CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,798 vulnerabilities with CWE-74
CVE-2025-10785 HIGH
Campcodes Grocery Sales and Inventory System 1.0 - SQL Injection via /manage_user.php ID Parameter
CVSS 7.3
CVE-2025-10784 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via /admin/edit_subject.php subject_code Parameter
CVSS 7.3
CVE-2025-10783 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via subject_code Parameter
CVSS 7.3
CVE-2025-10782 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10781 HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10780 MEDIUM
CodeAstro Simple Pharmacy Management 1.0 - SQL Injection via bar_code Parameter in view.php
CVSS 6.3
CVE-2025-10762 MEDIUM
kuaifan DooTask <1.2.49 - SQL Injection
CVSS 6.3
CVE-2025-10712 HIGH
07FLYCMS, 07FLY-CMS & 07FlyCRM <20250831 - SQL Injection
CVSS 7.3
CVE-2025-10689 MEDIUM
D-Link DIR-645 105B01 - OS Command Injection via soapcgi_main Service Argument
CVSS 6.3
CVE-2025-10688 HIGH
Pet Grooming Management Software 1.0 - SQL Injection via inv_no/insta_amt Parameter
CVSS 7.3
CVE-2025-10687 HIGH
SourceCodester Responsive E-Learning System 1.0 - SQL Injection via Username Parameter in add_teacher.php
CVSS 7.3
CVE-2025-10673 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via classId Parameter
CVSS 7.3
CVE-2025-10670 HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Profile ID Parameter
CVSS 7.3
CVE-2025-10668 HIGH
Online Discussion Forum 1.0 - SQL Injection via ID Parameter in Compose Message Admin
CVSS 7.3
CVE-2025-10667 HIGH
itsourcecode Online Discussion Forum 1.0 - SQL Injection via /members/compose_msg.php ID Parameter
CVSS 7.3
CVE-2025-10665 MEDIUM
kidaze CourseSelectionSystem < 2017-06-18 - SQL Injection via csem Argument
CVSS 6.3
CVE-2025-10664 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via /create-ticket.php Subject Parameter
CVSS 7.3
CVE-2025-10663 HIGH
PHPGurukul Online Course Registration 3.1 - SQL Injection via cgpa Parameter
CVSS 7.3
CVE-2025-10662 MEDIUM
SeaCMS <= 13.3 - SQL Injection via /admin_members.php ID Parameter
CVSS 4.7
CVE-2025-10634 MEDIUM
D-Link DIR-823X 240126/240802/250416 - OS Command Injection via Environment Variable Handler
CVSS 6.3
CVE-2025-10629 MEDIUM
D-Link DIR-852 1.00CN B09 - Remote Command Injection via SSDP ST Argument
CVSS 6.3
CVE-2025-10628 MEDIUM
D-Link DIR-852 1.00CN B09 - OS Command Injection via Web Management Interface
CVSS 6.3
CVE-2025-10627 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/delete_user.php ID Parameter
CVSS 6.3
CVE-2025-10626 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/update_s3.php Credits Parameter
CVSS 6.3
CVE-2025-10625 MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via Phone Parameter
CVSS 6.3
Details
Vulnerabilities 4,798
Exploit Likelihood High