CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,807 vulnerabilities with CWE-74
CVE-2025-7138 MEDIUM
Best Salon Management System 1.0 - SQL Injection via adminname Parameter
CVSS 6.3
CVE-2025-7137 MEDIUM
Best Salon Management System 1.0 - SQL Injection via staff_id Parameter
CVSS 6.3
CVE-2025-7136 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in View Vacancy
CVSS 7.3
CVE-2025-7135 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in save_vacancy Action
CVSS 7.3
CVE-2025-7134 HIGH
Campcodes Online Recruitment Management System 1.0 - SQL Injection via ID Parameter in Delete Application
CVSS 7.3
CVE-2025-7132 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7131 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via employee_id Parameter in save_employee_attendance
CVSS 7.3
CVE-2025-7130 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via /ajax.php ID Parameter
CVSS 7.3
CVE-2025-7129 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in delete_employee_attendance_single
CVSS 7.3
CVE-2025-7128 HIGH
Campcodes Payroll Management System 1.0 - SQL Injection via ID Parameter in /ajax.php
CVSS 7.3
CVE-2025-7127 MEDIUM
Employee Management System <= 1.0 - SQL Injection via currentpassword Parameter
CVSS 4.7
CVE-2025-7126 MEDIUM
Employee Management System <= 1.0 - SQL Injection via AdminName Parameter
CVSS 6.3
CVE-2025-7125 MEDIUM
Employee Management System <= 1.0 - SQL Injection via coursepg Parameter
CVSS 6.3
CVE-2025-7123 MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via cid/uid Parameter
CVSS 4.7
CVE-2025-7122 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /admin/index.php
CVSS 7.3
CVE-2025-7121 MEDIUM
Campcodes Complaint Management System 1.0 - SQL Injection via Complaint ID Parameter
CVSS 6.3
CVE-2025-7120 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Email Parameter in check_availability.php
CVSS 7.3
CVE-2025-7119 HIGH
Campcodes Complaint Management System 1.0 - SQL Injection via Username Parameter in /users/index.php
CVSS 7.3
CVE-2025-7102 MEDIUM
BoyunCMS < 1.4.20 - SQL Injection via Phone Parameter in Server.php
CVSS 6.3
CVE-2025-7101 MEDIUM
BoyunCMS < 1.4.20 - Remote Code Injection via db_pass Parameter in Configuration File Handler
CVSS 6.3
CVE-2025-7061 LOW
Intelbras InControl <2.21.60.9 - CSV Injection
CVSS 2.7
CVE-2025-6963 HIGH
Campcodes Employee Management System 1.0 - SQL Injection via myprofile.php ID Parameter
CVSS 7.3
CVE-2025-6962 HIGH
Campcodes Employee Management System 1.0 - SQL Injection via /myprofileup.php ID Parameter
CVSS 7.3
CVE-2025-6961 HIGH
Campcodes Employee Management System 1.0 - SQL Injection via /mark.php ID Parameter
CVSS 7.3
CVE-2025-6960 HIGH
Campcodes Employee Management System 1.0 - SQL Injection via ID Parameter in /empproject.php
CVSS 7.3
Details
Vulnerabilities 4,807
Exploit Likelihood High