CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,798 vulnerabilities with CWE-74
CVE-2025-10121 MEDIUM
uverif < 3.2 - SQL Injection via addbatch Function
CVSS 6.3
CVE-2025-10118 HIGH
E-Logbook with Health Monitoring System for COVID-19 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-10115 HIGH
SiempreCMS <= 1.3.6 - SQL Injection via user_search_ajax.php name/userName Parameter
CVSS 7.3
CVE-2025-10114 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Name Parameter in Profile
CVSS 7.3
CVE-2025-10113 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Room Module
CVSS 7.3
CVE-2025-10112 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via Department ID Parameter
CVSS 7.3
CVE-2025-10111 HIGH
itsourcecode Student Information Management System 1.0 - SQL Injection via ID Parameter in Instructor Module
CVSS 7.3
CVE-2025-10110 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Endpoint
CVSS 6.3
CVE-2025-10109 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in delete_payment Action
CVSS 7.3
CVE-2025-10108 HIGH
Campcodes Online Loan Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-10106 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Search Keyword Parameter
CVSS 6.3
CVE-2025-10105 MEDIUM
ChanCMS < 3.3.1 - SQL Injection via Article Search Keyword Parameter
CVSS 6.3
CVE-2025-10104 HIGH
Online Event Judging System 1.0 - SQL Injection via txtsearch Parameter in review_search.php
CVSS 7.3
CVE-2025-10103 HIGH
Online Event Judging System 1.0 - SQL Injection via main_event Parameter
CVSS 7.3
CVE-2025-10102 HIGH
Online Event Judging System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-56266 CRITICAL
Avigilon Access Control Manager 7.10.0.20 - Remote Code Execution via Host Header Injection
CVSS 9.8
CVE-2025-10100 HIGH
SourceCodester Simple Forum Discussion System 1.0 - SQL Injection via Username Parameter in admin_class.php
CVSS 7.3
CVE-2025-10098 MEDIUM
PHPGurukul User Management System 1.0 - SQL Injection via uid Parameter in edit-user-profile.php
CVSS 6.3
CVE-2025-10097 MEDIUM
SimStudioAI sim < 1.0.0 - Remote Code Injection via Execute API Code Argument
CVSS 6.3
CVE-2025-10090 HIGH
Jinher OA < 1.2 - SQL Injection via ID Parameter in GetTreeDate.aspx
CVSS 7.3
CVE-2025-10087 MEDIUM
Pet Grooming Management Software 1.0 - SQL Injection via product_id Parameter
CVSS 4.7
CVE-2025-10082 HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in manage-admins.php
CVSS 7.3
CVE-2025-10079 HIGH
PHPGurukul Small CRM 4.0 - SQL Injection via Contact Parameter in get-quote.php
CVSS 7.3
CVE-2025-10078 HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via ID Parameter in candidates.php
CVSS 7.3
CVE-2025-10077 HIGH
SourceCodester Online Polling System 1.0 - SQL Injection via Email Parameter in Registeracc.php
CVSS 7.3
Details
Vulnerabilities 4,798
Exploit Likelihood High