CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2025-2392 MEDIUM
Online Class and Exam Scheduling System 1.0 - SQL Injection via Activate Page ID Parameter
CVSS 4.7
CVE-2025-2391 HIGH
Blood Bank Management System 1.0 - SQL Injection in Admin Login Page
CVSS 7.3
CVE-2025-2390 MEDIUM
code-projects Blood Bank Management System 1.0 - SQL Injection in /user_dashboard/add_donor.php
CVSS 6.3
CVE-2025-2389 MEDIUM
Blood Bank Management System 1.0 - SQL Injection in /admin/add_city.php
CVSS 4.7
CVE-2025-2387 HIGH
SourceCodester Online Food Ordering System 2.0 - SQL Injection via pid Parameter in /admin/ajax.php
CVSS 7.3
CVE-2025-2386 HIGH
PHPGurukul Local Services Search Engine 1.0 - SQLi via serviceman-search.php Location
CVSS 7.3
CVE-2025-2385 HIGH
code-projects Modern Bag 1.0 - SQL Injection via User Email/Password Parameters
CVSS 7.3
CVE-2025-2384 MEDIUM
Real Estate Property Management System 1.0 - SQL Injection via InsertCustomer.php Parameter Handler
CVSS 6.3
CVE-2025-2383 HIGH
PHPGurukul Doctor Appointment Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-2382 HIGH
PHPGurukul Online Banquet Booking System 1.0 - SQL Injection via Booking Search Parameter
CVSS 7.3
CVE-2025-2381 HIGH
PHPGurukul Curfew e-Pass Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-2380 HIGH
PHPGurukul Apartment Visitors Management System 1.0 - SQL Injection via Mobile Number Parameter
CVSS 7.3
CVE-2025-2379 HIGH
PHPGurukul Apartment Visitors Management System 1.0 - SQL Injection via visname Parameter
CVSS 7.3
CVE-2025-2378 HIGH
PHPGurukul Medical Card Generation System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-2374 MEDIUM
PHPGurukul Human Metapneumovirus Testing Management System 1.0 - SQL Injection via Profile Parameter
CVSS 6.3
CVE-2025-2373 MEDIUM
Human Metapneumovirus Testing Management System 1.0 - SQL Injection via mobnumber/employeeid Parameter
CVSS 6.3
CVE-2025-2372 HIGH
PHPGurukul Human Metapneumovirus Testing Management System 1.0 - SQL Injection via Password Recovery Username Parameter
CVSS 7.3
CVE-2025-2362 HIGH
PHPGurukul Pre-School Enrollment System 1.0 - SQL Injection via mobnum Parameter
CVSS 7.3
CVE-2025-2358 MEDIUM
Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System ...
CVSS 6.3
CVE-2025-2353 HIGH
VAM Virtual Airlines Manager <2.6.2 - SQL Injection
CVSS 7.3
CVE-2025-2351 HIGH
DayCloud StudentManage 1.0 - SQL Injection
CVSS 7.3
CVE-2025-27107 HIGH
Minecraft <1.21.1-1.0.17, 1.21.4-1.0.9-254, 1.20.1-1.0.13, 1.19.2-1...
CVE-2025-27794 MEDIUM
Flarum < 1.8.10 - Session Hijacking via Subdomain Cookie Scoping
CVSS 6.8
CVE-2025-2217 MEDIUM
zzskzy Warehouse Refinement Management System 1.3 - SQL Injection via showid Parameter in getAdyData.ashx
CVSS 6.3
CVE-2025-2132 MEDIUM
ftcms 2.1 - SQL Injection via Search Component name Parameter
CVSS 4.7
Details
Vulnerabilities 4,808
Exploit Likelihood High