CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2026-0728 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter in delete_admin.php
CVSS 4.7
CVE-2026-0701 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 4.7
CVE-2026-0700 HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in check_admin.php
CVSS 7.3
CVE-2026-0699 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via activity_id Parameter
CVSS 4.7
CVE-2026-0698 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
CVE-2026-0697 MEDIUM
Intern Membership Management System 1.0 - SQL Injection via admin_id Parameter
CVSS 4.7
CVE-2026-0641 MEDIUM
TOTOLINK WA300 5.2cu.7112_B20190227 - OS Command Injection via UPLOAD_FILENAME Argument
CVSS 6.3
CVE-2026-0607 HIGH
Online Music Site 1.0 - SQL Injection via AdminViewSongs.php ID Parameter
CVSS 7.3
CVE-2026-0606 HIGH
Online Music Site 1.0 - SQL Injection via Albums.php ID Parameter
CVSS 7.3
CVE-2026-0605 HIGH
Online Music Site 1.0 - SQL Injection via Login Username/Password Parameters
CVSS 7.3
CVE-2026-0597 MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtRetailerAddress Parameter
CVSS 6.3
CVE-2026-0592 HIGH
Online Product Reservation System 1.0 - SQL Injection via User Registration Handler
CVSS 7.3
CVE-2026-0591 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via Cart Update Handler
CVSS 6.3
CVE-2026-0590 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via /app/checkout/delete.php ID Parameter
CVSS 6.3
CVE-2026-0585 HIGH
Online Product Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2026-0584 MEDIUM
Online Product Reservation System 1.0 - SQL Injection via ID Parameter in left_cart.php
CVSS 6.3
CVE-2026-0583 HIGH
Online Product Reservation System 1.0 - SQL Injection via User Login Email Parameter
CVSS 7.3
CVE-2026-0582 MEDIUM
itsourcecode Society Management System 1.0 - SQL Injection via Title Parameter in edit_activity_query.php
CVSS 6.3
CVE-2026-0581 MEDIUM
Tenda AC1206 Firmware 15.03.06.23 - OS Command Injection via BehaviorManager modulename Parameter
CVSS 6.3
CVE-2026-0579 HIGH
Online Product Reservation System 1.0 - SQL Injection via POST Parameter Handler
CVSS 7.3
CVE-2026-0578 HIGH
Online Product Reservation System 1.0 - SQL Injection via /handgunner-administrator/delete.php ID Parameter
CVSS 7.3
CVE-2026-0576 HIGH
Online Product Reservation System 1.0 - SQL Injection via Parameter Handler
CVSS 7.3
CVE-2026-0575 HIGH
Online Product Reservation System 1.0 - SQL Injection via Administrator Login Email/Password Parameters
CVSS 7.3
CVE-2026-0570 HIGH
Online Music Site 1.0 - SQL Injection via Feedback.php fname Parameter
CVSS 7.3
CVE-2026-0569 HIGH
Online Music Site 1.0 - SQL Injection via AlbumByCategory.php ID Parameter
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High