CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-10878
MEDIUM
D-Link DWR-M920 formSmsManage sub_41C8E8 command injection
CVSS 6.3
CVE-2026-10877
HIGH
SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection
CVSS 7.3
CVE-2026-47644
MEDIUM
Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-10875
MEDIUM
projectworlds Online Art Gallery Shop Project adminHome.ph sql injection
CVSS 6.3
CVE-2026-10874
MEDIUM
projectworlds Online Art Gallery Shop Project adminHome.php sql injection
CVSS 6.3
CVE-2026-41237
HIGH
Froxlor <2.3.7 DNS Record Validation - Zone File Injection
CVE-2026-41234
HIGH
Froxlor: BIND Zone File Injection via TXT Record Content
CVSS 7.6
CVE-2026-10811
MEDIUM
itsourcecode Fees Management System receipt.php sql injection
CVSS 6.3
CVE-2026-10809
MEDIUM
itsourcecode Fees Management System manage_user.php sql injection
CVSS 6.3
CVE-2026-10808
MEDIUM
itsourcecode Fees Management System manage_student.php sql injection
CVSS 6.3
CVE-2026-10729
LOW
HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
CVE-2026-10704
HIGH
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
CVSS 7.3
CVE-2026-10688
MEDIUM
ahujasid blender-mcp server.py execute_blender_code code injection
CVSS 5.5
CVE-2026-10661
MEDIUM
ahujasid blender-mcp server.py open injection
CVSS 4.3
CVE-2026-10620
HIGH
code-projects Student Admission System index.php sql injection
CVSS 7.3
CVE-2026-10608
HIGH
DedeCMS carbuyaction.php RemoveXSS sql injection
CVSS 7.3
CVE-2026-10607
HIGH
DedeCMS flink.php dede_htmlspecialchars sql injection
CVSS 7.3
CVE-2026-10606
HIGH
DedeCMS Feedback feedback.php TrimMsg sql injection
CVSS 7.3
CVE-2026-8993
MEDIUM
Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
CVSS 6.5
CVE-2026-10568
MEDIUM
itsourcecode Fees Management System manage_payment.php sql injection
CVSS 6.3
CVE-2026-10550
MEDIUM
elunez eladmin Application Deployment App.java command injection
CVSS 6.3
CVE-2026-10302
MEDIUM
itsourcecode Fees Management System 1.0 - SQL Injection via manage_fee.php ID Parameter
CVSS 6.3
CVE-2026-10297
MEDIUM
itsourcecode Fees Management System 1.0 - SQL Injection via /manage_course.php ID Parameter
CVSS 6.3
CVE-2026-10296
MEDIUM
Fees Management System 1.0 - SQL Injection via Username Parameter in /ajax.php
CVSS 6.3
CVE-2026-10290
HIGH
Hotel and Tourism Reservation System 1.0 - SQL Injection via tour.php GET Parameter
CVSS 7.3
Details
Vulnerabilities
4,984
Exploit Likelihood
High