CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,984 vulnerabilities with CWE-74
CVE-2026-13532 MEDIUM
itsourcecode Hospital Management System departmentDoctor.php sql injection
CVSS 6.3
CVE-2026-13531 MEDIUM
itsourcecode Hospital Management System department.php sql injection
CVSS 6.3
CVE-2026-13530 MEDIUM
itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
CVSS 6.3
CVE-2026-13529 MEDIUM
YzmCMS index.php sql injection
CVSS 5.6
CVE-2026-13527 HIGH
SourceCodester Class and Exam Timetabling System preview4.php sql injection
CVSS 7.3
CVE-2026-13526 HIGH
SourceCodester Class and Exam Timetabling System edit_class.php sql injection
CVSS 7.3
CVE-2026-13525 MEDIUM
CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection
CVSS 6.3
CVE-2026-13521 HIGH
SourceCodester Class and Exam Timetabling System preview5.php sql injection
CVSS 7.3
CVE-2026-13520 MEDIUM
itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection
CVSS 6.3
CVE-2026-13501 MEDIUM
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
CVSS 5.3
CVE-2026-13500 HIGH
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
CVSS 7.3
CVE-2026-13498 HIGH
yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
CVSS 7.3
CVE-2026-13497 MEDIUM
itsourcecode Hospital Management System appointment.php sql injection
CVSS 6.3
CVE-2026-13496 MEDIUM
itsourcecode Hospital Management System ajaxmedicine.php sql injection
CVSS 6.3
CVE-2026-13495 MEDIUM
itsourcecode Hospital Management System adminprofile.php sql injection
CVSS 4.7
CVE-2026-13488 HIGH
SourceCodester Class and Exam Timetabling System preview7.php sql injection
CVSS 7.3
CVE-2026-13487 HIGH
SourceCodester Class and Exam Timetabling System archive.php sql injection
CVSS 7.3
CVE-2026-13486 HIGH
SourceCodester Class and Exam Timetabling System preview6.php sql injection
CVSS 7.3
CVE-2026-13485 HIGH
SourceCodester Class and Exam Timetabling System preview.php sql injection
CVSS 7.3
CVE-2026-57522 LOW
Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
CVSS 3.5
CVE-2026-0864 MEDIUM
Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-50574 HIGH
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVSS 8.3
CVE-2026-12888 LOW
Thinkst Applied Research Canarytokens - HTML Injection in the Canarytoken Google Chat Notification
CVE-2026-12822 MEDIUM
langflow-ai langflow Bundle URL Loader code injection
CVSS 5.3
CVE-2026-12812 LOW
Radware Cyber Controller HTML Report Generation HTML injection
CVSS 3.5
Details
Vulnerabilities 4,984
Exploit Likelihood High