CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,983 vulnerabilities with CWE-74
CVE-2026-44182 CRITICAL
Jupyter Enterprise Gateway Has Kubernetes Manifest Injection via Jinja2 Template Rendering
CVE-2026-54728 MEDIUM
bunkerweb: Improper Input Validation and Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') in BunkerWeb
CVE-2026-15907 HIGH
H3C SecPath F1000-C8300 g=log_fw_nbc_mail_jsondata sql injection
CVSS 7.3
CVE-2026-56699 CRITICAL
Wazuh Manager - NDJSON Injection in inventory_sync via Agent-Controlled DataValue.index
CVSS 10.0
CVE-2026-15703 HIGH
SourceCodester Simple and Nice Shopping Cart Script userproductdeletequery.php sql injection
CVSS 7.3
CVE-2026-15676 HIGH
code-projects Online Job Portal DeleteUser.php sql injection
CVSS 7.3
CVE-2026-15675 HIGH
code-projects Online Job Portal EditUser.php sql injection
CVSS 7.3
CVE-2026-15672 MEDIUM
itsourcecode Electronic Judging System add_judges.php sql injection
CVSS 6.3
CVE-2026-15597 HIGH
SourceCodester Class and Exam Timetabling System edit_exam2.php sql injection
CVSS 7.3
CVE-2026-15559 MEDIUM
CodeAstro Simple Online Leave Management System POST accept.php sql injection
CVSS 6.3
CVE-2026-15558 MEDIUM
CodeAstro Simple Online Leave Management System deletemp.php sql injection
CVSS 6.3
CVE-2026-15537 HIGH
SourceCodester Online Book Store System login.php sql injection
CVSS 7.3
CVE-2026-15536 MEDIUM
itsourcecode Hospital Management System patviewprescription.php sql injection
CVSS 6.3
CVE-2026-15533 MEDIUM
DedeCMS Column Management search.php code injection
CVSS 4.7
CVE-2026-15523 MEDIUM
CodeAstro Simple Online Leave Management System dashboard.php sql injection
CVSS 6.3
CVE-2026-15517 HIGH
Jinher OA PlanGiveOut.aspx sql injection
CVSS 7.3
CVE-2026-15514 HIGH
Metasoft 美特软件 MetaCRM PHPRPC Remote Call rpc.jsp RPCService.query sql injection
CVSS 7.3
CVE-2026-15512 MEDIUM
pig-mesh Pig pig-codegen GeneratorServiceImpl.java code injection
CVSS 6.3
CVE-2026-15502 MEDIUM
AojiaoZero Antaris PayPal IPN Payment ipn.php _rewardPurchase sql injection
CVSS 6.3
CVE-2026-15498 HIGH
sergomanov SmartHomeAdatum Login users.php sql injection
CVSS 7.3
CVE-2026-15497 HIGH
SonicCloudOrg sonic-agent JWT Authentication Filter ExchangeController.java code injection
CVSS 7.3
CVE-2026-15494 MEDIUM
AMTT Hotel Broadband Operation System switch_status.php sql injection
CVSS 4.7
CVE-2026-15490 HIGH
RafyMrX TOKO-ONLINE-ROTI add.php sql injection
CVSS 7.3
CVE-2026-15489 HIGH
RafyMrX TOKO-ONLINE-ROTI login.php sql injection
CVSS 7.3
CVE-2026-15482 HIGH
Aster Telecom Azcall HTTP sis.php sql injection
CVSS 7.3
Details
Vulnerabilities 4,983
Exploit Likelihood High