CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-13532
MEDIUM
itsourcecode Hospital Management System departmentDoctor.php sql injection
CVSS 6.3
CVE-2026-13531
MEDIUM
itsourcecode Hospital Management System department.php sql injection
CVSS 6.3
CVE-2026-13530
MEDIUM
itsourcecode Hospital Management System Appointment appointmentdetail.php sql injection
CVSS 6.3
CVE-2026-13529
MEDIUM
YzmCMS index.php sql injection
CVSS 5.6
CVE-2026-13527
HIGH
SourceCodester Class and Exam Timetabling System preview4.php sql injection
CVSS 7.3
CVE-2026-13526
HIGH
SourceCodester Class and Exam Timetabling System edit_class.php sql injection
CVSS 7.3
CVE-2026-13525
MEDIUM
CodeAstro Human Resource Management System Update_Earn_Leave Endpoint Employee_model.php emselectByCode sql injection
CVSS 6.3
CVE-2026-13521
HIGH
SourceCodester Class and Exam Timetabling System preview5.php sql injection
CVSS 7.3
CVE-2026-13520
MEDIUM
itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection
CVSS 6.3
CVE-2026-13501
MEDIUM
antlr ANTLR4 gofmt GoTarget.java GoTarget command injection
CVSS 5.3
CVE-2026-13500
HIGH
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
CVSS 7.3
CVE-2026-13498
HIGH
yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injection
CVSS 7.3
CVE-2026-13497
MEDIUM
itsourcecode Hospital Management System appointment.php sql injection
CVSS 6.3
CVE-2026-13496
MEDIUM
itsourcecode Hospital Management System ajaxmedicine.php sql injection
CVSS 6.3
CVE-2026-13495
MEDIUM
itsourcecode Hospital Management System adminprofile.php sql injection
CVSS 4.7
CVE-2026-13488
HIGH
SourceCodester Class and Exam Timetabling System preview7.php sql injection
CVSS 7.3
CVE-2026-13487
HIGH
SourceCodester Class and Exam Timetabling System archive.php sql injection
CVSS 7.3
CVE-2026-13486
HIGH
SourceCodester Class and Exam Timetabling System preview6.php sql injection
CVSS 7.3
CVE-2026-13485
HIGH
SourceCodester Class and Exam Timetabling System preview.php sql injection
CVSS 7.3
CVE-2026-57522
LOW
Bitwarden Server < 2026.5.0 JSON Injection via Webhook Templates
CVSS 3.5
CVE-2026-0864
MEDIUM
Configuration Injection via Carriage Return (\r) in write() method
CVE-2026-50574
HIGH
yt-dlp: Arbitrary code execution via manifest downloads with aria2c
CVSS 8.3
CVE-2026-12888
LOW
Thinkst Applied Research Canarytokens - HTML Injection in the Canarytoken Google Chat Notification
CVE-2026-12822
MEDIUM
langflow-ai langflow Bundle URL Loader code injection
CVSS 5.3
CVE-2026-12812
LOW
Radware Cyber Controller HTML Report Generation HTML injection
CVSS 3.5
Details
Vulnerabilities
4,984
Exploit Likelihood
High