CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,983 vulnerabilities with CWE-74
CVE-2026-54680 CRITICAL
Logging operator has Fluentd configuration injection that allows remote code execution
CVSS 9.9
CVE-2026-16729 MEDIUM
undici vulnerable to cookie attribute injection via unsanitized domain and unparsed setCookie fields
CVSS 4.8
CVE-2026-54666 HIGH
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVSS 8.3
CVE-2026-54664 HIGH
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVSS 8.3
CVE-2026-54662 HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in fetch http-client template
CVSS 8.3
CVE-2026-54661 HIGH
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVSS 8.3
CVE-2026-18085 MEDIUM
Improper Input Validation Leads to Arbitrary File Download and Potential Denial of Service in BlackBerry UEM
CVE-2026-16765 HIGH
CodeAstro Online Classroom loginlinkadmin.php sql injection
CVSS 7.3
CVE-2026-16490 MEDIUM
itsourcecode Hospital Management System prescription.php sql injection
CVSS 6.3
CVE-2026-16484 HIGH
SourceCodester Class and Exam Timetabling System edit_subjecta.php sql injection
CVSS 7.3
CVE-2026-16449 MEDIUM
zsadmin2025 ZS-Admin com.zs.sys.dept.controller.SysDeptController page OrderItem.desc sql injection
CVSS 6.3
CVE-2026-16448 MEDIUM
D-Link DNS-1550-04 remote_backup.cgi cgi_check_rsync_rw command injection
CVSS 6.3
CVE-2026-16334 MEDIUM
itsourcecode Hospital Management System prescriptionorder.php sql injection
CVSS 6.3
CVE-2026-16252 HIGH
Beijing Shenzhou Shihan Technology Multimedia Integrated Business Display System Staffshinel Ds.jsp sql injection
CVSS 7.3
CVE-2026-16244 MEDIUM
itsourcecode Hospital Management System prescriptionorderreport.php sql injection
CVSS 6.3
CVE-2026-16228 HIGH
SourceCodester Class and Exam Timetabling System edit_schoolyr.php sql injection
CVSS 7.3
CVE-2026-16227 HIGH
SourceCodester Class and Exam Timetabling System edit_subject.php sql injection
CVSS 7.3
CVE-2026-16204 MEDIUM
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
CVSS 6.3
CVE-2026-16154 HIGH
SourceCodester Class and Exam Timetabling System edit_room1.php sql injection
CVSS 7.3
CVE-2026-16152 HIGH
SourceCodester Class and Exam Timetabling System edit_rooma.php sql injection
CVSS 7.3
CVE-2026-16133 MEDIUM
LiuMengxuan04 MiniCode mcp.ts child_process.spawn command injection
CVSS 5.0
CVE-2026-16131 MEDIUM
itsourcecode Hospital Management System prescriptionrecord.php sql injection
CVSS 6.3
CVE-2026-54159 CRITICAL
PrestaShop ps_facetedsearch < 4.0.4 - Unauthenticated PHP Object Injection
CVSS 10.0
CVE-2026-16014 HIGH
code-projects Hospital Bed Management System Login Form sql injection
CVSS 7.3
CVE-2026-16009 MEDIUM
itsourcecode Hospital Management System prescriptionorderdetail.php sql injection
CVSS 6.3
Details
Vulnerabilities 4,983
Exploit Likelihood High