CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2025-3299 HIGH
PHPGurukul Men Salon Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-3296 MEDIUM
SourceCodester Online Eyewear Shop 1.0 - SQL Injection
CVSS 6.3
CVE-2025-3267 MEDIUM
qinguoyi TinyWebServer <1.0 - SQL Injection
CVSS 6.3
CVE-2025-3265 HIGH
PHPGurukul e-Diary Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-3258 HIGH
PHPGurukul Old Age Home Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-3249 MEDIUM
TOTOLINK A6000R 1.0.1-B20201211.2000 - Command Injection
CVSS 6.3
CVE-2025-3245 MEDIUM
itsourcecode Library Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-3243 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-3242 MEDIUM
PHPGurukul e-Diary Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-3240 HIGH
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection
CVSS 7.3
CVE-2025-3239 HIGH
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection
CVSS 7.3
CVE-2025-3238 HIGH
PHPGurukul Online Fire Reporting System 1.2 - SQL Injection
CVSS 7.3
CVE-2025-3235 MEDIUM
PHPGurukul Old Age Home Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-3231 HIGH
PHPGurukul Zoo Management System 2.1 - SQL Injection
CVSS 7.3
CVE-2025-3229 MEDIUM
PHPGurukul Restaurant Table Booking System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-3220 HIGH
PHPGurukul e-Diary Management System 1.0 - SQL Injection via Category Parameter
CVSS 7.3
CVE-2025-3217 HIGH
PHPGurukul e-Diary Management System 1.0 - SQL Injection via Registration Email Parameter
CVSS 7.3
CVE-2025-3216 HIGH
PHPGurukul e-Diary Management System 1.0 - SQL Injection via Username/Contactno Parameter
CVSS 7.3
CVE-2025-3215 MEDIUM
PHPGurukul Restaurant Table Booking System 1.0 - SQL Injection via fullname Parameter
CVSS 6.3
CVE-2025-3213 HIGH
PHPGurukul e-Diary Management System 1.0 - SQL Injection via Remark Parameter
CVSS 7.3
CVE-2025-3211 MEDIUM
Patient Record Management System 1.0 - SQL Injection via itr_no/birth_id Parameter in birthing_print.php
CVSS 6.3
CVE-2025-3210 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via birth_id Parameter
CVSS 6.3
CVE-2025-3209 MEDIUM
Patient Record Management System 1.0 - SQL Injection via itr_no Parameter in add_patient.php
CVSS 6.3
CVE-2025-3208 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via itr_no Parameter in xray_print.php
CVSS 6.3
CVE-2025-3207 MEDIUM
code-projects Patient Record Management System 1.0 - SQL Injection via birth_id Parameter
CVSS 6.3
Details
Vulnerabilities 4,808
Exploit Likelihood High