CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,983 vulnerabilities with CWE-74
CVE-2026-15481 HIGH
Trendnet TEW-635BRM IPoA WAN Connection Setup rc ipoa_test command injection
CVSS 8.8
CVE-2026-15478 MEDIUM
IceHRM UserReport Endpoint EmployeeAttendanceReport.php sql injection
CVSS 6.3
CVE-2026-15477 MEDIUM
Bahmni bahmnicore Search Endpoint sql additionalParams sql injection
CVSS 6.3
CVE-2026-58493 MEDIUM
grav-plugin-database: DSN Parameter Injection via Unsanitized Configuration Values in Connection String Construction
CVE-2026-55615 CRITICAL
Langroid < 0.65.5 Neo4jChatAgent - Prompt-to-Cypher Injection
CVE-2026-0284 CRITICAL
PAN-OS LSVPN - Unauthenticated XML Injection
CVSS 9.9
CVE-2026-15190 HIGH
SourceCodester Simple and Nice Shopping Cart Script login.php sql injection
CVSS 7.3
CVE-2026-15137 HIGH
code-projects Interview Management System View.php sql injection
CVSS 7.3
CVE-2026-15135 HIGH
code-projects Online Food Order System edit_food_items.php sql injection
CVSS 7.3
CVE-2026-15134 HIGH
CodeAstro Simple Online Leave Management System index.php sql injection
CVSS 7.3
CVE-2026-58213 HIGH
NATS Server MQTT Bridge - NATS Protocol Injection
CVSS 7.1
CVE-2026-55404 HIGH
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
CVSS 7.5
CVE-2026-15035 MEDIUM
bentoml OpenLLM Model Repository Directory Name common.py async_run_command command injection
CVSS 5.3
CVE-2026-55427 HIGH
Coder vulnerable to SSH config injection via unsanitized server-supplied values in `coder config-ssh`
CVSS 8.3
CVE-2026-49099 MEDIUM
Apache Camel Salesforce: Non-Camel-prefixed Exchange header constants bypass the HTTP header filter, allowing an HTTP client to influence internal behaviour
CVSS 5.3
CVE-2026-49098 MEDIUM
Apache Camel Kafka - Kafka Header Control Injection
CVSS 5.3
CVE-2026-49097 MEDIUM
Apache Camel IRC - Message Redirection via irc.* Headers
CVSS 6.5
CVE-2026-48203 CRITICAL
Apache Camel Solr - Server-Side Request Forgery via SolrParam Headers
CVSS 9.1
CVE-2026-14799 MEDIUM
CodeAstro Ecommerce Website my_account.php sql injection
CVSS 6.3
CVE-2026-14798 MEDIUM
CodeAstro Apartment Visitor Management System visitor-entry.php sql injection
CVSS 6.3
CVE-2026-14797 MEDIUM
CodeAstro Apartment Visitor Management System edit-apartment.php sql injection
CVSS 6.3
CVE-2026-14796 MEDIUM
CodeAstro Apartment Visitor Management System report.php sql injection
CVSS 6.3
CVE-2026-14795 MEDIUM
CodeAstro Apartment Visitor Management System action-visitor.php sql injection
CVSS 6.3
CVE-2026-14774 MEDIUM
itsourcecode Hospital Management System paymentdischarge.php sql injection
CVSS 6.3
CVE-2026-14773 MEDIUM
itsourcecode Hospital Management System payment.php sql injection
CVSS 6.3
Details
Vulnerabilities 4,983
Exploit Likelihood High