CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2025-4488 HIGH
Gym Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-4487 HIGH
Gym Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-4486 HIGH
Gym Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-4485 HIGH
Gym Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-4484 HIGH
Gym Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-4483 HIGH
Gym Management System 1.0 - SQL Injection via /view_pdetails.php ID Parameter
CVSS 7.3
CVE-2025-4482 HIGH
Project Worlds Student Project Allocation System 1.0 - SQL Injection via Pat_BloodGroup1 Parameter
CVSS 7.3
CVE-2025-4481 HIGH
SourceCodester Apartment Visitor Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-4467 HIGH
Online Student Clearance System 1.0 - SQL Injection via Edit Admin Page Parameters
CVSS 7.3
CVE-2025-4466 HIGH
Gym Management System 1.0 - SQL Injection via registration_id Parameter in /ajax.php
CVSS 7.3
CVE-2025-4465 HIGH
Gym Management System 1.0 - SQL Injection via member_id Parameter in save_schedule Action
CVSS 7.3
CVE-2025-4464 HIGH
Gym Management System 1.0 - SQL Injection via /ajax.php Plan Parameter
CVSS 7.3
CVE-2025-4463 HIGH
Gym Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-4459 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via fecalysis_form.php itr_no Parameter
CVSS 6.3
CVE-2025-4458 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via /edit_upatient.php ID Parameter
CVSS 6.3
CVE-2025-4457 HIGH
Project Worlds Car Rental Project 1.0 - SQL Injection via /admin/approve.php ID Parameter
CVSS 7.3
CVE-2025-4456 HIGH
Project Worlds Car Rental Project 1.0 - SQL Injection via Signup Page Fname Parameter
CVSS 7.3
CVE-2025-4454 MEDIUM
D-Link DIR-619L 2.04B04 - OS Command Injection via Wake-on-LAN MAC Parameter
CVSS 6.3
CVE-2025-4453 MEDIUM
D-Link DIR-619L 2.04B04 - OS Command Injection via formSysCmd sysCmd Argument
CVSS 6.3
CVE-2025-4445 MEDIUM
D-Link DIR-605L 2.13B01 - OS Command Injection via Wake-on-LAN MAC Parameter
CVSS 6.3
CVE-2025-4443 MEDIUM
D-Link DIR-605L 2.13B01 - OS Command Injection via sysCmd Argument
CVSS 6.3
CVE-2025-20216 MEDIUM
Cisco Catalyst SD-WAN Manager - XSS
CVSS 4.7
CVE-2025-4363 HIGH
Gym Management System 1.0 - SQL Injection via /ajax.php rid Parameter
CVSS 7.3
CVE-2025-4362 HIGH
Gym Management System 1.0 - SQL Injection via member_id Parameter in save_membership Action
CVSS 7.3
CVE-2025-4361 HIGH
PHPGurukul Company Visitor Management System 2.0 - SQL Injection via Department Name Parameter
CVSS 7.3
Details
Vulnerabilities 4,808
Exploit Likelihood High