CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,792 vulnerabilities with CWE-74
CVE-2026-4569 MEDIUM
SourceCodester Sales and Inventory System HTTP POST Request view_category.php sql injection
CVSS 6.3
CVE-2026-4568 MEDIUM
SourceCodester Sales and Inventory System HTTP GET Request update_supplier.php sql injection
CVSS 6.3
CVE-2026-4564 MEDIUM
yangzongzhuan RuoYi Quartz Job job code injection
CVSS 4.7
CVE-2026-4554 MEDIUM
Tenda F453 WriteFacMac FormWriteFacMac privilege escalation
CVSS 6.3
CVE-2026-4550 MEDIUM
code-projects Simple Gym Management System func.php sql injection
CVSS 4.7
CVE-2026-4543 MEDIUM
Wavlink WL-WN578W2 POST Request firewall.cgi command injection
CVSS 6.3
CVE-2026-4540 HIGH
projectworlds Online Notes Sharing System Parameters login.php sql injection
CVSS 7.3
CVE-2026-4537 MEDIUM
Cudy TR1200 ipsec.lua action_ipsec_conn command injection
CVSS 4.7
CVE-2026-4533 MEDIUM
code-projects Simple Food Ordering System all-tickets.php sql injection
CVSS 6.3
CVE-2026-4530 MEDIUM
apconw Aix-DB terminology_retriever.py sql injection
CVSS 5.3
CVE-2026-4516 MEDIUM
Foundation Agents MetaGPT DataInterpreter write_analysis_code.py injection
CVSS 6.3
CVE-2026-4515 MEDIUM
Foundation Agents MetaGPT operator.py code_generate code injection
CVSS 6.3
CVE-2026-4513 MEDIUM
vanna-ai vanna base.py ask sql injection
CVSS 6.3
CVE-2026-4511 MEDIUM
vanna-ai vanna legacy exec injection
CVSS 6.3
CVE-2026-4508 HIGH
PbootCMS Member Login MemberController.php checkUsername sql injection
CVSS 7.3
CVE-2026-4507 MEDIUM
Mindinventory MindSQL mindsql_core.py ask_db sql injection
CVSS 6.3
CVE-2026-4506 MEDIUM
Mindinventory MindSQL mindsql_core.py ask_db code injection
CVSS 6.3
CVE-2026-4504 HIGH
eosphoros-ai db-gpt Incomplete Fix editor sql injection
CVSS 7.3
CVE-2026-4500 MEDIUM
bagofwords1 bagofwords code_execution.py generate_df injection
CVSS 6.3
CVE-2026-4485 MEDIUM
itsourcecode College Management System search_student.php sql injection
CVSS 6.3
CVE-2026-4473 MEDIUM
itsourcecode Online Doctor Appointment System appointment_action.php sql injection
CVSS 4.7
CVE-2026-4472 MEDIUM
itsourcecode Online Frozen Foods Ordering System admin_edit_supplier.php sql injection
CVSS 6.3
CVE-2026-4471 MEDIUM
itsourcecode Online Frozen Foods Ordering System admin_edit_employee.php sql injection
CVSS 4.7
CVE-2026-4470 MEDIUM
itsourcecode Online Frozen Foods Ordering System admin_edit_menu.php sql injection
CVSS 4.7
CVE-2026-4469 MEDIUM
itsourcecode Online Frozen Foods Ordering System admin_edit_menu_action.php sql injection
CVSS 4.7
Details
Vulnerabilities 4,792
Exploit Likelihood High