CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-10286
MEDIUM
CodeAstro Payroll System 1.0 - SQL Injection via emp_id Parameter in /home_employee.php
CVSS 6.3
CVE-2026-7770
HIGH
IBM i Access Client Solutions 1.1.5.0-1.1.9.12 - Remote Code Execution via IBM i Navigator Request Handling
CVSS 8.8
CVE-2026-10265
MEDIUM
itsourcecode Content Management System edit_topic.php sql injection
CVSS 6.3
CVE-2026-10263
HIGH
SourceCodester Computer Repair Shop Management System manage_product.php sql injection
CVSS 7.3
CVE-2026-10262
HIGH
code-projects Real State Services Login loginuser.php sql injection
CVSS 7.3
CVE-2026-10261
HIGH
CodeAstro Online Job Portal application_status.php sql injection
CVSS 7.3
CVE-2026-10260
HIGH
CodeAstro Online Job Portal delete-jobs.php sql injection
CVSS 7.3
CVE-2026-10258
MEDIUM
itsourcecode Content Management System add_sub_topic.php sql injection
CVSS 6.3
CVE-2026-10257
MEDIUM
itsourcecode Content Management System update_ss_img.php sql injection
CVSS 6.3
CVE-2026-10256
MEDIUM
itsourcecode Content Management System save_comment.php sql injection
CVSS 6.3
CVE-2026-10253
HIGH
itsourcecode Online House Rental System manage_payment.php sql injection
CVSS 7.3
CVE-2026-10252
HIGH
itsourcecode Online House Rental System manage_tenant.php sql injection
CVSS 7.3
CVE-2026-10251
HIGH
itsourcecode Online House Rental System ajax.php login sql injection
CVSS 7.3
CVE-2026-10250
HIGH
itsourcecode Online Blood Bank Management System campsdetails.php sql injection
CVSS 7.3
CVE-2026-10249
HIGH
itsourcecode Online Blood Bank Management System viewrequest.php sql injection
CVSS 7.3
CVE-2026-10248
MEDIUM
SourceCodester Pharmacy Sales and Inventory System Supplier Creation export create_supplier csv injection
CVSS 4.7
CVE-2026-10242
MEDIUM
itsourcecode Content Management System instructions.php sql injection
CVSS 6.3
CVE-2026-10237
MEDIUM
SourceCodester Water Billing Management System User Management manage_user sql injection
CVSS 4.7
CVE-2026-10235
MEDIUM
CodeAstro Ingredients Stock Management System stock_manager.php sql injection
CVSS 6.3
CVE-2026-10227
HIGH
raisulislamg4 student_management_system_by_php User Creation add_user_check.php sql injection
CVSS 7.3
CVE-2026-10226
HIGH
raisulislamg4 student_management_system_by_php delete.php sql injection
CVSS 7.3
CVE-2026-10225
HIGH
raisulislamg4 student_management_system_by_php Login login_check.php sql injection
CVSS 7.3
CVE-2026-10223
MEDIUM
NousResearch hermes-agent memory_tool.py _scan_memory_content injection
CVSS 6.3
CVE-2026-10222
MEDIUM
NousResearch hermes-agent config.py _sanitize_env_lines injection
CVSS 5.6
CVE-2026-10221
HIGH
NousResearch hermes-agent run_agent.py _compress_context injection
CVSS 7.3
Details
Vulnerabilities
4,984
Exploit Likelihood
High