CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2026-1690
MEDIUM
Tenda HG10 Firmware - OS Command Injection via sysCmd Parameter
CVSS 4.7
CVE-2026-1689
HIGH
Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon - OS Command Injection via Host Parameter
CVSS 7.3
CVE-2026-1688
HIGH
itsourcecode Directory Management System 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2026-1687
HIGH
Tenda HG10 Firmware - OS Command Injection via Samba Server String Parameter
CVSS 7.3
CVE-2026-1638
MEDIUM
Tenda AC21 1.1.1.1 - Command Injection
CVSS 6.3
CVE-2026-1625
MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection
CVSS 6.3
CVE-2026-1624
MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection
CVSS 6.3
CVE-2026-1623
MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Code Execution via setUpgradeFW FileName Parameter
CVSS 6.3
CVE-2026-1601
MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via setUploadUserData FileName Parameter
CVSS 6.3
CVE-2026-1596
MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection via fota_url Parameter
CVSS 6.3
CVE-2026-1595
HIGH
Society Management System 1.0 - SQL Injection via student_id Parameter in edit_student_query.php
CVSS 7.3
CVE-2026-1594
HIGH
Society Management System 1.0 - SQL Injection via /admin/add_expenses.php Detail Parameter
CVSS 7.3
CVE-2026-1593
HIGH
Society Management System 1.0 - SQL Injection via Edit Expenses Detail Parameter
CVSS 7.3
CVE-2026-1590
HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in Faculty Index
CVSS 7.3
CVE-2026-1589
HIGH
itsourcecode School Management System 1.0 - SQL Injection via txtsearch Parameter
CVSS 7.3
CVE-2026-1552
MEDIUM
SEMCMS 5.0 - SQL Injection via searchml Parameter in SEMCMS_Info.php
CVSS 6.3
CVE-2026-1551
MEDIUM
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter
CVSS 6.3
CVE-2026-1548
MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via CloudACMunualUpdateUserdata URL Parameter
CVSS 6.3
CVE-2026-1547
MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via setUnloadUserData plugin_name Parameter
CVSS 6.3
CVE-2026-1546
MEDIUM
jishenghua jshERP < 3.6 - SQL Injection via getBillItemByParam barCodes Argument
CVSS 6.3
CVE-2026-1545
HIGH
itsourcecode School Management System 1.0 - SQL Injection via /course/index.php ID Parameter
CVSS 7.3
CVE-2026-1535
HIGH
Online Music Site 1.0 - SQL Injection via AdminReply.php ID Argument
CVSS 7.3
CVE-2026-1534
HIGH
Online Music Site 1.0 - SQL Injection via AdminEditUser.php ID Parameter
CVSS 7.3
CVE-2026-1533
MEDIUM
Online Music Site 1.0 - SQL Injection in AdminAddCategory.php
CVSS 4.7
CVE-2026-1449
HIGH
Hisense TransTech Smart Bus Management System <20260113 - SQL Injec...
CVSS 7.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High