CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,792 vulnerabilities with CWE-74
CVE-2026-7716 MEDIUM
code-projects Gym Management System In PHP/Windows NT index.php sql injection
CVSS 6.3
CVE-2026-7705 MEDIUM
JD Cloud JDCOS Service jdcap set_iptv_info command injection
CVSS 6.3
CVE-2026-7703 HIGH
AV Stumpfl Pixera Two Media Server Websocket API code injection
CVSS 7.3
CVE-2026-7700 MEDIUM
langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection
CVSS 6.3
CVE-2026-7699 MEDIUM
Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection
CVSS 6.3
CVE-2026-7697 MEDIUM
AMTT Hotel Broadband Operation System cardhand_submit.php sql injection
CVSS 4.7
CVE-2026-7695 HIGH
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7694 HIGH
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7692 MEDIUM
Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection
CVSS 6.3
CVE-2026-7691 MEDIUM
Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection
CVSS 6.3
CVE-2026-7690 MEDIUM
Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
CVSS 6.3
CVE-2026-7688 MEDIUM
Dolibarr ERP CRM Shipments API Endpoint expedition.class.php _checkValForAPI sql injection
CVSS 5.0
CVE-2026-7687 MEDIUM
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
CVSS 6.3
CVE-2026-7683 MEDIUM
Edimax BR-6428nC Web setWAN command injection
CVSS 6.3
CVE-2026-7682 MEDIUM
Edimax BR-6208AC L2TP Mode setWAN command injection
CVSS 6.3
CVE-2026-7678 MEDIUM
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
CVSS 6.3
CVE-2026-7672 MEDIUM
youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection
CVSS 6.3
CVE-2026-7670 HIGH
Jinher OA UserSel.aspx sql injection
CVSS 7.3
CVE-2026-7669 MEDIUM
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deserialization
CVSS 5.6
CVE-2026-7632 HIGH
code-projects Online Hospital Management System viewappointment.php sql injection
CVSS 7.3
CVE-2026-7629 MEDIUM
kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool command injection
CVSS 6.3
CVE-2026-7628 MEDIUM
crazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection
CVSS 6.3
CVE-2026-7612 MEDIUM
itsourcecode Courier Management System edit_user.php sql injection
CVSS 4.7
CVE-2026-7595 MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
CVSS 6.3
CVE-2026-7592 HIGH
itsourcecode Courier Management System edit_staff.php sql injection
CVSS 7.3
Details
Vulnerabilities 4,792
Exploit Likelihood High