CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-14514 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14485 MEDIUM
EFM ipTIME A3004T <14.19.0 - Command Injection
CVSS 5.0
CVE-2025-14337 HIGH
isourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14336 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14335 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14334 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14285 HIGH
code-projects Employee Profile Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14276 MEDIUM
Ilevia EVE X1 Server <4.6.5.0.eden - Command Injection
CVSS 5.6
CVE-2025-14259 MEDIUM
Jihai Jshop MiniProgram Mall System 2.9.0 - SQL Injection
CVSS 6.3
CVE-2025-14258 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14257 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14256 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14251 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14250 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14249 HIGH
Code-projects Online Ordering System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14248 HIGH
Simple Shopping Cart 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14247 MEDIUM
Simple Shopping Cart 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14246 MEDIUM
Simple Shopping Cart 1.0 - SQL Injection
CVSS 6.3
CVE-2025-14245 HIGH
ideacms < 1.8 - SQL Injection via Coupon.php whereRaw Function
CVSS 7.3
CVE-2025-14230 MEDIUM
Code-projects Daily Time Recording System 4.5.0 - SQL Injection
CVSS 6.3
CVE-2025-14229 MEDIUM
SourceCodester Inventory Management System 1.0 - Code Injection
CVSS 4.7
CVE-2025-14227 MEDIUM
Philipinho Simple-PHP-Blog < 2025-01-22 - SQL Injection via /edit.php
CVSS 6.3
CVE-2025-14226 HIGH
itsourcecode Student Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-14225 MEDIUM
D-Link DCS-930L 1.15.04 - Command Injection
CVSS 6.3
CVE-2025-14223 HIGH
Simple Leave Manager 1.0 - SQL Injection
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High