CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,805 vulnerabilities with CWE-74
CVE-2025-8703 MEDIUM
Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 - SQL Injection via energyId Parameter
CVSS 6.3
CVE-2025-8702 MEDIUM
Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 - SQL Injection via ObjectID Parameter
CVSS 6.3
CVE-2025-8701 MEDIUM
Wanzhou WOES Intelligent Optimization Energy Saving System 1.0 - SQL Injection via optUser Parameter
CVSS 6.3
CVE-2025-8518 MEDIUM
Vvveb 1.0.5 - Remote Code Execution in Code Editor Save Function
CVSS 4.7
CVE-2025-8503 HIGH
Online Medicine Guide 1.0 - SQL Injection via mname Parameter in /adaddmed.php
CVSS 7.3
CVE-2025-8502 HIGH
Online Medicine Guide 1.0 - SQL Injection via /changepass.php ups Parameter
CVSS 7.3
CVE-2025-8500 MEDIUM
Human Resource Integrated System 1.0 - SQL Injection via /insert-and-view/action.php Content Parameter
CVSS 6.3
CVE-2025-8499 HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindambulence2.php
CVSS 7.3
CVE-2025-8498 HIGH
Online Medicine Guide 1.0 - SQL Injection via uname Parameter in cart/index.php
CVSS 7.3
CVE-2025-8497 HIGH
Online Medicine Guide 1.0 - SQL Injection via Search Parameter in cusfindphar2.php
CVSS 7.3
CVE-2025-8496 HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /viewform.php ID Parameter
CVSS 7.3
CVE-2025-8495 HIGH
Intern Membership Management System 1.0 - SQL Injection via Username Parameter in edit_admin_query.php
CVSS 7.3
CVE-2025-8494 HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/delete_student.php ID Parameter
CVSS 7.3
CVE-2025-8493 HIGH
Intern Membership Management System 1.0 - SQL Injection via /admin/edit_student_query.php ID Parameter
CVSS 7.3
CVE-2025-8471 HIGH
projectworlds Online Admission System 1.0 - SQL Injection via /adminlogin.php a_id Parameter
CVSS 7.3
CVE-2025-8470 HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via ID Parameter in deleteroom.php
CVSS 7.3
CVE-2025-8469 HIGH
SourceCodester Online Hotel Reservation System 1.0 - SQL Injection via /admin/deletegallery.php ID Parameter
CVSS 7.3
CVE-2025-8468 HIGH
Wazifa System 1.0 - SQL Injection via Reset Controller Email Parameter
CVSS 7.3
CVE-2025-8467 HIGH
Wazifa System 1.0 - SQL Injection via Username Parameter in regcontrol.php
CVSS 7.3
CVE-2025-8466 HIGH
Online Farm System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-8443 HIGH
Online Medicine Guide 1.0 - SQL Injection via Login Username Parameter
CVSS 7.3
CVE-2025-8442 HIGH
Online Medicine Guide 1.0 - SQL Injection via /cussignup.php uname Parameter
CVSS 7.3
CVE-2025-8441 HIGH
Online Medicine Guide 1.0 - SQL Injection via phuname Parameter in pharsignup.php
CVSS 7.3
CVE-2025-8439 HIGH
Wazifa System 1.0 - SQL Injection via Password Parameter in updatesettings.php
CVSS 7.3
CVE-2025-8438 HIGH
code-projects Wazifa System 1.0 - SQL Injection via Post Parameter
CVSS 7.3
Details
Vulnerabilities 4,805
Exploit Likelihood High