CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,798 vulnerabilities with CWE-74
CVE-2025-10785
HIGH
Campcodes Grocery Sales and Inventory System 1.0 - SQL Injection via /manage_user.php ID Parameter
CVSS 7.3
CVE-2025-10784
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via /admin/edit_subject.php subject_code Parameter
CVSS 7.3
CVE-2025-10783
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via subject_code Parameter
CVSS 7.3
CVE-2025-10782
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10781
HIGH
Campcodes Online Learning Management System 1.0 - SQL Injection via class_name Parameter
CVSS 7.3
CVE-2025-10780
MEDIUM
CodeAstro Simple Pharmacy Management 1.0 - SQL Injection via bar_code Parameter in view.php
CVSS 6.3
CVE-2025-10762
MEDIUM
kuaifan DooTask <1.2.49 - SQL Injection
CVSS 6.3
CVE-2025-10712
HIGH
07FLYCMS, 07FLY-CMS & 07FlyCRM <20250831 - SQL Injection
CVSS 7.3
CVE-2025-10689
MEDIUM
D-Link DIR-645 105B01 - OS Command Injection via soapcgi_main Service Argument
CVSS 6.3
CVE-2025-10688
HIGH
Pet Grooming Management Software 1.0 - SQL Injection via inv_no/insta_amt Parameter
CVSS 7.3
CVE-2025-10687
HIGH
SourceCodester Responsive E-Learning System 1.0 - SQL Injection via Username Parameter in add_teacher.php
CVSS 7.3
CVE-2025-10673
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via classId Parameter
CVSS 7.3
CVE-2025-10670
HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Profile ID Parameter
CVSS 7.3
CVE-2025-10668
HIGH
Online Discussion Forum 1.0 - SQL Injection via ID Parameter in Compose Message Admin
CVSS 7.3
CVE-2025-10667
HIGH
itsourcecode Online Discussion Forum 1.0 - SQL Injection via /members/compose_msg.php ID Parameter
CVSS 7.3
CVE-2025-10665
MEDIUM
kidaze CourseSelectionSystem < 2017-06-18 - SQL Injection via csem Argument
CVSS 6.3
CVE-2025-10664
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via /create-ticket.php Subject Parameter
CVSS 7.3
CVE-2025-10663
HIGH
PHPGurukul Online Course Registration 3.1 - SQL Injection via cgpa Parameter
CVSS 7.3
CVE-2025-10662
MEDIUM
SeaCMS <= 13.3 - SQL Injection via /admin_members.php ID Parameter
CVSS 4.7
CVE-2025-10634
MEDIUM
D-Link DIR-823X 240126/240802/250416 - OS Command Injection via Environment Variable Handler
CVSS 6.3
CVE-2025-10629
MEDIUM
D-Link DIR-852 1.00CN B09 - Remote Command Injection via SSDP ST Argument
CVSS 6.3
CVE-2025-10628
MEDIUM
D-Link DIR-852 1.00CN B09 - OS Command Injection via Web Management Interface
CVSS 6.3
CVE-2025-10627
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/delete_user.php ID Parameter
CVSS 6.3
CVE-2025-10626
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via /admin/update_s3.php Credits Parameter
CVSS 6.3
CVE-2025-10625
MEDIUM
Online Exam Form Submission 1.0 - SQL Injection via Phone Parameter
CVSS 6.3
Details
Vulnerabilities
4,798
Exploit Likelihood
High