CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,807 vulnerabilities with CWE-74
CVE-2025-6267 MEDIUM
ADP Application Developer Platform 1.0.0 - SQL Injection
CVSS 6.3
CVE-2025-24291 MEDIUM
Versa Director 21.2.2-21.2.3 22.1.1-22.1.4 - Argument Injection via File Upload MIME Type Bypass
CVSS 6.1
CVE-2025-47867 HIGH
Trend Micro Apex Central < 8.0.6955 - Local File Inclusion and Remote Code Execution via Widget
CVSS 7.5
CVE-2025-6173 MEDIUM
Webkul QloApps 1.6.1 - SQL Injection via /admin/ajax_products_list.php packItself Parameter
CVSS 4.7
CVE-2025-6160 HIGH
SourceCodester Client Database Management System 1.0 - SQL Injection via user_id Parameter
CVSS 7.3
CVE-2025-6159 HIGH
Hostel Management System 1.0 - SQL Injection via Allocate Room Search Box
CVSS 7.3
CVE-2025-6157 HIGH
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 7.3
CVE-2025-6156 MEDIUM
PHPGurukul Nipah Virus Testing Management System 1.0 - SQL Injection via testtype Parameter
CVSS 6.3
CVE-2025-6155 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6154 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via student_roll_no Parameter
CVSS 7.3
CVE-2025-6153 HIGH
PHPGurukul Hostel Management System 1.0 - SQL Injection via Search Box Parameter
CVSS 7.3
CVE-2025-6136 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertPayment.php recipt_no Parameter
CVSS 6.3
CVE-2025-6135 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertNominee.php client_id/nominee_id
CVSS 6.3
CVE-2025-6134 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertClient.php client_id Parameter
CVSS 6.3
CVE-2025-6133 MEDIUM
Projectworlds Life Insurance Management System 1.0 - SQL Injection via insertagent.php agent_id Parameter
CVSS 6.3
CVE-2025-6132 HIGH
Chanjet CRM 1.0 - SQL Injection via gblOrgID Parameter in departmentsetting.php
CVSS 7.3
CVE-2025-6124 HIGH
Restaurant Order System 1.0 - SQL Injection via /tablelow.php ID Parameter
CVSS 7.3
CVE-2025-6123 HIGH
Restaurant Order System 1.0 - SQL Injection via Payment.php tabidNoti Parameter
CVSS 7.3
CVE-2025-6122 MEDIUM
Restaurant Order System 1.0 - SQL Injection via /table.php ID Parameter
CVSS 6.3
CVE-2025-6118 HIGH
Das Parking Management System 6.2.0 - SQL Injection via vehicleTypeCode Parameter
CVSS 7.3
CVE-2025-6117 HIGH
Das Parking Management System 6.2.0 - SQL Injection via Reservations Search API Value Parameter
CVSS 7.3
CVE-2025-6116 HIGH
Das Parking Management System 6.2.0 - SQL Injection via /IntraFieldVehicle/Search Value Parameter
CVSS 7.3
CVE-2025-6100 MEDIUM
realguoshuai open-video-cms 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6096 MEDIUM
Jasmin Ransomware <1.0.1 - SQL Injection
CVSS 6.3
CVE-2025-6095 HIGH
Jasmin Ransomware 1.0.1 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,807
Exploit Likelihood High