CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2025-15420
HIGH
Yonyou KSOA 9.0 - SQL Injection via worksheetagent_work_report.jsp ID Parameter
CVSS 7.3
CVE-2025-15410
HIGH
Online Guitar Store 1.0 - SQL Injection via L_email Parameter in /login.php
CVSS 7.3
CVE-2025-15409
HIGH
Online Guitar Store 1.0 - SQL Injection via /admin/Delete_product.php del_pro Parameter
CVSS 7.3
CVE-2025-15408
HIGH
Online Guitar Store 1.0 - SQL Injection via dre_title Parameter
CVSS 7.3
CVE-2025-15407
HIGH
Online Guitar Store 1.0 - SQL Injection via Create_category.php dre_Ctitle Parameter
CVSS 7.3
CVE-2025-15394
MEDIUM
idreamsoft iCMS < 8.0.0 - Remote Code Injection via Config Parameter
CVSS 4.7
CVE-2025-15393
MEDIUM
KodiCMS < 13.82.135 - Remote Code Injection via Layout API Endpoint
CVSS 6.3
CVE-2025-15392
MEDIUM
KodiCMS < 13.82.135 - SQL Injection via Search API Endpoint Keyword Parameter
CVSS 6.3
CVE-2025-15391
MEDIUM
D-Link DIR-806A 100CNb11 - OS Command Injection in SSDP Request Handler
CVSS 6.3
CVE-2025-15357
MEDIUM
D-Link DI-7400G+ 19.12.25A1 - OS Command Injection via cmd Parameter
CVSS 6.3
CVE-2025-15354
HIGH
Society Management System 1.0 - SQL Injection via Username Parameter in add_admin.php
CVSS 7.3
CVE-2025-15353
HIGH
itsourcecode Society Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query
CVSS 7.3
CVE-2025-15263
HIGH
BiggiDroid Simple PHP CMS 1.0 - SQL Injection via Admin Login Username Parameter
CVSS 7.3
CVE-2025-15257
HIGH
Edimax BR-6208AC 1.02/1.03 - Command Injection via Web Configuration Interface
CVSS 7.3
CVE-2025-15256
HIGH
Edimax BR-6208AC 1.02-1.03 - OS Command Injection via formStaDrvSetup rootAPmac Parameter
CVSS 7.3
CVE-2025-67746
MEDIUM
Composer 2.0.0-2.2.25 and 2.0.0-2.9.2 - Terminal Output Injection via ANSI Control Characters
CVSS 4.3
CVE-2025-15250
MEDIUM
08CMS Novel System <3.4 - Code Injection
CVSS 4.7
CVE-2025-15243
HIGH
Simple Stock System 1.0 - SQL Injection via Username Parameter in Login
CVSS 7.3
CVE-2025-15212
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via regfood.php 'a' Parameter
CVSS 6.3
CVE-2025-15211
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via refNo/Fname/Lname/sex/age/contact/nationality_nid Parameters
CVSS 6.3
CVE-2025-15210
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via editrefugee.php Argument
CVSS 6.3
CVE-2025-15209
MEDIUM
Refugee Food Management System 1.0 - SQL Injection via editfood.php Parameter Manipulation
CVSS 6.3
CVE-2025-15208
HIGH
Refugee Food Management System 1.0 - SQL Injection via rfid Parameter in editrefugee.php
CVSS 7.3
CVE-2025-15207
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via chkId[] Parameter
CVSS 7.3
CVE-2025-15206
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtAreaCode Parameter
CVSS 7.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High