CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-7072
HIGH
CodePanda Source canteen_management_system login.php sql injection
CVSS 7.3
CVE-2026-7070
HIGH
code-projects Inventory Management System Login sql injection
CVSS 7.3
CVE-2026-7067
HIGH
D-Link DIR-822 udhcpd DHCP Service dhcpd.c system command injection
CVSS 7.3
CVE-2026-7063
HIGH
code-projects Employee Management System Endpoint eprocess.php sql injection
CVSS 7.3
CVE-2026-7060
HIGH
liyupi yu-picture MyBatis-Plus PictureServiceImpl.java PageRequest sql injection
CVSS 7.3
CVE-2026-7058
HIGH
666ghj MiroFish Inter-Process Communication simulation_ipc.py SimulationIPCClient.send_command command injection
CVSS 7.3
CVE-2026-7045
MEDIUM
baomidou dynamic-datasource 2.5.0 - Expression Injection
CVSS 6.3
CVE-2026-7039
HIGH
tufantunc ssh-mcp index.ts shell.write command injection
CVSS 7.8
CVE-2026-7028
MEDIUM
CodeAstro Online Job Portal All Jobs delete-jobs.php sql injection
CVSS 4.7
CVE-2026-7023
MEDIUM
ByteDance coze-studio databaseTool database_impl.go ExecuteSQL sql injection
CVSS 6.3
CVE-2026-7002
HIGH
KLiK SocialMediaWebsite Private Message get_message_ajax.php sql injection
CVSS 7.3
CVE-2026-6994
MEDIUM
Envoy Query Parameter header_mutation.cc params.add injection
CVSS 6.3
CVE-2026-6991
MEDIUM
colinhacks Zod CUID Data Type regexes.ts sql injection
CVSS 6.3
CVE-2026-6989
MEDIUM
Tenda F453 Telnet Service telnet TendaTelnet command injection
CVSS 6.3
CVE-2026-6987
HIGH
PicoClaw Web Launcher Management Plane restart command injection
CVSS 7.3
CVE-2026-6982
MEDIUM
star7th ShowDoc API Page Sort Endpoint PageController.class.PHP sql injection
CVSS 6.3
CVE-2026-6980
HIGH
Divyanshu-hash GitPilot-MCP main.py repo_path command injection
CVSS 7.3
CVE-2026-6978
MEDIUM
JiZhiCMS addcache.html htmlspecialchars_decode sql injection
CVSS 4.7
CVE-2026-41319
MEDIUM
MailKit has STARTTLS Response Injection via unflushed stream buffer that enables SASL mechanism downgrade
CVSS 6.5
CVE-2026-6799
MEDIUM
Comfast CF-N1-S Endpoint mbox-config command injection
CVSS 6.3
CVE-2026-1089
MEDIUM
User‑Controlled HTTP Header In Fortra's GoAnywhere MFT Allows Arbitrary DNS Lookups
CVSS 6.5
CVE-2026-0972
MEDIUM
GoAnywhere MFT SFTP Service Login Vulnerable to Brute Force Attack Under Certain Circumstances
CVSS 5.4
CVE-2026-6629
HIGH
Metasoft 美特软件 MetaCRM Interface sql.jsp Statement.executeUpdate sql injection
CVSS 7.3
CVE-2026-6628
MEDIUM
phili67 Ecclesia CRM Query Viewer view ValidateInput sql injection
CVSS 6.3
CVE-2026-6603
HIGH
modelscope agentscope _python.py execute_shell_command code injection
CVSS 7.3
Details
Vulnerabilities
4,984
Exploit Likelihood
High