CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-2087 HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2085 HIGH
D-Link DWR-M921 1.1.50 - Command Injection
CVSS 7.2
CVE-2026-2083 HIGH
code-projects Social Networking Site 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2080 HIGH
UTT HiPER 810 <1.7.4-141218 - Command Injection
CVSS 7.2
CVE-2026-2073 HIGH
isourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-25586 CRITICAL
sandboxjs < 0.8.29 - Prototype Pollution via hasOwnProperty Shadowing
CVSS 10.0
CVE-2026-25520 CRITICAL
nyariv/sandboxjs < 0.8.29 - Remote Code Execution via Function Constructor Exposure
CVSS 10.0
CVE-2026-2060 HIGH
Simple Blood Donor Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2059 HIGH
Medical Center Portal Management System 1.0 - SQL Injection via ID Parameter in emp_edit1.php
CVSS 7.3
CVE-2026-2058 HIGH
mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter
CVSS 7.3
CVE-2026-2057 HIGH
Medical Center Portal Management System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2026-2018 HIGH
itsourcecode School Management System <1.0 - SQL Injection
CVSS 7.3
CVE-2026-2014 HIGH
iSourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2013 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2012 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2011 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2008 MEDIUM
abhiphile fermat-mcp <47f11def1cd37e45dd060f30cdce346cbdbd6f0a - Co...
CVSS 6.3
CVE-2026-2000 MEDIUM
DCN DCME-320 <20260121 - Command Injection
CVSS 4.7
CVE-2026-1977 MEDIUM
isaacwasserman mcp-vegalite-server <16aefed598b8cd897b78e99b907f6e2...
CVSS 6.3
CVE-2026-1517 MEDIUM
iomad < 5.0 - SQL Injection in Company Admin Block
CVSS 4.7
CVE-2026-1802 HIGH
Ziroom ZHOME A0101 1.0.1.0 - Command Injection
CVSS 7.3
CVE-2026-24043 MEDIUM
jsPDF < 4.1.0 - XML Injection via addMetadata Function
CVSS 5.4
CVE-2026-1746 MEDIUM
JeecgBoot 3.9.0 - SQL Injection via Online Report API Keyword Parameter
CVSS 6.3
CVE-2026-1735 MEDIUM
Yealink MeetingBar A30 133.321.0 - Command Injection
CVSS 4.3
CVE-2026-1701 HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in Enrollment Index
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High