CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-29046 HIGH
TinyWeb < 2.04 - CGI Environment Variable Injection via Header Parsing
CVSS 8.2
CVE-2026-3616 MEDIUM
DefaultFuction Jeson CRM 1.0.0 - SQL Injection
CVSS 6.3
CVE-2026-3612 HIGH
Wavlink WL-NU516U1 V240425 - Command Injection
CVSS 7.2
CVE-2026-29053 HIGH
Ghost 0.7.2-6.19.0 - Code Injection
CVSS 7.6
CVE-2026-29085 MEDIUM
Hono < 4.12.4 - Server-Sent Events Injection via Unvalidated Event Fields
CVSS 6.5
CVE-2026-26002 CRITICAL
Open OnDemand <4.0.9/4.1.3 - Path Traversal
CVSS 9.8
CVE-2026-25750 HIGH
Langchain Helm Charts <0.12.71 - Auth Bypass
CVSS 8.1
CVE-2026-3487 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3486 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2026-3484 MEDIUM
PhialsBasement nmap-mcp-server - Command Injection
CVSS 6.3
CVE-2026-3413 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3411 HIGH
itsourcecode University Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3410 HIGH
itsourcecode Society Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3409 HIGH
eosphoros-ai db-gpt 0.7.5 - Code Injection
CVSS 7.3
CVE-2026-3406 HIGH
Online Art Gallery Shop 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3395 HIGH
MaxSite CMS <109.1 - Code Injection
CVSS 7.3
CVE-2026-3292 MEDIUM
jizhicms < 2.5.6 - SQL Injection via Batch Interface findAll Function
CVSS 6.3
CVE-2026-3287 MEDIUM
youlai-mall 2.0.0 - SQL Injection via App-side Product Pagination Endpoint
CVSS 6.3
CVE-2026-3261 HIGH
itsourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27148 CRITICAL
Storybook <7.6.23/8.6.17/9.1.19/10.2.10 - WebSocket Hijacking
CVSS 9.6
CVE-2026-3200 HIGH
z-9527 admin 1.0/2.0 - SQL Injection
CVSS 7.3
CVE-2026-27727 CRITICAL
mchange-commons-java - Deserialization
CVSS 9.8
CVE-2026-3164 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3153 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3152 HIGH
itsourcecode College Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High