CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-14711 HIGH
FantasticLBP Hotels Server <67b44df162fab26df209bd5d5d542875fcbec1d...
CVSS 7.3
CVE-2025-14710 HIGH
FantasticLBP Hotels Server - SQL Injection
CVSS 7.3
CVE-2025-14707 CRITICAL
sgwbox N3 Firmware < 2.0.25 - Remote Command Injection via http_eshell_server params Argument
CVSS 9.8
CVE-2025-14706 CRITICAL
sgwbox N3 < 2.0.25 - Remote Command Injection via NETREBOOT Interface
CVSS 9.8
CVE-2025-14705 CRITICAL
sgwbox N3 Firmware < 2.0.25 - OS Command Injection via SHARESERVER Feature Params Argument
CVSS 9.8
CVE-2025-14694 MEDIUM
ketr JEPaaS <= 7.2.8 - SQL Injection via readAllPostil keyWord Parameter
CVSS 4.7
CVE-2025-14674 MEDIUM
aizuda snail-job <1.6.0 - Code Injection
CVSS 6.3
CVE-2025-14668 HIGH
campcodes Advanced Online Examination System 1.0 - SQL Injection via Username Parameter in loginExe.php
CVSS 7.3
CVE-2025-14667 HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14666 HIGH
itsourcecode COVID Tracking System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14664 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14661 HIGH
itsourcecode Student Managemen System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14659 HIGH
D-Link DIR-860LB1/DIR-868LB1 - Command Injection
CVSS 8.8
CVE-2025-14653 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14652 HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14650 HIGH
iSourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14649 HIGH
itsourcecode Online Cake Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14648 MEDIUM
dedebiz < 6.5.9 - Remote Command Injection via /src/admin/catalog_add.php
CVSS 4.7
CVE-2025-14647 HIGH
Computer Book Store 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14646 HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14645 HIGH
Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14644 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14643 HIGH
Simple Attendance Record System 2.0 - SQL Injection
CVSS 7.3
CVE-2025-14640 HIGH
Code-projects Student File Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14639 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High