CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2026-3151
HIGH
itsourcecode College Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3150
MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3149
MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3148
HIGH
SourceCodester Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3135
HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3134
HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3133
HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3069
HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3068
HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3066
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3065
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3064
MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3057
MEDIUM
pearProjectApi <2.8.10 - SQL Injection
CVSS 6.3
CVE-2026-3046
HIGH
itsourcecode E-Logbook 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3042
HIGH
itsourcecode Event Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2963
MEDIUM
Jinher OA C6 <20260210 - SQL Injection
CVSS 6.3
CVE-2026-2956
MEDIUM
qinming99 dst-admin <=1.5.0 - Command Injection
CVSS 6.3
CVE-2026-2954
MEDIUM
Dromara UJCMS 10.0.2 - Code Injection
CVSS 6.3
CVE-2026-2912
HIGH
Online Reviewer System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2867
HIGH
itsourcecode Vehicle Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2865
HIGH
Agri-Trading Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27194
CRITICAL
D-Tale < 3.20.0 save-column-filter - Remote Code Execution
CVSS 9.8
CVE-2026-27203
HIGH
eBay API MCP Server - Code Injection
CVSS 8.3
CVE-2026-27022
MEDIUM
@langchain/langgraph-checkpoint-redis - Command Injection
CVSS 6.5
CVE-2026-2848
HIGH
SourceCodester Tourism Website 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High