CWE-74: Injection

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

2,164
Total CVEs
103
Critical
1,273
High
7.0
Avg CVSS
2
In CISA KEV

Yearly Trend

2026
219
2025
1,633
2024
163
2023
62
2022
24

Top Affected Vendors

1 Phpgurukul 259
2 Fabian 191
3 Campcodes 170
4 Code Projects 125
5 Angeljudesuarez 86
6 Projectworlds 62
7 Anisha 53
8 Carmelo 51
9 1000projects 45
10 Oretnom23 43

All Injection CVEs (2,164)

CVE-2024-41122
7.5

This vulnerability in Woodpecker CI/CD allows any user to create malicious workflows that can lead to host takeover of the agent executing the workflo...

Jul 19, 2024
CVE-2024-29896
7.5

CVE-2024-29896 is an injection vulnerability in Astro-Shield's automated CSP header generation feature. When enabled with user-controllable content, i...

Mar 28, 2024
CVE-2023-36260
7.5

The Feed Me plugin 4.6.1 for Craft CMS contains a denial of service vulnerability where remote attackers can submit crafted strings to Feed-Me Name an...

Jan 30, 2024
CVE-2023-32786
7.5

This vulnerability in Langchain allows attackers to inject malicious prompts that force the service to retrieve data from arbitrary URLs, enabling ser...

Oct 20, 2023
CVE-2023-43667
7.5

This CVE describes a log injection vulnerability in Apache InLong that allows attackers to inject malicious content into log files. This affects Apach...

Oct 16, 2023
CVE-2023-25141
7.5

This critical vulnerability in Apache Sling JCR Base allows remote code execution through JNDI/RMI injection when running on older JDK versions. Attac...

Feb 14, 2023
CVE-2022-29631
7.5

CVE-2022-29631 is a CRLF injection vulnerability in Jodd HTTP library that allows attackers to perform Server-Side Request Forgery (SSRF) attacks. By ...

Jun 6, 2022
CVE-2022-27924
7.5

CVE-2022-27924 is an unauthenticated memcache command injection vulnerability in Zimbra Collaboration Suite. It allows attackers to overwrite arbitrar...

Apr 21, 2022
CVE-2022-28345
7.5

This vulnerability in Signal for iOS allows attackers to spoof URLs using Right-to-Left Override (RTLO) characters combined with non-breaking spaces a...

Apr 15, 2022
CVE-2022-0391
7.5

This vulnerability in Python's urllib.parse module allows injection attacks via crafted URLs containing carriage return (\r) or line feed (\n) charact...

Feb 9, 2022
CVE-2021-37262
7.5

CVE-2021-37262 is a regex injection vulnerability in JFinal_cms 5.1.0 that allows attackers to craft malicious regular expressions, causing excessive ...

Dec 16, 2021
CVE-2021-37033
7.5

This is an injection vulnerability in Huawei smartphones that allows attackers to inject malicious input into affected systems. Successful exploitatio...

Nov 23, 2021
CVE-2021-37933
7.5

This LDAP injection vulnerability in Huntflow Enterprise allows unauthenticated remote attackers to bypass authentication by manipulating the email pa...

Oct 14, 2021
CVE-2021-38371
7.5

This vulnerability in Exim's STARTTLS implementation allows attackers to inject malicious responses during SMTP communication by exploiting buffering ...

Aug 10, 2021
CVE-2020-23148
7.5

This LDAP injection vulnerability in rConfig allows attackers to manipulate LDAP queries by sending crafted POST requests to the login endpoint. Attac...

Aug 9, 2021
CVE-2021-32558
7.5

This vulnerability in Asterisk IAX2 channel driver allows remote attackers to crash the service by sending packets with unsupported media formats. It ...

Jul 30, 2021
CVE-2021-29702
7.5

CVE-2021-29702 is a denial-of-service vulnerability in IBM Db2 where a specially crafted SELECT statement causes the database server to crash and term...

Jun 16, 2021
CVE-2021-33668
7.5

CVE-2021-33668 is an LDAP injection vulnerability in SAP's SCIMono software that allows unauthenticated attackers to inject malicious LDAP queries. Th...

Jun 9, 2021
CVE-2021-31402
7.5

CVE-2021-31402 is a CRLF injection vulnerability in the Dio HTTP client package for Dart. Attackers who can control the HTTP method string can inject ...

Apr 15, 2021
CVE-2021-21420
7.5

The vscode-stripe extension for Visual Studio Code contains a vulnerability where loading untrusted repositories with malicious settings could allow a...

Apr 1, 2021
CVE-2020-35564
7.5

CVE-2020-35564 is an injection vulnerability in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software that allows attackers to execute malicious code...

Feb 16, 2021
CVE-2021-23335
7.5

CVE-2021-23335 is an LDAP injection vulnerability in the is-user-valid npm package that allows attackers to manipulate LDAP queries. This can lead to ...

Feb 11, 2021
CVE-2021-21305
7.4

CarrierWave versions before 1.3.2 and 2.1.1 contain a code injection vulnerability in the #manipulate! method that allows remote code execution. Attac...

Feb 8, 2021
CVE-2026-3413
7.3

This SQL injection vulnerability in itsourcecode University Management System 1.0 allows attackers to manipulate database queries through the ID param...

Mar 2, 2026
CVE-2026-3411
7.3

This SQL injection vulnerability in itsourcecode University Management System 1.0 allows attackers to manipulate database queries through the /admin_s...

Mar 2, 2026
CVE-2026-3409
7.3

This CVE-2026-3409 vulnerability allows remote attackers to execute arbitrary code through a code injection flaw in the Flow Import Endpoint of eospho...

Mar 2, 2026
CVE-2026-3406
7.3

This SQL injection vulnerability in Online Art Gallery Shop 1.0 allows attackers to manipulate database queries through the registration form's fname ...

Mar 2, 2026
CVE-2026-3395
7.3

This vulnerability allows remote attackers to execute arbitrary code on MaxSite CMS installations through a code injection flaw in the MarkItUp Previe...

Mar 1, 2026
CVE-2026-3164
7.3

This SQL injection vulnerability in itsourcecode News Portal Project 1.0 allows attackers to manipulate database queries through the pagetitle paramet...

Feb 25, 2026
CVE-2026-3151
7.3

CVE-2026-3151 is an SQL injection vulnerability in itsourcecode College Management System 1.0 that allows attackers to manipulate database queries thr...

Feb 25, 2026
CVE-2026-3153
7.3

This SQL injection vulnerability in itsourcecode Document Management System 1.0 allows attackers to execute arbitrary SQL commands via the Username pa...

Feb 25, 2026
CVE-2026-3135
7.3

This SQL injection vulnerability in itsourcecode News Portal Project 1.0 allows attackers to manipulate database queries through the Category paramete...

Feb 25, 2026
CVE-2026-3133
7.3

This SQL injection vulnerability in itsourcecode Document Management System 1.0 allows attackers to manipulate database queries through the login page...

Feb 25, 2026
CVE-2026-3069
7.3

CVE-2026-3069 is an SQL injection vulnerability in itsourcecode Document Management System 1.0 that allows remote attackers to execute arbitrary SQL c...

Feb 24, 2026
CVE-2026-3068
7.3

CVE-2026-3068 is a SQL injection vulnerability in itsourcecode Document Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Feb 24, 2026
CVE-2026-3046
7.3

This SQL injection vulnerability in itsourcecode E-Logbook with Health Monitoring System for COVID-19 1.0 allows attackers to execute arbitrary SQL co...

Feb 24, 2026
CVE-2026-3042
7.3

This SQL injection vulnerability in itsourcecode Event Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID para...

Feb 24, 2026
CVE-2026-2912
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows remote attackers to manipulate database queries through the test_i...

Feb 22, 2026
CVE-2026-2867
7.3

CVE-2026-2867 is an SQL injection vulnerability in itsourcecode Vehicle Management System 1.0 that allows remote attackers to execute arbitrary SQL co...

Feb 21, 2026
CVE-2026-2865
7.3

This SQL injection vulnerability in Agri-Trading Online Shopping System 1.0 allows attackers to execute arbitrary SQL commands via manipulated Product...

Feb 21, 2026
CVE-2026-2821
7.3

This CVE describes a SQL injection vulnerability in Fujian Smart Integrated Management Platform System that allows attackers to execute arbitrary SQL ...

Feb 20, 2026
CVE-2026-2820
7.3

This SQL injection vulnerability in Fujian Smart Integrated Management Platform System allows remote attackers to execute arbitrary SQL commands via t...

Feb 20, 2026
CVE-2026-2689
7.3

This SQL injection vulnerability in itsourcecode Event Management System 1.0 allows attackers to manipulate database queries through the /admin/manage...

Feb 19, 2026
CVE-2026-2691
7.3

This SQL injection vulnerability in itsourcecode Event Management System 1.0 allows attackers to manipulate database queries through the ID parameter ...

Feb 19, 2026
CVE-2026-2621
7.3

This SQL injection vulnerability in Sciyon Koyuan Thermoelectricity Heat Network Management System 3.0 allows remote attackers to execute arbitrary SQ...

Feb 17, 2026
CVE-2026-2620
7.3

This SQL injection vulnerability in Huace Monitoring and Early Warning System 2.2 allows remote attackers to execute arbitrary SQL commands via the ID...

Feb 17, 2026
CVE-2026-2533
7.3

This CVE describes a command injection vulnerability in Tosei Self-service Washing Machine software version 4.02. Attackers can remotely execute arbit...

Feb 16, 2026
CVE-2026-2225
7.3

CVE-2026-2225 is a SQL injection vulnerability in itsourcecode News Portal Project 1.0 that allows remote attackers to execute arbitrary SQL commands ...

Feb 9, 2026
CVE-2026-2223
7.3

This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID para...

Feb 9, 2026
CVE-2026-2220
7.3

CVE-2026-2220 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0 that allows remote attackers to execute arbitrary SQL comma...

Feb 9, 2026

About Injection (CWE-74)

The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.

Our database tracks 2,164 CVEs classified as CWE-74, with 103 rated critical and 1,273 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.

External reference: View CWE-74 on MITRE CWE →

Monitor Injection Vulnerabilities

Get alerted when new Injection CVEs affect your infrastructure.

Start Monitoring Free