CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,170)
CVE-2025-15243 is an SQL injection vulnerability in Simple Stock System 1.0's login.php file that allows remote attackers to execute arbitrary SQL com...
Dec 30, 2025CVE-2025-15208 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows attackers to manipulate database queries through...
Dec 29, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_area.php file via the txtAreaCode parameter. This al...
Dec 29, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/view_products.php file through manipulation of the chkId...
Dec 29, 2025CVE-2025-15198 is a SQL injection vulnerability in the College Notes Uploading System 1.0 that allows attackers to manipulate database queries through...
Dec 29, 2025CVE-2025-15196 is an SQL injection vulnerability in code-projects Assessment Management 1.0 that allows attackers to execute arbitrary SQL commands vi...
Dec 29, 2025CVE-2025-15195 is a SQL injection vulnerability in code-projects Assessment Management 1.0 that allows remote attackers to execute arbitrary SQL comma...
Dec 29, 2025This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the 'a' parameter in /h...
Dec 29, 2025CVE-2025-15185 is a SQL injection vulnerability in the Refugee Food Management System 1.0 that allows remote attackers to execute arbitrary SQL comman...
Dec 29, 2025This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to execute arbitrary SQL commands via the 'a' parameter in /ho...
Dec 29, 2025This SQL injection vulnerability in Refugee Food Management System 1.0 allows attackers to manipulate database queries through the tfid parameter in /...
Dec 29, 2025CVE-2025-15182 is a SQL injection vulnerability in code-projects Refugee Food Management System 1.0 that allows remote attackers to execute arbitrary ...
Dec 29, 2025CVE-2025-15181 is an SQL injection vulnerability in the Refugee Food Management System 1.0 that allows attackers to manipulate database queries throug...
Dec 29, 2025CVE-2025-15168 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 29, 2025CVE-2025-15167 is a SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows attackers to execute arbitrary SQL command...
Dec 29, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /updatesupplier.php?action=edit endpoint of i...
Dec 29, 2025CVE-2025-15165 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...
Dec 29, 2025This CVE describes a SQL injection vulnerability in phpok3w's show.php file through manipulation of the ID parameter. Attackers can remotely exploit t...
Dec 28, 2025This SQL injection vulnerability in the saiftheboss7 onlinemcqexam software allows attackers to manipulate database queries through the ans1/ans2 para...
Dec 28, 2025This CVE describes an SQL injection vulnerability in FantasticLBP Hotels_Server's Room.php API endpoint. Attackers can exploit the hotelId parameter t...
Dec 28, 2025This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Student Management System 1.0 through the /list_repor...
Dec 25, 2025This vulnerability allows remote attackers to execute SQL injection attacks against itsourcecode Student Management System 1.0 via the ID parameter in...
Dec 25, 2025CVE-2025-15075 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 25, 2025CVE-2025-15074 is a SQL injection vulnerability in itsourcecode Online Frozen Foods Ordering System 1.0 that allows remote attackers to execute arbitr...
Dec 25, 2025CVE-2025-15073 is an SQL injection vulnerability in itsourcecode Online Frozen Foods Ordering System 1.0 that allows remote attackers to execute arbit...
Dec 24, 2025This SQL injection vulnerability in code-projects Student Information System 1.0 allows attackers to manipulate database queries through the searchbox...
Dec 24, 2025This vulnerability allows remote attackers to execute arbitrary commands on Tenda WH450 routers by injecting malicious input into the 'ipaddress' para...
Dec 23, 2025CVE-2025-15049 is a SQL injection vulnerability in code-projects Online Farm System 1.0 that allows attackers to execute arbitrary SQL commands via th...
Dec 23, 2025CVE-2025-15034 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 23, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'a' parameter in /home/home.php in code-projects Refugee Food Man...
Dec 22, 2025This SQL injection vulnerability in Simple Stock System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'uname' parameter in /lo...
Dec 22, 2025This SQL injection vulnerability in SeaCMS allows remote attackers to execute arbitrary SQL commands through manipulated page/limit parameters in the ...
Dec 21, 2025This CVE describes a SQL injection vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0. Attackers can remotely exploit the ...
Dec 21, 2025This SQL injection vulnerability in Campcodes Complete Online Beauty Parlor Management System 1.0 allows attackers to execute arbitrary SQL commands t...
Dec 21, 2025CVE-2025-14968 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands via the ema...
Dec 19, 2025CVE-2025-14959 is an SQL injection vulnerability in Simple Stock System 1.0 that allows remote attackers to execute arbitrary SQL commands through the...
Dec 19, 2025This vulnerability allows remote attackers to execute SQL injection attacks against the Scholars Tracking System 1.0 by manipulating the post_content ...
Dec 19, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_category.php file via the txtCategoryName parameter....
Dec 19, 2025CVE-2025-14950 is an SQL injection vulnerability in code-projects Scholars Tracking System 1.0 that allows attackers to execute arbitrary SQL commands...
Dec 19, 2025This SQL injection vulnerability in Scholars Tracking System 1.0 allows attackers to execute arbitrary SQL commands via the ID parameter in /admin/del...
Dec 19, 2025This SQL injection vulnerability in Campcodes Supplier Management System 1.0 allows attackers to execute arbitrary SQL commands through the cmbAreaCod...
Dec 18, 2025This CVE describes a SQL injection vulnerability in code-projects Online Appointment Booking System 1.0. Attackers can remotely exploit the /admin/del...
Dec 17, 2025CVE-2025-14832 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...
Dec 17, 2025This SQL injection vulnerability in FantasticLBP Hotels Server allows attackers to execute arbitrary SQL commands by manipulating the 'telephone' para...
Dec 15, 2025This SQL injection vulnerability in FantasticLBP Hotels Server allows remote attackers to execute arbitrary SQL commands via the pickedHotelName/type ...
Dec 15, 2025This SQL injection vulnerability in campcodes Advanced Online Examination System 1.0 allows attackers to manipulate database queries through the Usern...
Dec 14, 2025CVE-2025-14666 is an SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comma...
Dec 14, 2025CVE-2025-14667 is a SQL injection vulnerability in itsourcecode COVID Tracking System 1.0 that allows remote attackers to execute arbitrary SQL comman...
Dec 14, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/view_unit.php file through manipulation of the chkId[] p...
Dec 14, 2025This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the 'sy' ...
Dec 14, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free