CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,516 vulnerabilities with CWE-74
CVE-2026-5183 MEDIUM
TRENDnet TEW-713RE addRouting sub_421494 command injection
CVSS 6.3
CVE-2026-5182 HIGH
SourceCodester Teacher Record System Parameter sql injection
CVSS 7.3
CVE-2026-5180 HIGH
SourceCodester Simple Doctors Appointment System ajax.php sql injection
CVSS 7.3
CVE-2026-5179 HIGH
SourceCodester Simple Doctors Appointment System login.php sql injection
CVSS 7.3
CVE-2026-5178 MEDIUM
Totolink A3300R cstecgi.cgi setIptvCfg command injection
CVSS 6.3
CVE-2026-5177 MEDIUM
Totolink A3300R cstecgi.cgi setWiFiBasicCfg command injection
CVSS 6.3
CVE-2026-34041 CRITICAL
act: Unrestricted set-env and add-path command processing enables environment injection
CVSS 9.8
CVE-2026-5176 HIGH
Totolink A3300R cstecgi.cgi setSyslogCfg command injection
CVSS 7.3
CVE-2026-5153 MEDIUM
Tenda CH22 WriteFacMac FormWriteFacMac command injection
CVSS 6.3
CVE-2026-5150 HIGH
code-projects Accounting System Parameter viewin_costumer.php sql injection
CVSS 7.3
CVE-2026-5148 MEDIUM
YunaiV yudao-cloud page sql injection
CVSS 4.7
CVE-2026-5147 HIGH
YunaiV yudao-cloud get-by-website sql injection
CVSS 7.3
CVE-2026-5105 MEDIUM
Totolink A3300R Parameter cstecgi.cgi setVpnPassCfg command injection
CVSS 6.3
CVE-2026-5104 MEDIUM
Totolink A3300R cstecgi.cgi setStaticRoute command injection
CVSS 6.3
CVE-2026-5103 MEDIUM
Totolink A3300R cstecgi.cgi setUPnPCfg command injection
CVSS 6.3
CVE-2026-5102 MEDIUM
Totolink A3300R Parameter cstecgi.cgi setSmartQosCfg command injection
CVSS 6.3
CVE-2026-5101 MEDIUM
Totolink A3300R Parameter cstecgi.cgi setLanCfg command injection
CVSS 6.3
CVE-2026-5041 MEDIUM
code-projects Chamber of Commerce Membership Management System pageMail.php fwrite command injection
CVSS 4.7
CVE-2026-5035 HIGH
code-projects Accounting System Parameter view_work.php sql injection
CVSS 7.3
CVE-2026-5034 HIGH
code-projects Accounting System Parameter edit_costumer.php sql injection
CVSS 7.3
CVE-2026-5033 HIGH
code-projects Accounting System Parameter view_costumer.php sql injection
CVSS 7.3
CVE-2026-5030 MEDIUM
Totolink NR1800X Telnet Service cstecgi.cgi NTPSyncWithHost command injection
CVSS 6.3
CVE-2026-5020 MEDIUM
Totolink A3600R Parameter cstecgi.cgi setNoticeCfg command injection
CVSS 6.3
CVE-2026-5019 HIGH
code-projects Simple Food Order System Parameter all-orders.php sql injection
CVSS 7.3
CVE-2026-5018 HIGH
code-projects Simple Food Order System Parameter register-router.php sql injection
CVSS 7.3
Details
Vulnerabilities 4,516
Exploit Likelihood High