CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,792 vulnerabilities with CWE-74
CVE-2026-10729 LOW
HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens
CVE-2026-10704 HIGH
SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.php login sql injection
CVSS 7.3
CVE-2026-10688 MEDIUM
ahujasid blender-mcp server.py execute_blender_code code injection
CVSS 5.5
CVE-2026-10661 MEDIUM
ahujasid blender-mcp server.py open injection
CVSS 4.3
CVE-2026-10620 HIGH
code-projects Student Admission System index.php sql injection
CVSS 7.3
CVE-2026-10608 HIGH
DedeCMS carbuyaction.php RemoveXSS sql injection
CVSS 7.3
CVE-2026-10607 HIGH
DedeCMS flink.php dede_htmlspecialchars sql injection
CVSS 7.3
CVE-2026-10606 HIGH
DedeCMS Feedback feedback.php TrimMsg sql injection
CVSS 7.3
CVE-2026-8993 MEDIUM
Improper URL Handler Processing in D.Launcher 2 enables NTLM Credential Disclosure and SSRF attacks
CVSS 6.5
CVE-2026-10568 MEDIUM
itsourcecode Fees Management System manage_payment.php sql injection
CVSS 6.3
CVE-2026-10550 MEDIUM
elunez eladmin Application Deployment App.java command injection
CVSS 6.3
CVE-2026-10302 MEDIUM
itsourcecode Fees Management System 1.0 - SQL Injection via manage_fee.php ID Parameter
CVSS 6.3
CVE-2026-10297 MEDIUM
itsourcecode Fees Management System 1.0 - SQL Injection via /manage_course.php ID Parameter
CVSS 6.3
CVE-2026-10296 MEDIUM
Fees Management System 1.0 - SQL Injection via Username Parameter in /ajax.php
CVSS 6.3
CVE-2026-10290 HIGH
Hotel and Tourism Reservation System 1.0 - SQL Injection via tour.php GET Parameter
CVSS 7.3
CVE-2026-10286 MEDIUM
CodeAstro Payroll System 1.0 - SQL Injection via emp_id Parameter in /home_employee.php
CVSS 6.3
CVE-2026-7770 HIGH
IBM i Access Client Solutions 1.1.5.0-1.1.9.12 - Remote Code Execution via IBM i Navigator Request Handling
CVSS 8.8
CVE-2026-10265 MEDIUM
itsourcecode Content Management System edit_topic.php sql injection
CVSS 6.3
CVE-2026-10263 HIGH
SourceCodester Computer Repair Shop Management System manage_product.php sql injection
CVSS 7.3
CVE-2026-10262 HIGH
code-projects Real State Services Login loginuser.php sql injection
CVSS 7.3
CVE-2026-10261 HIGH
CodeAstro Online Job Portal application_status.php sql injection
CVSS 7.3
CVE-2026-10260 HIGH
CodeAstro Online Job Portal delete-jobs.php sql injection
CVSS 7.3
CVE-2026-10258 MEDIUM
itsourcecode Content Management System add_sub_topic.php sql injection
CVSS 6.3
CVE-2026-10257 MEDIUM
itsourcecode Content Management System update_ss_img.php sql injection
CVSS 6.3
CVE-2026-10256 MEDIUM
itsourcecode Content Management System save_comment.php sql injection
CVSS 6.3
Details
Vulnerabilities 4,792
Exploit Likelihood High