CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-3151 HIGH
itsourcecode College Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3150 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3149 MEDIUM
itsourcecode College Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2026-3148 HIGH
SourceCodester Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3135 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3134 HIGH
itsourcecode News Portal 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3133 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3069 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3068 HIGH
itsourcecode Document Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3066 MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3065 MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3064 MEDIUM
HummerRisk <1.5.0 - Command Injection
CVSS 6.3
CVE-2026-3057 MEDIUM
pearProjectApi <2.8.10 - SQL Injection
CVSS 6.3
CVE-2026-3046 HIGH
itsourcecode E-Logbook 1.0 - SQL Injection
CVSS 7.3
CVE-2026-3042 HIGH
itsourcecode Event Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2963 MEDIUM
Jinher OA C6 <20260210 - SQL Injection
CVSS 6.3
CVE-2026-2956 MEDIUM
qinming99 dst-admin <=1.5.0 - Command Injection
CVSS 6.3
CVE-2026-2954 MEDIUM
Dromara UJCMS 10.0.2 - Code Injection
CVSS 6.3
CVE-2026-2912 HIGH
Online Reviewer System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2867 HIGH
itsourcecode Vehicle Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2865 HIGH
Agri-Trading Online Shopping System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-27194 CRITICAL
D-Tale < 3.20.0 save-column-filter - Remote Code Execution
CVSS 9.8
CVE-2026-27203 HIGH
eBay API MCP Server - Code Injection
CVSS 8.3
CVE-2026-27022 MEDIUM
@langchain/langgraph-checkpoint-redis - Command Injection
CVSS 6.5
CVE-2026-2848 HIGH
SourceCodester Tourism Website 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High