CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,808 vulnerabilities with CWE-74
CVE-2024-10844 HIGH
Bookstore Management System 1.0 - SQL Injection via search.php s Parameter
CVSS 7.3
CVE-2024-10842 LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via Username_Baru/Password Parameter
CVSS 2.4
CVE-2024-10841 MEDIUM
romadebrian WEB-Sekolah 1.0 - SQL Injection via Name Parameter in Mail Handler
CVSS 5.5
CVE-2024-10840 LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via kode Parameter in Backend
CVSS 2.4
CVE-2024-10810 MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor/app_request.php app_id Parameter
CVSS 6.3
CVE-2024-10809 MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor Chat Name/Message Parameter
CVSS 6.3
CVE-2024-10808 MEDIUM
E-Health Care System 1.0 - SQL Injection via Admin/req_detail.php id Parameter
CVSS 6.3
CVE-2024-10807 LOW
Hospital Management System 4.0 - Cross-Site Scripting via searchdata Parameter
CVSS 2.4
CVE-2024-10806 LOW
Hospital Management System 4.0 - Cross-Site Scripting via betweendates-detailsreports.php fromdate/todate Parameters
CVSS 2.4
CVE-2024-10805 MEDIUM
University Event Management System 1.0 - SQL Injection via doedit.php id Parameter
CVSS 6.3
CVE-2024-10791 HIGH
Codezips Hospital Appointment System 1.0 - SQL Injection via Name Parameter in doctorAction.php
CVSS 7.3
CVE-2024-10768 LOW
PHPGurukul Online Shopping Portal 2.0 - Cross-Site Scripting in two_tables.php
CVSS 3.5
CVE-2024-10752 HIGH
Codezips Pet Shop Management System 1.0 - SQL Injection via /productsadd.php id/name Parameter
CVSS 7.3
CVE-2024-10700 MEDIUM
University Event Management System 1.0 - SQL Injection via submit.php Parameters
CVSS 6.3
CVE-2024-10697 MEDIUM
Tenda AC6 15.03.05.19 - OS Command Injection via WriteFacMac API Endpoint
CVSS 6.3
CVE-2024-10491 MEDIUM
Express 3.0.0-3.21.4 and <4.0.0-rc1 - Arbitrary Resource Injection via Link Header
CVSS 4.0
CVE-2024-8309 CRITICAL
langchain-ai/langchain <0.2.5 - SQL Injection
CVSS 9.8
CVE-2024-7472 MEDIUM
lunary-ai/lunary <1.2.26 - Command Injection
CVSS 6.5
CVE-2024-49381 HIGH
Plenti < 0.7.2 - Arbitrary File Deletion via /postLocal Endpoint
CVSS 7.5
CVE-2024-49380 HIGH
Plenti < 0.7.2 - Arbitrary File Write and Remote Code Execution via /postLocal Endpoint
CVSS 7.5
CVE-2024-48927 MEDIUM
Umbraco CMS 8.0-8.18.14, 10.0.0-10.8.6, 13.0-13.5.1 - Remote Code Execution via SVG Preview
CVSS 4.6
CVE-2024-10157 HIGH
PHPGurukul Boat Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2024-10153 MEDIUM
PHPGurukul Boat Booking System 1.0 - SQL Injection
CVSS 6.3
CVE-2024-48918 HIGH
RDSlight < 1.1.0 - Command Injection and Memory Tampering via User Input Handling
CVE-2024-47764 MEDIUM
cookie < 0.7.0 - Cookie Field Injection via Name, Path, or Domain
Details
Vulnerabilities 4,808
Exploit Likelihood High