...
Nov 7, 2025CVE-2025-12857 is an SQL injection vulnerability in Responsive Hotel Site 1.0's roombook.php admin file that allows attackers to manipulate database q...
Nov 7, 2025This SQL injection vulnerability in SourceCodester Best House Rental Management System 1.0 allows attackers to manipulate database queries through the...
Nov 7, 2025CodeAstro Gym Management System 1.0 contains a SQL injection vulnerability in the /admin/view-progress-report.php file through manipulation of the ID ...
Nov 3, 2025This SQL injection vulnerability in Simple Online Hotel Reservation System 2.0 allows attackers to manipulate database queries through the Name parame...
Nov 2, 2025This vulnerability is an SQL injection flaw in the Food Ordering System 1.0 by code-projects, specifically in the /admin/deleteitem.php file via the i...
Oct 27, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free