CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,264)
This SQL injection vulnerability in code-projects Food Ordering System 1.0 allows attackers to manipulate database queries through the itemPrice param...
Oct 27, 2025This SQL injection vulnerability in Bdtask Wholesale Inventory Control and Inventory Management System allows attackers to manipulate database queries...
Oct 27, 2025This SQL injection vulnerability in Vvveb CMS allows attackers to execute arbitrary SQL commands through the Raw SQL Handler import function. It affec...
Oct 19, 2025This SQL injection vulnerability in code-projects Automated Voting System 1.0 allows attackers to manipulate database queries through the Password par...
Oct 13, 2025This SQL injection vulnerability in Campcodes Online Beauty Parlor Management System 1.0 allows attackers to manipulate database queries through the '...
Oct 13, 2025This vulnerability allows SQL injection through the mobilenumber parameter in the /admin-profile.php file of Campcodes Online Apartment Visitor Manage...
Oct 11, 2025CVE-2025-11342 is a SQL injection vulnerability in code-projects Online Course Registration 1.0 that allows attackers to manipulate database queries t...
Oct 6, 2025This vulnerability allows remote attackers to execute arbitrary commands on Keyfactor RG-EW5100BE devices by injecting malicious commands through the ...
Sep 27, 2025This vulnerability allows remote attackers to execute arbitrary code through template management functionality in MuYuCMS. It affects all installation...
Sep 26, 2025This SQL injection vulnerability in SeaCMS allows attackers to manipulate database queries through the /admin_members.php endpoint. Attackers can pote...
Sep 18, 2025This CVE describes a code injection vulnerability in the fcba_zzm ics-park Smart Park Management System 2.0, specifically in the Scheduled Task Module...
Sep 14, 2025This SQL injection vulnerability in Maccms10 allows attackers to manipulate database queries through the 'where' parameter in the 'rep' function. Atta...
Sep 9, 2025This SQL injection vulnerability in SourceCodester Pet Grooming Management Software 1.0 allows attackers to manipulate database queries through the pr...
Sep 8, 2025This SQL injection vulnerability in RemoteClinic 2.0 allows attackers to manipulate database queries through the ID parameter in /staff/profile.php. A...
Sep 2, 2025This critical SQL injection vulnerability in the itsourcecode Employee Management System allows attackers to manipulate database queries through the c...
Jul 7, 2025This critical SQL injection vulnerability in Campcodes Complaint Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
Jul 7, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /admin/testimonials/manage.php file of Source...
Jun 29, 2025CVE-2025-6867 is a critical SQL injection vulnerability in SourceCodester Simple Company Website 1.0 that allows remote attackers to execute arbitrary...
Jun 29, 2025This SQL injection vulnerability in code-projects Product Inventory System 1.0 allows attackers to manipulate database queries through the ID paramete...
Jun 29, 2025This is a critical SQL injection vulnerability in the like-girl software version 5.2.0. Attackers can remotely exploit the /admin/ipAddPost.php file b...
Jun 12, 2025This critical SQL injection vulnerability in kiCode111 like-girl 5.2.0 allows remote attackers to execute arbitrary SQL commands via the /admin/ImgUpd...
Jun 12, 2025This CVE describes a critical SQL injection vulnerability in kiCode111 like-girl version 5.2.0. Attackers can exploit the /admin/ImgAddPost.php file b...
Jun 12, 2025This critical SQL injection vulnerability in SourceCodester Client Database Management System 1.0 allows attackers to execute arbitrary SQL commands v...
May 26, 2025This CVE describes a critical code injection vulnerability in DedeCMS 5.7.117 that allows remote attackers to execute arbitrary code by manipulating t...
May 25, 2025This vulnerability allows unauthenticated remote attackers to inject HTML content into authenticated users' browsers via the Cisco Catalyst SD-WAN Man...
May 7, 2025This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands via the e_id parameter in the /admin_top...
Apr 19, 2025This critical SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through the /admin_link.php endpoint. At...
Apr 18, 2025This critical vulnerability in WuzhiCMS 4.1 allows remote attackers to execute arbitrary code through code injection in the Setting Handler component....
Apr 14, 2025A critical SQL injection vulnerability exists in CodeZips Hospital Management System 1.0 via the /suadpeted.php file's ID parameter. This allows remot...
Mar 23, 2025This critical vulnerability in code-projects Online Class and Exam Scheduling System 1.0 allows remote attackers to execute SQL injection attacks via ...
Mar 17, 2025This critical SQL injection vulnerability in code-projects Online Class and Exam Scheduling System 1.0 allows remote attackers to execute arbitrary SQ...
Mar 17, 2025This critical SQL injection vulnerability in ftcms 2.1 allows remote attackers to execute arbitrary SQL commands through the name parameter in the sea...
Mar 9, 2025This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the state_...
Mar 7, 2025This is a critical SQL injection vulnerability in code-projects Blood Bank Management System 1.0 that allows attackers to manipulate database queries ...
Mar 6, 2025This critical SQL injection vulnerability in Blood Bank Management System 1.0 allows attackers to execute arbitrary SQL commands via the member_id par...
Mar 6, 2025This critical SQL injection vulnerability in PHPGurukul Restaurant Table Booking System 1.0 allows attackers to manipulate database queries through th...
Mar 4, 2025This vulnerability in ShopXO allows remote attackers to perform injection attacks through the template handler component. It affects all ShopXO instal...
Feb 24, 2025This critical SQL injection vulnerability in 1000 Projects Bookstore Management System 1.0 allows remote attackers to execute arbitrary SQL commands v...
Feb 11, 2025This critical SQL injection vulnerability in Pimcore Customer Data Framework allows remote attackers to execute arbitrary SQL commands via the filterD...
Jan 28, 2025This CVE describes a critical command injection vulnerability in EnGenius networking devices that allows remote attackers to execute arbitrary command...
Nov 25, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected EnGenius networking devices by injecting malicious input...
Nov 25, 2024This critical vulnerability allows remote attackers to execute arbitrary commands on affected EnGenius networking devices by injecting malicious input...
Nov 25, 2024This critical vulnerability in EnGenius wireless access points allows remote attackers to execute arbitrary commands via command injection in the trac...
Nov 25, 2024This critical vulnerability in EnGenius networking devices allows remote attackers to execute arbitrary commands by manipulating the 'https_enable' pa...
Nov 25, 2024This critical vulnerability in SourceCodester Best Employee Management System 1.0 allows authenticated attackers to perform SQL injection attacks via ...
Nov 14, 2024This vulnerability allows remote attackers to execute SQL injection attacks against the Real Estate Management System by manipulating the 'id' paramet...
Nov 10, 2024This is a SQL injection vulnerability in the Interlib Library Cluster Automation Management System that allows attackers to execute arbitrary SQL comm...
Nov 7, 2024This CVE describes a command injection vulnerability in Yealink MeetingBar A30's Diagnostic Handler component. Attackers with physical access to the d...
Feb 2, 2026This vulnerability allows attackers to inject malicious scripts into the E-Learning System's lesson module through Title/Description fields. When exec...
Jan 19, 2026This CVE describes a vulnerability in Composer PHP dependency manager where attackers controlling remote package sources could inject ANSI control cha...
Dec 30, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,264 CVEs classified as CWE-74, with 133 rated critical and 1,328 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free