CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,984 vulnerabilities with CWE-74
CVE-2026-8795
HIGH
Rapid7 Velociraptor < 0.76.6 - Improper Encoding or Escaping of Output
CVSS 7.8
CVE-2026-11585
MEDIUM
CodeAstro Student Attendance Management System createClassArms.php sql injection
CVSS 6.3
CVE-2026-11584
MEDIUM
CodeAstro Student Attendance Management System createClass.php edit sql injection
CVSS 6.3
CVE-2026-11583
MEDIUM
CodeAstro Student Attendance Management System createClass.php sql injection
CVSS 6.3
CVE-2026-11582
HIGH
CodeAstro Student Attendance Management System index.php sql injection
CVSS 7.3
CVE-2026-11559
MEDIUM
CodeAstro Payroll System view_account.php sql injection
CVSS 6.3
CVE-2026-11558
MEDIUM
CodeAstro Payroll System home_salary.php sql injection
CVSS 6.3
CVE-2026-11531
HIGH
imvks786 student_management_system Administrator Login Endpoint admin_login.php sql injection
CVSS 7.3
CVE-2026-11530
HIGH
imvks786 student_management_system Login index.ph sql injection
CVSS 7.3
CVE-2026-11529
MEDIUM
designcomputer mysql-mcp-server mysql URI server.py read_resource sql injection
CVSS 6.3
CVE-2026-11514
MEDIUM
itsourcecode Hospital Management System addpatient.php sql injection
CVSS 6.3
CVE-2026-11513
MEDIUM
itsourcecode Hospital Management System adminaccount.php sql injection
CVSS 6.3
CVE-2026-11511
LOW
Bolt CMS HTML Attribute TextType.php HTML injection
CVSS 3.5
CVE-2026-11510
MEDIUM
CodeAstro Leave Management System add_leave.php sql injection
CVSS 6.3
CVE-2026-11509
MEDIUM
CodeAstro Leave Management System search_staff_for_updation.php sql injection
CVSS 6.3
CVE-2026-11508
MEDIUM
CodeAstro Leave Management System search_staff_to_assign_pc.php sql injection
CVSS 6.3
CVE-2026-11507
MEDIUM
CodeAstro Leave Management System delete_leave_type.php sql injection
CVSS 6.3
CVE-2026-11506
MEDIUM
CodeAstro Leave Management System search_staff_for_deletion.php sql injection
CVSS 6.3
CVE-2026-11501
HIGH
SourceCodester Hospitals Patient Records Management System Master.php save_patient sql injection
CVSS 7.3
CVE-2026-11495
MEDIUM
CodeAstro Ingredients Stock Management System add_stock.php sql injection
CVSS 6.3
CVE-2026-11490
HIGH
code-projects Online Music Site Search.php sql injection
CVSS 7.3
CVE-2026-11489
HIGH
code-projects Online Music Site AdminDeleteAlbum.php sql injection
CVSS 7.3
CVE-2026-11488
HIGH
code-projects Simple Flight Ticket Booking System POST Parameter checkUser.php sql injection
CVSS 7.3
CVE-2026-11487
MEDIUM
Neovim View Branch secure.lua M.read command injection
CVSS 5.3
CVE-2026-11486
HIGH
SourceCodester Class and Exam Timetabling System archive1.php sql injection
CVSS 7.3
Details
Vulnerabilities
4,984
Exploit Likelihood
High