CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,983 vulnerabilities with CWE-74
CVE-2026-54680
CRITICAL
Logging operator has Fluentd configuration injection that allows remote code execution
CVSS 9.9
CVE-2026-16729
MEDIUM
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVSS 4.8
CVE-2026-54666
HIGH
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVSS 8.3
CVE-2026-54664
HIGH
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVSS 8.3
CVE-2026-54662
HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVSS 8.3
CVE-2026-54661
HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVSS 8.3
CVE-2026-18085
MEDIUM
Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEM
CVE-2026-16765
HIGH
CodeAstro Online Classroom loginlinkadmin.php sql injection
CVSS 7.3
CVE-2026-16490
MEDIUM
itsourcecode Hospital Management System prescription.php sql injection
CVSS 6.3
CVE-2026-16484
HIGH
SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
CVSS 7.3
CVE-2026-16449
MEDIUM
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
CVSS 6.3
CVE-2026-16448
MEDIUM
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
CVSS 6.3
CVE-2026-16334
MEDIUM
itsourcecode Hospital Management System prescriptionorder.php sql injection
CVSS 6.3
CVE-2026-16252
HIGH
Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection
CVSS 7.3
CVE-2026-16244
MEDIUM
itsourcecode Hospital Management System prescriptionorderreport.php sql injection
CVSS 6.3
CVE-2026-16228
HIGH
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
CVSS 7.3
CVE-2026-16227
HIGH
SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
CVSS 7.3
CVE-2026-16204
MEDIUM
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
CVSS 6.3
CVE-2026-16154
HIGH
SourceCodester Class and Exam Timetabling System edit_room1.php sql injection
CVSS 7.3
CVE-2026-16152
HIGH
SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection
CVSS 7.3
CVE-2026-16133
MEDIUM
LiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection
CVSS 5.0
CVE-2026-16131
MEDIUM
itsourcecode Hospital Management System prescriptionrecord.php sql injection
CVSS 6.3
CVE-2026-54159
CRITICAL
PrestaShop ps_facetedsearch < 4.0.4 - Unauthenticated PHP Object Injection
CVSS 10.0
CVE-2026-16014
HIGH
code-projects Hospital Bed Management System Login Form sql injection
CVSS 7.3
CVE-2026-16009
MEDIUM
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
CVSS 6.3
Details
Vulnerabilities
4,983
Exploit Likelihood
High