CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,807 vulnerabilities with CWE-74
CVE-2025-7177 MEDIUM
PHPGurukul Car Washing Management System 1.0 - SQL Injection via wpid Parameter
CVSS 4.7
CVE-2025-7176 HIGH
PHPGurukul Hospital Management System 1.0 - SQL Injection via viewid Parameter in view-medhistory.php
CVSS 7.3
CVE-2025-7174 HIGH
code-projects Library System 1.0 - SQL Injection via /teacher-issue-book.php idn Parameter
CVSS 7.3
CVE-2025-7173 HIGH
code-projects Library System 1.0 - SQL Injection via Username Parameter in /add-student.php
CVSS 7.3
CVE-2025-7172 HIGH
code-projects Crime Reporting System 1.0 - SQL Injection via email Parameter in /headlogin.php
CVSS 7.3
CVE-2025-7171 HIGH
code-projects Crime Reporting System 1.0 - SQL Injection via /policelogin.php Email Parameter
CVSS 7.3
CVE-2025-7170 HIGH
code-projects Crime Reporting System 1.0 - SQL Injection via Name Parameter in registration.php
CVSS 7.3
CVE-2025-7169 HIGH
code-projects Crime Reporting System 1.0 - SQL Injection via location Parameter in complainer_page.php
CVSS 7.3
CVE-2025-7168 HIGH
code-projects Crime Reporting System 1.0 - SQL Injection via Userlogin Email Parameter
CVSS 7.3
CVE-2025-7167 MEDIUM
Responsive Blog Site 1.0 - SQL Injection via Category.php ID Parameter
CVSS 6.3
CVE-2025-7166 MEDIUM
Responsive Blog Site 1.0 - SQL Injection via ID Parameter in single.php
CVSS 6.3
CVE-2025-7165 HIGH
PHPGurukul Cyber Cafe Management System 1.0 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-7164 HIGH
PHPGurukul Cyber Cafe Management System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-7163 MEDIUM
PHPGurukul Zoo Management System 2.1 - SQL Injection via cnum Parameter in add-animals.php
CVSS 6.3
CVE-2025-7162 MEDIUM
PHPGurukul Zoo Management System 2.1 - SQL Injection via cprice Parameter
CVSS 6.3
CVE-2025-7161 MEDIUM
PHPGurukul Zoo Management System 2.1 - SQL Injection via cprice Parameter
CVSS 6.3
CVE-2025-7160 HIGH
PHPGurukul Zoo Management System 2.1 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-7159 MEDIUM
PHPGurukul Zoo Management System 2.1 - SQL Injection via /admin/manage-animals.php ID Parameter
CVSS 6.3
CVE-2025-7158 MEDIUM
PHPGurukul Zoo Management System 2.1 - SQL Injection via ID Parameter in manage-normal-ticket.php
CVSS 6.3
CVE-2025-7157 HIGH
Online Note Sharing 1.0 - SQL Injection via Login Username/Password Parameter
CVSS 7.3
CVE-2025-7156 MEDIUM
hitsz-ids airda 0.0.3 - SQL Injection
CVSS 6.3
CVE-2025-7155 HIGH
PHPGurukul Online Notes Sharing System 1.0 - SQL Injection via Session ID Cookie
CVSS 7.3
CVE-2025-7150 MEDIUM
Campcodes Advanced Online Voting System 1.0 - SQL Injection via ID Parameter in voters_delete.php
CVSS 6.3
CVE-2025-7149 MEDIUM
Campcodes Advanced Online Voting System 1.0 - SQL Injection via ID Parameter in candidates_delete.php
CVSS 6.3
CVE-2025-7147 HIGH
CodeAstro Patient Record Management System 1.0 - SQL Injection via /login.php uname Parameter
CVSS 7.3
Details
Vulnerabilities 4,807
Exploit Likelihood High