CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2025-13570
MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=state ID Parameter
CVSS 6.3
CVE-2025-13569
MEDIUM
COVID Tracking System 1.0 - SQL Injection via /admin/?page=city ID Parameter
CVSS 6.3
CVE-2025-13568
MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Admin People Page
CVSS 6.3
CVE-2025-13567
MEDIUM
itsourcecode COVID Tracking System 1.0 - SQL Injection via ID Parameter in Establishment Page
CVSS 6.3
CVE-2025-13562
HIGH
D-Link DIR-852 1.00 - Remote Command Injection via gena.cgi Service Argument
CVSS 7.3
CVE-2025-13561
HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-13560
HIGH
SourceCodester Company Website CMS 1.0 - SQL Injection via Reset Password Email Parameter
CVSS 7.3
CVE-2025-13557
HIGH
Campcodes Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
CVE-2025-13556
HIGH
Campcodes Online Polling System 1.0 - SQL Injection via myusername Parameter
CVSS 7.3
CVE-2025-13555
HIGH
Campcodes School File Management System 1.0 - SQL Injection via stud_no Parameter
CVSS 7.3
CVE-2025-13554
HIGH
Campcodes Supplier Management System 1.0 - SQL Injection via txtUsername Parameter in Login Component
CVSS 7.3
CVE-2025-13546
MEDIUM
ashraf-kabir travel-agency - SQL Injection via Search Component user_query Parameter
CVSS 6.3
CVE-2025-13545
MEDIUM
ashraf-kabir travel-agency < 2025-07-05 - SQL Injection via edit_pack Parameter
CVSS 4.7
CVE-2025-13485
HIGH
itsourcecode Online File Management System 1.0 - SQL Injection via Username Parameter in ajax.php
CVSS 7.3
CVE-2025-64428
CRITICAL
Dataease < 2.10.17 - JNDI Injection via iiop, corbaname, and iiopname Schemes
CVSS 9.8
CVE-2025-13451
HIGH
SourceCodester Online Shop Project 1.0 - SQL Injection via Search Parameter in action.php
CVSS 7.3
CVE-2025-13449
HIGH
Online Shop Project 1.0 - SQL Injection via Login Password Parameter
CVSS 7.3
CVE-2025-13442
HIGH
UTT 750W < 3.2.2-191225 - OS Command Injection via formPdbUpConfig policyNames Parameter
CVSS 7.3
CVE-2025-13424
MEDIUM
Campcodes Supplier Management System 1.0 - SQL Injection via txtProductName Parameter
CVSS 4.7
CVE-2025-13422
HIGH
Sports Club Management System 1.0 - SQL Injection via login_id Parameter
CVSS 7.3
CVE-2025-13421
HIGH
Human Resource Management System 1.0 - SQL Injection via NoticeDesc Parameter
CVSS 7.3
CVE-2025-13420
HIGH
itsourcecode Human Resource Management System 1.0 - SQL Injection via EventStore.php eventSubject Parameter
CVSS 7.3
CVE-2025-13410
HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via tid Parameter in /admin/receipt.php
CVSS 7.3
CVE-2025-13396
MEDIUM
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in add-office.php
CVSS 6.3
CVE-2025-13395
HIGH
codehub666 94list - SQL Injection in Login Function
CVSS 7.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High