CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2025-1116 HIGH
Dreamvention Live AJAX Search Free <1.0.6 - SQL Injection
CVSS 7.3
CVE-2025-24962 HIGH
reNgine - OS Command Injection via nmap_cmd Parameter
CVSS 8.8
CVE-2025-22978 CRITICAL
eladmin <= 2.7 - CSV Injection in Exception Log Download Module
CVSS 9.8
CVE-2025-0967 MEDIUM
Chat System 1.0 - SQL Injection via chatname/chatpass Parameter
CVSS 6.3
CVE-2025-0950 MEDIUM
Tailoring Management System 1.0 - SQL Injection via staffid Parameter in staffview.php
CVSS 6.3
CVE-2025-0949 MEDIUM
Tailoring Management System 1.0 - SQL Injection via partview.php typeid Parameter
CVSS 6.3
CVE-2025-0948 MEDIUM
Tailoring Management System 1.0 - SQL Injection via incview.php incid Parameter
CVSS 6.3
CVE-2025-0947 MEDIUM
Tailoring Management System 1.0 - SQL Injection via expview.php expid Parameter
CVSS 6.3
CVE-2025-0946 MEDIUM
Tailoring Management System 1.0 - SQL Injection via templatedelete.php id Parameter
CVSS 6.3
CVE-2025-0945 MEDIUM
Tailoring Management System 1.0 - SQL Injection via typedelete.php id Parameter
CVSS 6.3
CVE-2025-0944 MEDIUM
Tailoring Management System 1.0 - SQL Injection via customerview.php id Parameter
CVSS 6.3
CVE-2025-0943 MEDIUM
Tailoring Management System 1.0 - SQL Injection via deldoc.php id Parameter
CVSS 6.3
CVE-2025-0934 MEDIUM
Job Recruitment 1.0 - SQL Injection via n Argument in /parse/_call_job_search_ajax.php
CVSS 6.3
CVE-2025-0882 MEDIUM
Chat System <= 1.0 - SQL Injection via User Parameter in addnewmember.php
CVSS 6.3
CVE-2025-0881 MEDIUM
Codezips Gym Management System 1.0 - SQL Injection via rname Parameter in saveroutine.php
CVSS 6.3
CVE-2025-0880 MEDIUM
Codezips Gym Management System 1.0 - SQL Injection via planid Parameter
CVSS 6.3
CVE-2025-0874 MEDIUM
Simple Car Rental System 1.0 - SQL Injection via /admin/approve.php id Parameter
CVSS 6.3
CVE-2025-0873 MEDIUM
Tailoring Management System 1.0 - SQL Injection via Customer Edit Parameters
CVSS 6.3
CVE-2025-0872 MEDIUM
Tailoring Management System 1.0 - SQL Injection via addpayment.php id/amount/desc/inccat Parameters
CVSS 6.3
CVE-2025-0847 HIGH
1000 Projects Employee Task Management System 1.0 - SQL Injection via Login Email Parameter
CVSS 7.3
CVE-2025-0846 HIGH
1000 Projects Employee Task Management System 1.0 - SQL Injection via AdminLogin.php Email Parameter
CVSS 7.3
CVE-2025-0843 HIGH
needyamin Library Card System 1.0 - SQL Injection via Admin Panel Email/Password Argument
CVSS 7.3
CVE-2025-0842 HIGH
needyamin Library Card System 1.0 - SQL Injection via Admin Login
CVSS 7.3
CVE-2025-24374 MEDIUM
Twig 3.16.0-3.18.9 - Cross-Site Scripting via Null Coalescing Operator
CVSS 4.3
CVE-2025-0803 HIGH
Codezips Gym Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,808
Exploit Likelihood High