CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-2176 MEDIUM
Contact Management System 1.0 - SQL Injection via selecteditem[0] Argument
CVSS 6.3
CVE-2026-2173 HIGH
Online Examination System 1.0 - SQL Injection via login.php Username/Password Parameters
CVSS 7.3
CVE-2026-2172 HIGH
Online Application System for Admission 1.0 - SQL Injection via Login Endpoint
CVSS 7.3
CVE-2026-2171 HIGH
Online Student Management System 1.0 - SQL Injection via Login Component
CVSS 7.3
CVE-2026-2169 MEDIUM
D-Link DWR-M921 1.1.50 - Remote Command Injection via fota_url Parameter
CVSS 6.3
CVE-2026-2168 MEDIUM
D-Link DWR-M921 1.1.50 - Remote Command Injection via fota_url Parameter
CVSS 6.3
CVE-2026-2166 HIGH
Online Reviewer System 1.0 - SQL Injection via Login Username/Password Parameter
CVSS 7.3
CVE-2026-2163 MEDIUM
D-Link DIR-600 Firmware < 2.15wwb02 - Remote Command Injection via ssdp.cgi HTTP_ST Parameter
CVSS 4.7
CVE-2026-2162 MEDIUM
News Portal Project 1.0 - SQL Injection via pagetitle Parameter in /admin/aboutus.php
CVSS 4.7
CVE-2026-2161 HIGH
itsourcecode Directory Management System 1.0 - SQL Injection via /admin/forget-password.php Email Parameter
CVSS 7.3
CVE-2026-2158 HIGH
Student Web Portal 1.0 - SQL Injection via Username Parameter in check_user.php
CVSS 7.3
CVE-2026-2136 HIGH
projectworlds Online Food Ordering System 1.0 - SQL Injection via /view-ticket.php ID Parameter
CVSS 7.3
CVE-2026-2135 MEDIUM
UTT HiPER 810 1.7.4-141218 - OS Command Injection via formPdbUpConfig policyNames Argument
CVSS 6.3
CVE-2026-2134 MEDIUM
PHPGurukul Hospital Management System 4.0 - SQL Injection via ID Parameter in manage-doctors.php
CVSS 4.7
CVE-2026-2132 HIGH
Online Music Site 1.0 - SQL Injection via AdminUpdateCategory txtcat Parameter
CVSS 7.3
CVE-2026-2130 MEDIUM
mcp-maigret < 1.0.13 - Command Injection via Username Argument
CVSS 6.3
CVE-2026-2122 MEDIUM
Xiaopi Panel <20260126 - SQL Injection
CVSS 6.3
CVE-2026-2118 HIGH
UTT HiPER 810 1.7.4-141218 - OS Command Injection via Isp_Name Argument
CVSS 7.2
CVE-2026-2117 HIGH
Society Management System 1.0 - SQL Injection via activity_id Parameter in edit_activity.php
CVSS 7.3
CVE-2026-2116 HIGH
Society Management System 1.0 - SQL Injection via expenses_id Parameter in edit_expenses.php
CVSS 7.3
CVE-2026-2115 HIGH
Society Management System 1.0 - SQL Injection via Expenses ID Parameter
CVSS 7.3
CVE-2026-2114 HIGH
Society Management System 1.0 - SQL Injection via admin_id Parameter in edit_admin.php
CVSS 7.3
CVE-2026-2090 HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2089 HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2088 HIGH
PHPGurukul Beauty Parlour Management System 1.1 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High