CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Yearly Trend
Top Affected Vendors
All Injection CVEs (2,170)
CVE-2025-14653 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to manipulate database queries th...
Dec 14, 2025CVE-2025-14652 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows attackers to manipulate database queries ...
Dec 14, 2025CVE-2025-14650 is a SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL ...
Dec 14, 2025CVE-2025-14649 is an SQL injection vulnerability in itsourcecode Online Cake Ordering System 1.0 that allows remote attackers to execute arbitrary SQL...
Dec 14, 2025CVE-2025-14647 is a SQL injection vulnerability in Computer Book Store 1.0 that allows remote attackers to execute arbitrary SQL commands via the 'boo...
Dec 14, 2025This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands via the user_i...
Dec 14, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'stud_id' parameter in the /admin/delete_student.php file in code...
Dec 14, 2025CVE-2025-14644 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 14, 2025This SQL injection vulnerability in Simple Attendance Record System 2.0 allows attackers to manipulate database queries through the student parameter ...
Dec 14, 2025This vulnerability allows remote attackers to execute SQL injection attacks against the Student File Management System 1.0 by manipulating the stud_no...
Dec 14, 2025CVE-2025-14639 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 14, 2025This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows attackers to manipulate database queries through the /pe...
Dec 14, 2025This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
Dec 13, 2025This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to execute arbitrary SQL commands through the fi...
Dec 13, 2025This SQL injection vulnerability in code-projects Student File Management System 1.0 allows remote attackers to execute arbitrary SQL commands via the...
Dec 13, 2025This SQL injection vulnerability in code-projects Student File Management System 1.0 allows attackers to manipulate database queries through the user_...
Dec 13, 2025This vulnerability allows remote attackers to execute SQL injection attacks via the 'stud_no' parameter in the login_query.php file of Student File Ma...
Dec 13, 2025CVE-2025-14620 is an SQL injection vulnerability in code-projects Student File Management System 1.0 that allows attackers to manipulate database quer...
Dec 13, 2025CVE-2025-14588 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 13, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'keyname' parameter in the /admin/search1.php file of Prison Mana...
Dec 13, 2025This SQL injection vulnerability in itsourcecode Online Pet Shop Management System 1.0 allows remote attackers to execute arbitrary SQL commands via t...
Dec 13, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the ID parameter in the /admin/?page=zone endpoint of itsourcecode CO...
Dec 12, 2025This SQL injection vulnerability in the itsourcecode COVID Tracking System 1.0 allows attackers to manipulate database queries through the admin login...
Dec 12, 2025CVE-2025-14578 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 12, 2025This CVE describes an SQL injection vulnerability in the Advanced Library Management System 1.0 by projectworlds. Attackers can exploit the roll_numbe...
Dec 12, 2025CVE-2025-14570 is a SQL injection vulnerability in Advanced Library Management System 1.0 that allows attackers to execute arbitrary SQL commands via ...
Dec 12, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands through the Username parameter in the /Profilers/SProfile/login1.php file...
Dec 12, 2025This CVE describes a SQL injection vulnerability in kidaze CourseSelectionSystem that allows remote attackers to execute arbitrary SQL commands via th...
Dec 12, 2025CVE-2025-14537 is a SQL injection vulnerability in code-projects Class and Exam Timetable Management 1.0 that allows attackers to manipulate database ...
Dec 11, 2025CVE-2025-14536 is an SQL injection vulnerability in code-projects Class and Exam Timetable Management 1.0 that allows attackers to execute arbitrary S...
Dec 11, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_unit.php file via the txtunitDetails parameter. This...
Dec 11, 2025Campcodes Supplier Management System 1.0 contains a SQL injection vulnerability in the /admin/add_distributor.php file via the txtDistributorAddress p...
Dec 11, 2025CVE-2025-14337 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 9, 2025CVE-2025-14335 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 9, 2025This vulnerability allows remote attackers to execute SQL injection attacks against the itsourcecode Student Management System 1.0 via the 'sy' parame...
Dec 9, 2025CVE-2025-14334 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows attackers to execute arbitrary SQL commands ...
Dec 9, 2025This vulnerability allows remote attackers to execute arbitrary SQL commands via the 'per_id' parameter in the edit_personnel.php file of Employee Pro...
Dec 9, 2025CVE-2025-14258 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 8, 2025CVE-2025-14256 is an SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL c...
Dec 8, 2025CVE-2025-14257 is a SQL injection vulnerability in itsourcecode Student Management System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 8, 2025CVE-2025-14250 is a SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows remote attackers to execute arbitrary SQL comm...
Dec 8, 2025CVE-2025-14251 is an SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows attackers to manipulate database queries thro...
Dec 8, 2025CVE-2025-14248 is an SQL injection vulnerability in Simple Shopping Cart 1.0's admin login page that allows attackers to execute arbitrary SQL command...
Dec 8, 2025CVE-2025-14249 is a SQL injection vulnerability in code-projects Online Ordering System 1.0 that allows attackers to manipulate database queries throu...
Dec 8, 2025This SQL injection vulnerability in IdeaCMS allows remote attackers to execute arbitrary SQL commands through the whereRaw function in Coupon.php. It ...
Dec 8, 2025This SQL injection vulnerability in itsourcecode Student Management System 1.0 allows attackers to manipulate database queries through the fname param...
Dec 8, 2025CVE-2025-14223 is an SQL injection vulnerability in Simple Leave Manager 1.0 that allows attackers to manipulate database queries through the staff_id...
Dec 8, 2025CVE-2025-14218 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 8, 2025CVE-2025-14216 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 8, 2025CVE-2025-14217 is a SQL injection vulnerability in code-projects Currency Exchange System 1.0 that allows remote attackers to execute arbitrary SQL co...
Dec 8, 2025About Injection (CWE-74)
The product constructs all or part of a command, data structure, or record using externally-influenced input, but does not neutralize or incorrectly neutralizes special elements that could modify the intended behavior.
Our database tracks 2,170 CVEs classified as CWE-74, with 104 rated critical and 1,277 rated high severity. The average CVSS score for Injection vulnerabilities is 7.0.
External reference: View CWE-74 on MITRE CWE →
Monitor Injection Vulnerabilities
Get alerted when new Injection CVEs affect your infrastructure.
Start Monitoring Free