CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-4206 MEDIUM
D-Link DNS-1550-04 dsk_mgr.cgi ScanDisk_run_e2fsck command injection
CVSS 6.3
CVE-2026-4205 MEDIUM
D-Link DNS-1550-04 app_mgr.cgi FTP_Server_BlockIP_Del command injection
CVSS 6.3
CVE-2026-4204 MEDIUM
D-Link DNS-1550-04 gui_mgr.cgi cgi_mycloud_auto_downlaod command injection
CVSS 6.3
CVE-2026-4203 MEDIUM
D-Link DNS-1550-04 network_mgr.cgi cgi_dhcpd command injection
CVSS 6.3
CVE-2026-4199 MEDIUM
bazinga012 mcp_code_executor index.ts installDependencies command injection
CVSS 5.3
CVE-2026-4198 MEDIUM
mcp-server-auto-commit 1.0.0 - Command Injection
CVSS 5.3
CVE-2026-4197 MEDIUM
D-Link DNS-1550-04 download_mgr.cgi RSS_Item_List command injection
CVSS 6.3
CVE-2026-4196 MEDIUM
D-Link DNS-1550-04 remote_backup.cgi cgi_set_rsync_server command injection
CVSS 6.3
CVE-2026-4195 MEDIUM
D-Link DNS-1550-04 wizard_mgr.cgi command injection
CVSS 6.3
CVE-2026-4192 MEDIUM
quip-mcp-server 1.0.0 - Command Injection
CVSS 6.3
CVE-2026-4190 HIGH
node-api-postgres up to 2.5 - SQL Injection
CVSS 7.3
CVE-2026-4189 MEDIUM
phpipam <= 1.7.4 - SQL Injection via subnetOrdering Parameter
CVSS 4.7
CVE-2026-4173 MEDIUM
CodePhiliaX Chat2DB <=0.3.7 - SQL Injection
CVSS 6.3
CVE-2026-4164 CRITICAL
Wavlink WL-WN578W2 221110 - Command Injection
CVSS 9.8
CVE-2026-4163 CRITICAL
Wavlink WL-WN579A3 220323 - Command Injection
CVSS 9.8
CVE-2026-32616 HIGH
Pigeon <1.0.201 Email Verification - Host Header Injection
CVSS 8.2
CVE-2026-4039 MEDIUM
OpenClaw 2026.2.19-2 - Code Injection
CVSS 6.3
CVE-2026-4014 HIGH
Cafe Reservation System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3992 MEDIUM
CodeGenieApp serverless-express <4.17.1 - Code Injection
CVSS 6.3
CVE-2026-3981 HIGH
Online Doctor Appointment System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3980 HIGH
Online Doctor Appointment System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3969 HIGH
FeMiner wms <= 1.0 - SQL Injection via Basic Organizational Structure Module Name Parameter
CVSS 7.3
CVE-2026-3968 MEDIUM
AutohomeCorp frostmourne <1.0 - Code Injection
CVSS 6.3
CVE-2026-3957 MEDIUM
weimai-wetapp 5fe9e82 - SQL Injection
CVSS 4.7
CVE-2026-3956 MEDIUM
weimai-wetapp up to 5fe9e82 - SQL Injection
CVSS 4.7
Details
Vulnerabilities 4,795
Exploit Likelihood High