CWE-74

High likelihood

Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

Parent: CWE-707 - Improper Neutralization

The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.

4,807 vulnerabilities with CWE-74
CVE-2025-6768 MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-6767 MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-6766 MEDIUM
sfturing hosp_order < 2021-09-03 - SQL Injection via OfficeServiceImpl.java getOfficeName Function
CVSS 6.3
CVE-2025-6753 MEDIUM
huija bicycleSharingServer 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6749 MEDIUM
huija bicycleSharingServer - SQL Injection
CVSS 6.3
CVE-2025-6738 MEDIUM
huija bicycleSharingServer <7b8a3ba48ad618604abd4797d2e7cf3b5ac7625...
CVSS 6.3
CVE-2025-6668 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandId Parameter
CVSS 7.3
CVE-2025-6665 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via editBrandStatus Parameter
CVSS 7.3
CVE-2025-6612 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via categoriesId Parameter
CVSS 7.3
CVE-2025-6611 HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandStatus Parameter
CVSS 7.3
CVE-2025-20281 CRITICAL KEV
Cisco Identity Services Engine - Unauthenticated Remote Code Execution via API Request
CVSS 10.0
CVE-2025-6610 MEDIUM
Employee Management System <= 1.0 - SQL Injection via FirstName Parameter in editempprofile.php
CVSS 4.7
CVE-2025-6609 MEDIUM
Best Salon Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 6.3
CVE-2025-6608 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6607 MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/stock.php ID Parameter
CVSS 6.3
CVE-2025-6606 MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/add-services.php Type Parameter
CVSS 6.3
CVE-2025-6605 MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6604 MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in add-staff.php
CVSS 6.3
CVE-2025-6583 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6582 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6581 MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6580 HIGH
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6579 HIGH
code-projects Car Rental System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6578 HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6570 MEDIUM
PHPGurukul Hospital Management System 4.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities 4,807
Exploit Likelihood High