CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,808 vulnerabilities with CWE-74
CVE-2024-10844
HIGH
Bookstore Management System 1.0 - SQL Injection via search.php s Parameter
CVSS 7.3
CVE-2024-10842
LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via Username_Baru/Password Parameter
CVSS 2.4
CVE-2024-10841
MEDIUM
romadebrian WEB-Sekolah 1.0 - SQL Injection via Name Parameter in Mail Handler
CVSS 5.5
CVE-2024-10840
LOW
romadebrian WEB-Sekolah 1.0 - Cross-Site Scripting via kode Parameter in Backend
CVSS 2.4
CVE-2024-10810
MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor/app_request.php app_id Parameter
CVSS 6.3
CVE-2024-10809
MEDIUM
E-Health Care System 1.0 - SQL Injection via Doctor Chat Name/Message Parameter
CVSS 6.3
CVE-2024-10808
MEDIUM
E-Health Care System 1.0 - SQL Injection via Admin/req_detail.php id Parameter
CVSS 6.3
CVE-2024-10807
LOW
Hospital Management System 4.0 - Cross-Site Scripting via searchdata Parameter
CVSS 2.4
CVE-2024-10806
LOW
Hospital Management System 4.0 - Cross-Site Scripting via betweendates-detailsreports.php fromdate/todate Parameters
CVSS 2.4
CVE-2024-10805
MEDIUM
University Event Management System 1.0 - SQL Injection via doedit.php id Parameter
CVSS 6.3
CVE-2024-10791
HIGH
Codezips Hospital Appointment System 1.0 - SQL Injection via Name Parameter in doctorAction.php
CVSS 7.3
CVE-2024-10768
LOW
PHPGurukul Online Shopping Portal 2.0 - Cross-Site Scripting in two_tables.php
CVSS 3.5
CVE-2024-10752
HIGH
Codezips Pet Shop Management System 1.0 - SQL Injection via /productsadd.php id/name Parameter
CVSS 7.3
CVE-2024-10700
MEDIUM
University Event Management System 1.0 - SQL Injection via submit.php Parameters
CVSS 6.3
CVE-2024-10697
MEDIUM
Tenda AC6 15.03.05.19 - OS Command Injection via WriteFacMac API Endpoint
CVSS 6.3
CVE-2024-10491
MEDIUM
Express 3.0.0-3.21.4 and <4.0.0-rc1 - Arbitrary Resource Injection via Link Header
CVSS 4.0
CVE-2024-8309
CRITICAL
langchain-ai/langchain <0.2.5 - SQL Injection
CVSS 9.8
CVE-2024-7472
MEDIUM
lunary-ai/lunary <1.2.26 - Command Injection
CVSS 6.5
CVE-2024-49381
HIGH
Plenti < 0.7.2 - Arbitrary File Deletion via /postLocal Endpoint
CVSS 7.5
CVE-2024-49380
HIGH
Plenti < 0.7.2 - Arbitrary File Write and Remote Code Execution via /postLocal Endpoint
CVSS 7.5
CVE-2024-48927
MEDIUM
Umbraco CMS 8.0-8.18.14, 10.0.0-10.8.6, 13.0-13.5.1 - Remote Code Execution via SVG Preview
CVSS 4.6
CVE-2024-10157
HIGH
PHPGurukul Boat Booking System 1.0 - SQL Injection
CVSS 7.3
CVE-2024-10153
MEDIUM
PHPGurukul Boat Booking System 1.0 - SQL Injection
CVSS 6.3
CVE-2024-48918
HIGH
RDSlight < 1.1.0 - Command Injection and Memory Tampering via User Input Handling
CVE-2024-47764
MEDIUM
cookie < 0.7.0 - Cookie Field Injection via Name, Path, or Domain
Details
Vulnerabilities
4,808
Exploit Likelihood
High