CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-1690 MEDIUM
Tenda HG10 Firmware - OS Command Injection via sysCmd Parameter
CVSS 4.7
CVE-2026-1689 HIGH
Tenda HG10 US_HG7_HG9_HG10re_300001138_en_xpon - OS Command Injection via Host Parameter
CVSS 7.3
CVE-2026-1688 HIGH
itsourcecode Directory Management System 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2026-1687 HIGH
Tenda HG10 Firmware - OS Command Injection via Samba Server String Parameter
CVSS 7.3
CVE-2026-1638 MEDIUM
Tenda AC21 1.1.1.1 - Command Injection
CVSS 6.3
CVE-2026-1625 MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection
CVSS 6.3
CVE-2026-1624 MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection
CVSS 6.3
CVE-2026-1623 MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Code Execution via setUpgradeFW FileName Parameter
CVSS 6.3
CVE-2026-1601 MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via setUploadUserData FileName Parameter
CVSS 6.3
CVE-2026-1596 MEDIUM
D-Link DWR-M961 1.1.47 - Command Injection via fota_url Parameter
CVSS 6.3
CVE-2026-1595 HIGH
Society Management System 1.0 - SQL Injection via student_id Parameter in edit_student_query.php
CVSS 7.3
CVE-2026-1594 HIGH
Society Management System 1.0 - SQL Injection via /admin/add_expenses.php Detail Parameter
CVSS 7.3
CVE-2026-1593 HIGH
Society Management System 1.0 - SQL Injection via Edit Expenses Detail Parameter
CVSS 7.3
CVE-2026-1590 HIGH
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter in Faculty Index
CVSS 7.3
CVE-2026-1589 HIGH
itsourcecode School Management System 1.0 - SQL Injection via txtsearch Parameter
CVSS 7.3
CVE-2026-1552 MEDIUM
SEMCMS 5.0 - SQL Injection via searchml Parameter in SEMCMS_Info.php
CVSS 6.3
CVE-2026-1551 MEDIUM
itsourcecode School Management System 1.0 - SQL Injection via ID Parameter
CVSS 6.3
CVE-2026-1548 MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via CloudACMunualUpdateUserdata URL Parameter
CVSS 6.3
CVE-2026-1547 MEDIUM
Totolink A7000R 4.1cu.4154 - Remote Command Injection via setUnloadUserData plugin_name Parameter
CVSS 6.3
CVE-2026-1546 MEDIUM
jishenghua jshERP < 3.6 - SQL Injection via getBillItemByParam barCodes Argument
CVSS 6.3
CVE-2026-1545 HIGH
itsourcecode School Management System 1.0 - SQL Injection via /course/index.php ID Parameter
CVSS 7.3
CVE-2026-1535 HIGH
Online Music Site 1.0 - SQL Injection via AdminReply.php ID Argument
CVSS 7.3
CVE-2026-1534 HIGH
Online Music Site 1.0 - SQL Injection via AdminEditUser.php ID Parameter
CVSS 7.3
CVE-2026-1533 MEDIUM
Online Music Site 1.0 - SQL Injection in AdminAddCategory.php
CVSS 4.7
CVE-2026-1449 HIGH
Hisense TransTech Smart Bus Management System <20260113 - SQL Injec...
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High