CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,795 vulnerabilities with CWE-74
CVE-2025-12313
MEDIUM
D-Link DI-7001 MINI 19.09.19A1/24.04.18B1 - OS Command Injection via /msp_info.htm cmd Parameter
CVSS 6.3
CVE-2025-12309
HIGH
Nero Social Networking Site 1.0 - SQL Injection via ID Parameter in friendprofile.php
CVSS 7.3
CVE-2025-12308
HIGH
Nero Social Networking Site 1.0 - SQL Injection via deletemessage.php message_id Parameter
CVSS 7.3
CVE-2025-12307
HIGH
Nero Social Networking Site 1.0 - SQL Injection via ID Parameter in addfriend.php
CVSS 7.3
CVE-2025-12306
HIGH
Nero Social Networking Site 1.0 - SQL Injection via ID Parameter in acceptoffres.php
CVSS 7.3
CVE-2025-12294
MEDIUM
SourceCodester Point of Sales 1.0 - SQL Injection via delete_category.php ID Parameter
CVSS 4.7
CVE-2025-12293
HIGH
SourceCodester Point of Sales 1.0 - SQL Injection via Category Parameter in category.php
CVSS 7.3
CVE-2025-12292
HIGH
SourceCodester Point of Sales 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-12287
MEDIUM
Bdtask Wholesale < 2025-10-13 - SQL Injection via Admin Dashboard Edit Profile
CVSS 4.7
CVE-2025-12277
HIGH
Abdullah-Hasan-Sajjad Online-School <f09dda77b4c29aa083ff57f4b1eb99...
CVSS 7.3
CVE-2025-12266
MEDIUM
Zytec Dalian Zhuoyun Technology Central Authentication Service <202...
CVSS 6.3
CVE-2025-12263
MEDIUM
Online Event Judging System 1.0 - SQL Injection via judge_id Parameter in edit_judge.php
CVSS 6.3
CVE-2025-12262
MEDIUM
Online Event Judging System 1.0 - SQL Injection via crit_id Parameter in edit_criteria.php
CVSS 6.3
CVE-2025-12261
MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection via ID Parameter in remove-announcement.php
CVSS 6.3
CVE-2025-12257
HIGH
SourceCodester Online Student Result System 1.0 - SQL Injection via ID Parameter in view_result.php
CVSS 7.3
CVE-2025-12256
MEDIUM
Online Event Judging System 1.0 - SQL Injection via contestant_id Parameter
CVSS 6.3
CVE-2025-12255
MEDIUM
Online Event Judging System 1.0 - SQL Injection via fullname Parameter
CVSS 6.3
CVE-2025-12254
MEDIUM
Online Event Judging System 1.0 - SQL Injection via fullname Parameter in add_judge.php
CVSS 6.3
CVE-2025-12253
HIGH
Amttgroup Hibos - Injection
CVSS 7.3
CVE-2025-12252
MEDIUM
Online Event Judging System 1.0 - SQL Injection via /ajax/action.php Content Parameter
CVSS 6.3
CVE-2025-12249
MEDIUM
Axosoft Scrum and Bug Tracking 22.1.1.11545 - Code Injection
CVSS 6.3
CVE-2025-12248
HIGH
CLTPHP 3.0 - SQL Injection via /home/search.html Keyword Parameter
CVSS 7.3
CVE-2025-12243
MEDIUM
Client Details System 1.0 - SQL Injection via ID Parameter in welcome.php
CVSS 6.3
CVE-2025-12242
MEDIUM
CodeAstro Gym Management System 1.0 - SQL Injection via ID Parameter in check-attendance.php
CVSS 6.3
CVE-2025-12238
MEDIUM
Automated Voting System 1.0 - SQL Injection via Username Parameter in /admin/user.php
CVSS 6.3
Details
Vulnerabilities
4,795
Exploit Likelihood
High