CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,792 vulnerabilities with CWE-74
CVE-2026-4783 MEDIUM
itsourcecode College Management System Parameter add-single-student-results.php sql injection
CVSS 6.3
CVE-2026-4781 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Parameter update_purchase.php sql injection
CVSS 6.3
CVE-2026-4780 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Parameter update_out_standing.php sql injection
CVSS 6.3
CVE-2026-4779 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Parameter update_customer_details.php sql injection
CVSS 6.3
CVE-2026-4778 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Parameter update_category.php sql injection
CVSS 6.3
CVE-2026-4777 MEDIUM
SourceCodester Sales and Inventory System POST Parameter view_supplier.php sql injection
CVSS 6.3
CVE-2026-30932 HIGH
Froxlor is vulnerable to BIND zone file injection via unsanitized DNS record content in DomainZones API
CVSS 8.8
CVE-2026-33475 CRITICAL
Langflow GitHub Actions Shell Injection
CVSS 9.1
CVE-2026-4632 HIGH
itsourcecode Online Enrollment System Parameter index.php sql injection
CVSS 7.3
CVE-2026-4625 HIGH
SourceCodester Online Admission System programmes.php sql injection
CVSS 7.3
CVE-2026-4624 HIGH
SourceCodester Online Library Management System Parameter home.php sql injection
CVSS 7.3
CVE-2026-4615 HIGH
Online Catering Reservation 1.0 - SQL Injection
CVSS 7.3
CVE-2026-4614 MEDIUM
itsourcecode sanitize or validate this input Parameter subjects.php sql injection
CVSS 6.3
CVE-2026-4613 HIGH
SourceCodester E-Commerce Site 1.0 - SQL Injection
CVSS 7.3
CVE-2026-33202 CRITICAL
Active Storage <8.1.2.1 - Path Traversal
CVSS 9.1
CVE-2026-4612 HIGH
itsourcecode Free Hotel Reservation System Parameter index.php sql injection
CVSS 7.3
CVE-2026-4597 MEDIUM
648540858 wvp-GB28181-pro Stream Proxy Query StreamProxyProvider.java selectAll sql injection
CVSS 6.3
CVE-2026-4581 HIGH
code-projects Simple Laundry System Parameters checklogin.php sql injection
CVSS 7.3
CVE-2026-4580 HIGH
code-projects Simple Laundry System Parameters checkupdatestatus.php sql injection
CVSS 7.3
CVE-2026-4579 HIGH
code-projects Simple Laundry System Parameters viewdetail.php sql injection
CVSS 7.3
CVE-2026-4574 MEDIUM
SourceCodester Simple E-learning System User Profile Update sql injection
CVSS 6.3
CVE-2026-4573 MEDIUM
SourceCodester Simple E-learning System HTTP GET Parameter delete_post.php sql injection
CVSS 6.3
CVE-2026-4572 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_product.php sql injection
CVSS 6.3
CVE-2026-4571 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_payments.php sql injection
CVSS 6.3
CVE-2026-4570 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_customers.php sql injection
CVSS 6.3
Details
Vulnerabilities 4,792
Exploit Likelihood High