CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,516 vulnerabilities with CWE-74
CVE-2026-5551 HIGH
itsourcecode Free Hotel Reservation System Parameter login.php sql injection
CVSS 7.3
CVE-2026-5543 MEDIUM
PHPGurukul User Registration & Login and User Management System yesterday-reg-users.php sql injection
CVSS 6.3
CVE-2026-5540 HIGH
code-projects Simple Laundry System Parameter modifymember.php sql injection
CVSS 7.3
CVE-2026-5537 MEDIUM
halex CourseSEL HTTP GET Parameter IndexController.class.php check_sel sql injection
CVSS 6.3
CVE-2026-5534 HIGH
itsourcecode Online Enrollment System Parameter index.php sql injection
CVSS 7.3
CVE-2026-34773 MEDIUM
Electron: Registry key path injection in app.setAsDefaultProtocolClient on Windows
CVSS 4.7
CVE-2026-34767 MEDIUM
Electron: HTTP Response Header Injection in custom protocol handlers and webRequest
CVSS 5.9
CVE-2026-5368 HIGH
projectworlds Car Rental Project Parameter login.php sql injection
CVSS 7.3
CVE-2026-5339 MEDIUM
Tenda G103 Setting gpon.lua action_set_net_settings command injection
CVSS 4.7
CVE-2026-5338 MEDIUM
Tenda G103 Setting system.lua action_set_system_settings command injection
CVSS 4.7
CVE-2026-5334 HIGH
itsourcecode Online Enrollment System Parameter index.php sql injection
CVSS 7.3
CVE-2026-5333 HIGH
DefaultFuction Content-Management-System tools.php command injection
CVSS 7.3
CVE-2026-5328 MEDIUM
shsuishang modulithshop ProductItemDao ProductIndexServiceImpl.java listItem sql injection
CVSS 6.3
CVE-2026-5327 MEDIUM
efforthye fast-filesystem-mcp index.ts handleGetDiskUsage command injection
CVSS 6.3
CVE-2026-5322 HIGH
AlejandroArciniegas mcp-data-vis MCP server.js request sql injection
CVSS 7.3
CVE-2026-5257 HIGH
code-projects Simple Laundry System Parameter delstaffinfo.php sql injection
CVSS 7.3
CVE-2026-5256 HIGH
code-projects Simple Laundry System Parameter modify.php sql injection
CVSS 7.3
CVE-2026-5238 HIGH
itsourcecode Payroll Management System Parameter view_employee.php sql injection
CVSS 7.3
CVE-2026-5237 HIGH
itsourcecode Payroll Management System Parameter manage_user.php sql injection
CVSS 7.3
CVE-2026-5206 MEDIUM
code-projects Simple Gym Management System Payment sql injection
CVSS 6.3
CVE-2026-5198 HIGH
code-projects Student Membership System Admin Login index.php sql injection
CVSS 7.3
CVE-2026-5197 MEDIUM
code-projects Student Membership System delete_user.php sql injection
CVSS 6.3
CVE-2026-5196 MEDIUM
code-projects Student Membership System delete_member.php sql injection
CVSS 6.3
CVE-2026-5195 HIGH
code-projects Student Membership System User Registration sql injection
CVSS 7.3
CVE-2026-5184 MEDIUM
TRENDnet TEW-713RE setSysAdm command injection
CVSS 6.3
Details
Vulnerabilities 4,516
Exploit Likelihood High