CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,808 vulnerabilities with CWE-74
CVE-2025-1116
HIGH
Dreamvention Live AJAX Search Free <1.0.6 - SQL Injection
CVSS 7.3
CVE-2025-24962
HIGH
reNgine - OS Command Injection via nmap_cmd Parameter
CVSS 8.8
CVE-2025-22978
CRITICAL
eladmin <= 2.7 - CSV Injection in Exception Log Download Module
CVSS 9.8
CVE-2025-0967
MEDIUM
Chat System 1.0 - SQL Injection via chatname/chatpass Parameter
CVSS 6.3
CVE-2025-0950
MEDIUM
Tailoring Management System 1.0 - SQL Injection via staffid Parameter in staffview.php
CVSS 6.3
CVE-2025-0949
MEDIUM
Tailoring Management System 1.0 - SQL Injection via partview.php typeid Parameter
CVSS 6.3
CVE-2025-0948
MEDIUM
Tailoring Management System 1.0 - SQL Injection via incview.php incid Parameter
CVSS 6.3
CVE-2025-0947
MEDIUM
Tailoring Management System 1.0 - SQL Injection via expview.php expid Parameter
CVSS 6.3
CVE-2025-0946
MEDIUM
Tailoring Management System 1.0 - SQL Injection via templatedelete.php id Parameter
CVSS 6.3
CVE-2025-0945
MEDIUM
Tailoring Management System 1.0 - SQL Injection via typedelete.php id Parameter
CVSS 6.3
CVE-2025-0944
MEDIUM
Tailoring Management System 1.0 - SQL Injection via customerview.php id Parameter
CVSS 6.3
CVE-2025-0943
MEDIUM
Tailoring Management System 1.0 - SQL Injection via deldoc.php id Parameter
CVSS 6.3
CVE-2025-0934
MEDIUM
Job Recruitment 1.0 - SQL Injection via n Argument in /parse/_call_job_search_ajax.php
CVSS 6.3
CVE-2025-0882
MEDIUM
Chat System <= 1.0 - SQL Injection via User Parameter in addnewmember.php
CVSS 6.3
CVE-2025-0881
MEDIUM
Codezips Gym Management System 1.0 - SQL Injection via rname Parameter in saveroutine.php
CVSS 6.3
CVE-2025-0880
MEDIUM
Codezips Gym Management System 1.0 - SQL Injection via planid Parameter
CVSS 6.3
CVE-2025-0874
MEDIUM
Simple Car Rental System 1.0 - SQL Injection via /admin/approve.php id Parameter
CVSS 6.3
CVE-2025-0873
MEDIUM
Tailoring Management System 1.0 - SQL Injection via Customer Edit Parameters
CVSS 6.3
CVE-2025-0872
MEDIUM
Tailoring Management System 1.0 - SQL Injection via addpayment.php id/amount/desc/inccat Parameters
CVSS 6.3
CVE-2025-0847
HIGH
1000 Projects Employee Task Management System 1.0 - SQL Injection via Login Email Parameter
CVSS 7.3
CVE-2025-0846
HIGH
1000 Projects Employee Task Management System 1.0 - SQL Injection via AdminLogin.php Email Parameter
CVSS 7.3
CVE-2025-0843
HIGH
needyamin Library Card System 1.0 - SQL Injection via Admin Panel Email/Password Argument
CVSS 7.3
CVE-2025-0842
HIGH
needyamin Library Card System 1.0 - SQL Injection via Admin Login
CVSS 7.3
CVE-2025-24374
MEDIUM
Twig 3.16.0-3.18.9 - Cross-Site Scripting via Null Coalescing Operator
CVSS 4.3
CVE-2025-0803
HIGH
Codezips Gym Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
4,808
Exploit Likelihood
High