CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,792 vulnerabilities with CWE-74
CVE-2026-7716
MEDIUM
code-projects Gym Management System In PHP/Windows NT index.php sql injection
CVSS 6.3
CVE-2026-7705
MEDIUM
JD Cloud JDCOS Service jdcap set_iptv_info command injection
CVSS 6.3
CVE-2026-7703
HIGH
AV Stumpfl Pixera Two Media Server Websocket API code injection
CVSS 7.3
CVE-2026-7700
MEDIUM
langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection
CVSS 6.3
CVE-2026-7699
MEDIUM
Dromara MaxKey StrUtils.java StrUtils.checkSqlInjection sql injection
CVSS 6.3
CVE-2026-7697
MEDIUM
AMTT Hotel Broadband Operation System cardhand_submit.php sql injection
CVSS 4.7
CVE-2026-7695
HIGH
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7694
HIGH
Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System elecMaxMinAvgValue sql injection
CVSS 7.3
CVE-2026-7692
MEDIUM
Wavlink WL-WN570HA1 adm.cgi ping_ddns command injection
CVSS 6.3
CVE-2026-7691
MEDIUM
Wavlink WL-WN570HA1 adm.cgi set_sys_cmd command injection
CVSS 6.3
CVE-2026-7690
MEDIUM
Wavlink WL-WN570HA1 adm.cgi set_sys_adm command injection
CVSS 6.3
CVE-2026-7688
MEDIUM
Dolibarr ERP CRM Shipments API Endpoint expedition.class.php _checkValForAPI sql injection
CVSS 5.0
CVE-2026-7687
MEDIUM
langflow-ai langflow Full Builtins code_parser.py CodeParser.parse_callable_details command injection
CVSS 6.3
CVE-2026-7683
MEDIUM
Edimax BR-6428nC Web setWAN command injection
CVSS 6.3
CVE-2026-7682
MEDIUM
Edimax BR-6208AC L2TP Mode setWAN command injection
CVSS 6.3
CVE-2026-7678
MEDIUM
YunaiV yudao-cloud GoViewDataServiceImpl.java getDataBySQL sql injection
CVSS 6.3
CVE-2026-7672
MEDIUM
youlaitech youlai-boot Users Endpoint UserController.java getUserList sql injection
CVSS 6.3
CVE-2026-7670
HIGH
Jinher OA UserSel.aspx sql injection
CVSS 7.3
CVE-2026-7669
MEDIUM
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deserialization
CVSS 5.6
CVE-2026-7632
HIGH
code-projects Online Hospital Management System viewappointment.php sql injection
CVSS 7.3
CVE-2026-7629
MEDIUM
kleneway awesome-cursor-mpc-server Ccode-Review Tool codeReview.ts runCodeReviewTool command injection
CVSS 6.3
CVE-2026-7628
MEDIUM
crazyrabbitLTC mcp-code-review-server RepoMix repomix.ts executeRepomix command injection
CVSS 6.3
CVE-2026-7612
MEDIUM
itsourcecode Courier Management System edit_user.php sql injection
CVSS 4.7
CVE-2026-7595
MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
CVSS 6.3
CVE-2026-7592
HIGH
itsourcecode Courier Management System edit_staff.php sql injection
CVSS 7.3
Details
Vulnerabilities
4,792
Exploit Likelihood
High