CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,798 vulnerabilities with CWE-74
CVE-2025-10121
MEDIUM
uverif < 3.2 - SQL Injection via addbatch Function
CVSS 6.3
CVE-2025-10118
HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10115
HIGH
SiempreCMS <= 1.3.6 - SQL Injection via user_search_ajax.php name/userName Parameter
CVSS 7.3
CVE-2025-10114
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Name Parameter in Profile
CVSS 7.3
CVE-2025-10113
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Room Module
CVSS 7.3
CVE-2025-10112
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via Department ID Parameter
CVSS 7.3
CVE-2025-10111
HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Instructor Module
CVSS 7.3
CVE-2025-10110
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Endpoint
CVSS 6.3
CVE-2025-10109
HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in delete_payment Action
CVSS 7.3
CVE-2025-10108
HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-10106
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Keyword Parameter
CVSS 6.3
CVE-2025-10105
MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Article Search Keyword Parameter
CVSS 6.3
CVE-2025-10104
HIGH
Online Event Judging System 1.0 - SQL Injection via txtsearch Parameter in review_search.php
CVSS 7.3
CVE-2025-10103
HIGH
Online Event Judging System 1.0 - SQL Injection via main_event Parameter
CVSS 7.3
CVE-2025-10102
HIGH
Online Event Judging System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-56266
CRITICAL
Avigilon Access Control Manager 7.10.0.20 - Remote Code Execution via Host Header Injection
CVSS 9.8
CVE-2025-10100
HIGH
SourceCodester Simple Forum Discussion System 1.0 - SQL Injection via Username Parameter in admin_class.php
CVSS 7.3
CVE-2025-10098
MEDIUM
PHPGurukul User Management System 1.0 - SQL Injection via uid Parameter in edit-user-profile.php
CVSS 6.3
CVE-2025-10097
MEDIUM
SimStudioAI sim < 1.0.0 - Remote Code Injection via Execute API Code Argument
CVSS 6.3
CVE-2025-10090
HIGH
Jinher OA < 1.2 - SQL Injection via ID Parameter in GetTreeDate.aspx
CVSS 7.3
CVE-2025-10087
MEDIUM
Pet Grooming Management Software 1.0 - SQL Injection via product_id Parameter
CVSS 4.7
CVE-2025-10082
HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in manage-admins.php
CVSS 7.3
CVE-2025-10079
HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Contact Parameter in get-quote.php
CVSS 7.3
CVE-2025-10078
HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via ID Parameter in candidates.php
CVSS 7.3
CVE-2025-10077
HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
Details
Vulnerabilities
4,798
Exploit Likelihood
High