CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,983 vulnerabilities with CWE-74
CVE-2026-15481
HIGH
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
CVSS 8.8
CVE-2026-15478
MEDIUM
IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
CVSS 6.3
CVE-2026-15477
MEDIUM
Bahmni bahmnicore Search Endpoint sql additionalParams sql injection
CVSS 6.3
CVE-2026-58493
MEDIUM
grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction
CVE-2026-55615
CRITICAL
Langroid < 0.65.5 Neo4jChatAgent - Prompt-to-Cypher Injection
CVE-2026-0284
CRITICAL
PAN-OS LSVPN - Unauthenticated XML Injection
CVSS 9.9
CVE-2026-15190
HIGH
SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
CVSS 7.3
CVE-2026-15137
HIGH
code-projects Interview Management System View.php sql injection
CVSS 7.3
CVE-2026-15135
HIGH
code-projects Online Food Order System edit_food_items.php sql injection
CVSS 7.3
CVE-2026-15134
HIGH
CodeAstro Simple Online Leave Management System index.php sql injection
CVSS 7.3
CVE-2026-58213
HIGH
NATS Server MQTT Bridge - NATS Protocol Injection
CVSS 7.1
CVE-2026-55404
HIGH
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
CVSS 7.5
CVE-2026-15035
MEDIUM
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
CVSS 5.3
CVE-2026-55427
HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVSS 8.3
CVE-2026-49099
MEDIUM
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
CVSS 5.3
CVE-2026-49098
MEDIUM
Apache Camel Kafka - Kafka Header Control Injection
CVSS 5.3
CVE-2026-49097
MEDIUM
Apache Camel IRC - Message Redirection via irc.* Headers
CVSS 6.5
CVE-2026-48203
CRITICAL
Apache Camel Solr - Server-Side Request Forgery via SolrParam Headers
CVSS 9.1
CVE-2026-14799
MEDIUM
CodeAstro Ecommerce Website my_account.php sql injection
CVSS 6.3
CVE-2026-14798
MEDIUM
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
CVSS 6.3
CVE-2026-14797
MEDIUM
CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
CVSS 6.3
CVE-2026-14796
MEDIUM
CodeAstro Apartment Visitor Management System report.php sql injection
CVSS 6.3
CVE-2026-14795
MEDIUM
CodeAstro Apartment Visitor Management System action-visitor.php sql injection
CVSS 6.3
CVE-2026-14774
MEDIUM
itsourcecode Hospital Management System paymentdischarge.php sql injection
CVSS 6.3
CVE-2026-14773
MEDIUM
itsourcecode Hospital Management System payment.php sql injection
CVSS 6.3
Details
Vulnerabilities
4,983
Exploit Likelihood
High