CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,795 vulnerabilities with CWE-74
CVE-2025-12614 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12612 MEDIUM
Campcodes School Fees Payment Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-12610 MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12609 MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12608 HIGH
iSourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12607 HIGH
isourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12606 HIGH
iSourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12605 HIGH
itsourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12604 HIGH
itsourcecode Online Loan Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-12598 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12597 MEDIUM
SourceCodester Best House Rental Management System 1.0 - SQL Injection
CVSS 4.7
CVE-2025-12594 MEDIUM
Simple Online Hotel Reservation System 2.0 - SQL Injection
CVSS 4.7
CVE-2025-12342 HIGH
Serdar Bayram Ghost Hot Spot <20251014 - SQL Injection
CVSS 7.3
CVE-2025-12339 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_football.php pid Parameter
CVSS 7.3
CVE-2025-12338 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via /admin/admin_product.php pid Parameter
CVSS 7.3
CVE-2025-12337 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via admin_feature.php pid Parameter
CVSS 7.3
CVE-2025-12336 HIGH
Campcodes Retro Basketball Shoes Online Store 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-12329 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /details.php
CVSS 6.3
CVE-2025-12328 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via Name Argument in contestproblem.php
CVSS 6.3
CVE-2025-12327 MEDIUM
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via ID Parameter in /description.php
CVSS 6.3
CVE-2025-12326 HIGH
shawonruet/ruet_oj < 2022-10-19 - SQL Injection via POST Request Handler
CVSS 7.3
CVE-2025-12325 HIGH
Best Salon Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-12316 HIGH
Courier Management System 1.0 - SQL Injection via OfficeName Parameter in Edit Courier
CVSS 7.3
CVE-2025-12315 MEDIUM
Food Ordering System 1.0 - SQL Injection via itemPrice Parameter in /admin/menu.php
CVSS 4.7
CVE-2025-12314 MEDIUM
code-projects Food Ordering System 1.0 - SQL Injection via /admin/deleteitem.php itemID Parameter
CVSS 4.7
Details
Vulnerabilities 4,795
Exploit Likelihood High