CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-45344 HIGH
LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized instances
CVSS 8.1
CVE-2026-9607 MEDIUM
itsourcecode Courier Management System parcel_list.php sql injection
CVSS 6.3
CVE-2026-9606 HIGH
itsourcecode Courier Management System manage_user.php sql injection
CVSS 7.3
CVE-2026-9584 HIGH
code-projects Project Management System Login chk.php sql injection
CVSS 7.3
CVE-2026-9575 HIGH
itsourcecode Student Transcript Processing System index.php sql injection
CVSS 7.3
CVE-2026-9574 HIGH
itsourcecode Student Transcript Processing System trans.php sql injection
CVSS 7.3
CVE-2026-9573 HIGH
itsourcecode Student Transcript Processing System index.php sql injection
CVSS 7.3
CVE-2026-9568 MEDIUM
ThingsBoard YAML provision getGatewayDockerComposeFile code injection
CVSS 5.0
CVE-2026-9552 HIGH
Das Parking Management System 停车场管理系统 Search API Endpoint sql injection
CVSS 7.3
CVE-2026-9551 HIGH
Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cmdshell sql injection
CVSS 7.3
CVE-2026-9544 HIGH
Shenzhen Sixun Software Sixun Shanghui Group Business Management System PayConfig sql injection
CVSS 7.3
CVE-2026-9542 MEDIUM
CodeAstro Leave Management System add_staff.php sql injection
CVSS 6.3
CVE-2026-9528 HIGH
itsourcecode Electronic Judging System delete_judge.php sql injection
CVSS 7.3
CVE-2026-9526 HIGH
itsourcecode Electronic Judging System edit_team.php sql injection
CVSS 7.3
CVE-2026-9525 HIGH
itsourcecode Electronic Judging System edit_judge.php sql injection
CVSS 7.3
CVE-2026-9524 MEDIUM
xianrendzw EasyReport REST Endpoint execute sql injection
CVSS 6.3
CVE-2026-9523 HIGH
Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform getCalcmeterDetailDayListTree sql injection
CVSS 7.3
CVE-2026-9474 HIGH
yashpokharna2555 StudentManagementSystem studentdel.php confirm_logged_in sql injection
CVSS 7.3
CVE-2026-9470 HIGH
yashpokharna2555 StudentManagementSystem student_trans.php confirm_logged_in sql injection
CVSS 7.3
CVE-2026-9469 HIGH
yashpokharna2555 StudentManagementSystem success.php sql injection
CVSS 7.3
CVE-2026-9465 HIGH
Tiandy Easy7 Integrated Management Platform GetDBDataEx.jsp sql injection
CVSS 7.3
CVE-2026-9453 HIGH
FoundDream miniclawd SkillsLoader skills-loader.ts which command injection
CVSS 7.3
CVE-2026-9451 MEDIUM
code-projects Employee Management System applyleaveprocess.php sql injection
CVSS 6.3
CVE-2026-9450 MEDIUM
code-projects Employee Management System psubmit.php sql injection
CVSS 6.3
CVE-2026-9449 MEDIUM
code-projects Employee Management System changepassemp.php sql injection
CVSS 6.3
Details
Vulnerabilities 4,984
Exploit Likelihood High