CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2026-2087
HIGH
SourceCodester Online Class Record System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2085
HIGH
D-Link DWR-M921 1.1.50 - Command Injection
CVSS 7.2
CVE-2026-2083
HIGH
code-projects Social Networking Site 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2080
HIGH
UTT HiPER 810 <1.7.4-141218 - Command Injection
CVSS 7.2
CVE-2026-2073
HIGH
isourcecode School Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-25586
CRITICAL
sandboxjs < 0.8.29 - Prototype Pollution via hasOwnProperty Shadowing
CVSS 10.0
CVE-2026-25520
CRITICAL
nyariv/sandboxjs < 0.8.29 - Remote Code Execution via Function Constructor Exposure
CVSS 10.0
CVE-2026-2060
HIGH
Simple Blood Donor Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2059
HIGH
Medical Center Portal Management System 1.0 - SQL Injection via ID Parameter in emp_edit1.php
CVSS 7.3
CVE-2026-2058
HIGH
mathurvishal CloudClassroom-PHP-Project - SQL Injection via gnamex Parameter
CVSS 7.3
CVE-2026-2057
HIGH
Medical Center Portal Management System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2026-2018
HIGH
itsourcecode School Management System <1.0 - SQL Injection
CVSS 7.3
CVE-2026-2014
HIGH
iSourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2013
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2012
HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2011
HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2026-2008
MEDIUM
abhiphile fermat-mcp <47f11def1cd37e45dd060f30cdce346cbdbd6f0a - Co...
CVSS 6.3
CVE-2026-2000
MEDIUM
DCN DCME-320 <20260121 - Command Injection
CVSS 4.7
CVE-2026-1977
MEDIUM
isaacwasserman mcp-vegalite-server <16aefed598b8cd897b78e99b907f6e2...
CVSS 6.3
CVE-2026-1517
MEDIUM
iomad < 5.0 - SQL Injection in Company Admin Block
CVSS 4.7
CVE-2026-1802
HIGH
Ziroom ZHOME A0101 1.0.1.0 - Command Injection
CVSS 7.3
CVE-2026-24043
MEDIUM
jsPDF < 4.1.0 - XML Injection via addMetadata Function
CVSS 5.4
CVE-2026-1746
MEDIUM
JeecgBoot 3.9.0 - SQL Injection via Online Report API Keyword Parameter
CVSS 6.3
CVE-2026-1735
MEDIUM
Yealink MeetingBar A30 133.321.0 - Command Injection
CVSS 4.3
CVE-2026-1701
HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in Enrollment Index
CVSS 7.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High