CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-13570 MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=state ID Parameter
CVSS 6.3
CVE-2025-13569 MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=city ID Parameter
CVSS 6.3
CVE-2025-13568 MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Admin People Page
CVSS 6.3
CVE-2025-13567 MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Establishment Page
CVSS 6.3
CVE-2025-13562 HIGH
D-Link DIR-852 1.00 - Remote Command Injection via gena.cgi Service Argument
CVSS 7.3
CVE-2025-13561 HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-13560 HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Reset Password Email Parameter
CVSS 7.3
CVE-2025-13557 HIGH
Campcodes Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
CVE-2025-13556 HIGH
Campcodes Online Polling System 1.0 - SQL Injection via myusername Parameter
CVSS 7.3
CVE-2025-13555 HIGH
Campcodes School File Management System 1.0 - SQL Injection via stud_no Parameter
CVSS 7.3
CVE-2025-13554 HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtUsername Parameter in Login Component
CVSS 7.3
CVE-2025-13546 MEDIUM
ashraf-kabir travel-agency - SQL Injection via Search Component user_query Parameter
CVSS 6.3
CVE-2025-13545 MEDIUM
ashraf-kabir travel-agency < 2025-07-05 - SQL Injection via edit_pack Parameter
CVSS 4.7
CVE-2025-13485 HIGH
itsourcecode Online File Management System 1.0 - SQL Injection via Username Parameter in ajax.php
CVSS 7.3
CVE-2025-64428 CRITICAL
Dataease < 2.10.17 - JNDI Injection via iiop, corbaname, and iiopname Schemes
CVSS 9.8
CVE-2025-13451 HIGH
SourceCodester Online Shop Project 1.0 - SQL Injection via Search Parameter in action.php
CVSS 7.3
CVE-2025-13449 HIGH
Online Shop Project 1.0 - SQL Injection via Login Password Parameter
CVSS 7.3
CVE-2025-13442 HIGH
UTT 750W < 3.2.2-191225 - OS Command Injection via formPdbUpConfig policyNames Parameter
CVSS 7.3
CVE-2025-13424 MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtProductName Parameter
CVSS 4.7
CVE-2025-13422 HIGH
Sports Club Management System 1.0 - SQL Injection via login_id Parameter
CVSS 7.3
CVE-2025-13421 HIGH
Human Resource Management System 1.0 - SQL Injection via NoticeDesc Parameter
CVSS 7.3
CVE-2025-13420 HIGH
itsourcecode Human Resource Management System 1.0 - SQL Injection via EventStore.php eventSubject Parameter
CVSS 7.3
CVE-2025-13410 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via tid Parameter in /admin/receipt.php
CVSS 7.3
CVE-2025-13396 MEDIUM
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in add-office.php
CVSS 6.3
CVE-2025-13395 HIGH
codehub666 94list - SQL Injection in Login Function
CVSS 7.3
Details
Vulnerabilities 4,795
Exploit Likelihood High