CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-1129 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/worksadd.jsp ID Parameter
CVSS 7.3
CVE-2026-1125 HIGH
D-Link DIR-823X 250416 - OS Command Injection via wd_enable Parameter
CVSS 7.3
CVE-2026-1124 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/work_report.jsp ID Parameter
CVSS 7.3
CVE-2026-1123 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/work_mod.jsp ID Parameter
CVSS 7.3
CVE-2026-1122 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/work_info.jsp ID Parameter
CVSS 7.3
CVE-2026-1121 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/del_workplan.jsp ID Parameter
CVSS 7.3
CVE-2026-1120 HIGH
Yonyou KSOA 9.0 - SQL Injection via /worksheet/del_work.jsp ID Parameter
CVSS 7.3
CVE-2026-1119 HIGH
Society Management System 1.0 - SQL Injection via activity_id Parameter
CVSS 7.3
CVE-2026-1118 MEDIUM
Society Management System 1.0 - SQL Injection via Title Parameter in add_activity.php
CVSS 6.3
CVE-2026-1105 HIGH
EasyCMS < 1.6 - SQL Injection via _order Parameter in UserAction.class.php
CVSS 7.3
CVE-2026-1066 MEDIUM
kalcaddle kodbox <1.61.10 - Command Injection
CVSS 6.3
CVE-2026-1064 MEDIUM
Bastillion <4.0.1 - Command Injection
CVSS 4.7
CVE-2026-1063 MEDIUM
Bastillion <4.0.1 - Command Injection
CVSS 4.7
CVE-2026-1059 HIGH
FeMiner warehouse_management_system < 2021-11-15 - SQL Injection via Username Parameter in chkuser.php
CVSS 7.3
CVE-2026-1050 HIGH
risenet-y9boot-support-platform-service - SQL Injection in REST Authenticate Endpoint
CVSS 7.3
CVE-2026-22708 CRITICAL
Cursor < 2.3 - Environment Variable Manipulation via Shell Built-in Execution
CVSS 9.8
CVE-2026-22200 HIGH
Enhancesoft osTicket 1.17.0-1.17.6 and 1.18.0-1.18.2 - Unauthenticated Arbitrary File Read via Ticket PDF Export
CVSS 7.5
CVE-2026-0852 HIGH
Online Music Site 1.0 - SQL Injection via AdminUpdateUser.php ID Parameter
CVSS 7.3
CVE-2026-0851 HIGH
Online Music Site 1.0 - SQL Injection via txtusername Parameter
CVSS 7.3
CVE-2026-0850 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via delete_activity.php activity_id Parameter
CVSS 4.7
CVE-2026-0843 MEDIUM
jjjfood/jjjshop_food <20260103 - SQL Injection
CVSS 6.3
CVE-2026-0803 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via enroll.php Parameters
CVSS 6.3
CVE-2026-0733 MEDIUM
Online Course Registration System < 3.1 - SQL Injection via id/cid Parameter in manage-students.php
CVSS 6.3
CVE-2026-0732 MEDIUM
D-Link DI-8200G 17.12.20A1 - OS Command Injection via /upgrade_filter.asp path Parameter
CVSS 6.3
CVE-2026-0729 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Title Parameter in add_activity.php
CVSS 4.7
Details
Vulnerabilities 4,795
Exploit Likelihood High