CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-69205 MEDIUM
Micro Registration Utility <88db9a9 - Command Injection
CVSS 6.3
CVE-2025-15205 MEDIUM
Student File Management System 1.0 - SQL Injection via download.php istore_id Parameter
CVSS 6.3
CVE-2025-15198 HIGH
College Notes Uploading System 1.0 - SQL Injection via User Parameter in login.php
CVSS 7.3
CVE-2025-15196 HIGH
code-projects Assessment Management 1.0 - SQL Injection via login.php userid Parameter
CVSS 7.3
CVE-2025-15195 HIGH
code-projects Assessment Management 1.0 - SQL Injection via linked[] Parameter
CVSS 7.3
CVE-2025-15192 MEDIUM
D-Link DWR-M920 < 1.1.50 - Remote Command Injection via formLtefotaUpgradeQuectel fota_url Parameter
CVSS 6.3
CVE-2025-15191 MEDIUM
D-Link DWR-M920 < 1.1.50 - OS Command Injection via formLtefotaUpgradeFibocom fota_url Parameter
CVSS 6.3
CVE-2025-15186 HIGH
Refugee Food Management System 1.0 - SQL Injection via /home/addusers.php a Parameter
CVSS 7.3
CVE-2025-15185 HIGH
Refugee Food Management System 1.0 - SQL Injection via 'a' Parameter in /home/refugeesreport.php
CVSS 7.3
CVE-2025-15184 HIGH
Refugee Food Management System 1.0 - SQL Injection via 'a' Parameter in refugeesreport2.php
CVSS 7.3
CVE-2025-15183 HIGH
Refugee Food Management System 1.0 - SQL Injection via tfid Parameter
CVSS 7.3
CVE-2025-15182 HIGH
Refugee Food Management System 1.0 - SQL Injection via refNo Parameter
CVSS 7.3
CVE-2025-15181 HIGH
Refugee Food Management System 1.0 - SQL Injection via rfid Parameter in pagenateRefugeesList.php
CVSS 7.3
CVE-2025-15169 MEDIUM
BiggiDroid Simple PHP CMS 1.0 - SQL Injection via /admin/editsite.php ID Parameter
CVSS 4.7
CVE-2025-15168 HIGH
itsourcecode Student Management System 1.0 - SQL Injection via statistical.php ID Parameter
CVSS 7.3
CVE-2025-15167 HIGH
Online Cake Ordering System 1.0 - SQL Injection via detailtransac.php ID Parameter
CVSS 7.3
CVE-2025-15166 HIGH
Online Cake Ordering System 1.0 - SQL Injection via /updatesupplier.php ID Parameter
CVSS 7.3
CVE-2025-15165 HIGH
Online Cake Ordering System 1.0 - SQL Injection via /updatecustomer.php ID Parameter
CVSS 7.3
CVE-2025-15148 MEDIUM
CmsEasy < 7.7.7.0 - Remote Code Execution via Backend Template Management Page
CVSS 4.7
CVE-2025-15143 MEDIUM
EyouCMS < 1.7.6 - SQL Injection via FilemanagerLogic.php Content Argument
CVSS 4.7
CVE-2025-15142 HIGH
phpok3w < 901d96a06809fb28b17f3a4362c59e70411c933c - SQL Injection via ID Parameter in show.php
CVSS 7.3
CVE-2025-15140 HIGH
saiftheboss7 onlinemcqexam <0e56806132971e49721db3ef01868098c7b42ad...
CVSS 7.3
CVE-2025-15139 MEDIUM
TRENDnet TEW-822DRE 1.00B21/1.01B06 - Remote Command Injection via peerPin Argument
CVSS 6.3
CVE-2025-15137 HIGH
TRENDnet TEW-800MB 1.0.1.0 - OS Command Injection via NTPSyncWithHost.cgi
CVSS 8.8
CVE-2025-15136 HIGH
TRENDnet TEW-800MB 1.0.1.0 - OS Command Injection via WizardConfigured Parameter
CVSS 8.8
Details
Vulnerabilities 4,795
Exploit Likelihood High