CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,165)
CVE-2026-2220 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0 that allows remote attackers to execute arbitrary SQL comma...
Feb 9, 2026CVE-2026-2221 is a SQL injection vulnerability in code-projects Online Reviewer System 1.0 that allows remote attackers to execute arbitrary SQL comma...
Feb 9, 2026This SQL injection vulnerability in itsourcecode Event Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter i...
Feb 9, 2026This SQL injection vulnerability in code-projects Online Music Site 1.0 allows remote attackers to execute arbitrary SQL commands via the ID parameter...
Feb 9, 2026CVE-2026-2212 is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands v...
Feb 9, 2026This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the difficulty_id...
Feb 9, 2026This CVE describes a SQL injection vulnerability in code-projects Online Reviewer System 1.0. Attackers can remotely exploit the user-delete.php file ...
Feb 9, 2026This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the test_id param...
Feb 9, 2026This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows remote attackers to execute arbitrary SQL commands via the test_id...
Feb 9, 2026This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the ID parameter ...
Feb 9, 2026CVE-2026-2190 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Feb 8, 2026CVE-2026-2189 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Feb 8, 2026This CVE describes a SQL injection vulnerability in code-projects Online Application System for Admission 1.0, specifically in the login endpoint at e...
Feb 8, 2026CVE-2026-2173 is an SQL injection vulnerability in code-projects Online Examination System 1.0 that allows attackers to manipulate database queries th...
Feb 8, 2026This SQL injection vulnerability in Online Student Management System 1.0 allows attackers to manipulate database queries through the login form. Attac...
Feb 8, 2026This SQL injection vulnerability in code-projects Online Reviewer System 1.0 allows attackers to manipulate database queries through the login form. R...
Feb 8, 2026This SQL injection vulnerability in itsourcecode Directory Management System 1.0 allows attackers to execute arbitrary SQL commands via the email para...
Feb 8, 2026CVE-2026-2158 is a SQL injection vulnerability in code-projects Student Web Portal 1.0 that allows remote attackers to execute arbitrary SQL commands ...
Feb 8, 2026CVE-2026-2136 is a SQL injection vulnerability in projectworlds Online Food Ordering System 1.0 that allows remote attackers to execute arbitrary SQL ...
Feb 8, 2026This is a SQL injection vulnerability in code-projects Online Music Site 1.0 that allows remote attackers to execute arbitrary SQL commands via the tx...
Feb 8, 2026This vulnerability allows remote attackers to execute arbitrary SQL commands via the expenses_id parameter in the /admin/edit_expenses.php file in its...
Feb 8, 2026This is a SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL commands via...
Feb 8, 2026This vulnerability allows remote attackers to execute arbitrary SQL commands on itsourcecode Society Management System 1.0 through the /admin/delete_e...
Feb 7, 2026CVE-2026-2114 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to manipulate database queries thr...
Feb 7, 2026This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows remote attackers to execute arbitrary SQL commands via the 't...
Feb 7, 2026This SQL injection vulnerability in PHPGurukul Beauty Parlour Management System 1.1 allows attackers to manipulate database queries through the 'delid...
Feb 7, 2026This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows attackers to manipulate database queries through the ID param...
Feb 7, 2026This SQL injection vulnerability in SourceCodester Online Class Record System 1.0 allows attackers to manipulate database queries through the user_ema...
Feb 7, 2026This SQL injection vulnerability in code-projects Social Networking Site 1.0 allows attackers to manipulate database queries through the /delete_post....
Feb 7, 2026CVE-2026-2073 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Feb 7, 2026This SQL injection vulnerability in Simple Blood Donor Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID para...
Feb 6, 2026This SQL injection vulnerability in SourceCodester Medical Center Portal Management System 1.0 allows attackers to manipulate database queries through...
Feb 6, 2026This CVE describes a SQL injection vulnerability in the CloudClassroom-PHP-Project software that allows remote attackers to execute arbitrary SQL comm...
Feb 6, 2026This SQL injection vulnerability in SourceCodester Medical Center Portal Management System 1.0 allows attackers to execute arbitrary SQL commands via ...
Feb 6, 2026CVE-2026-2018 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Feb 6, 2026CVE-2026-2014 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to manipulate database queries thro...
Feb 6, 2026This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter...
Feb 6, 2026This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to execute arbitrary SQL commands through the /ramonsy...
Feb 6, 2026CVE-2026-2012 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Feb 6, 2026This CVE describes a command injection vulnerability in the Ziroom ZHOME A0101 router firmware version 1.0.1.0. Attackers can remotely execute arbitra...
Feb 3, 2026CVE-2026-1701 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Jan 30, 2026This CVE describes a remote command injection vulnerability in Tenda HG10 routers. Attackers can execute arbitrary commands on affected devices by man...
Jan 30, 2026This SQL injection vulnerability in itsourcecode Directory Management System 1.0 allows attackers to execute arbitrary SQL commands via the Username p...
Jan 30, 2026This CVE describes a command injection vulnerability in Tenda HG10 routers through the Boa webserver's formSamba endpoint. Attackers can remotely exec...
Jan 30, 2026CVE-2026-1595 is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Jan 29, 2026This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode School Management System 1.0 via the txtsearch parame...
Jan 29, 2026This SQL injection vulnerability in itsourcecode School Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the ID par...
Jan 29, 2026CVE-2026-1593 is a SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows remote attackers to execute arbitrary SQL com...
Jan 29, 2026This is an SQL injection vulnerability in itsourcecode Society Management System 1.0 that allows attackers to execute arbitrary SQL commands through t...
Jan 29, 2026CVE-2026-1545 is a SQL injection vulnerability in itsourcecode School Management System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Jan 28, 2026About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,165 CVEs classified as CWE-74, with 104 rated critical and 1,273 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free