CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,807 vulnerabilities with CWE-74
CVE-2025-6768
MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-6767
MEDIUM
sfturing hosp_order <627f426331da8086ce8fff2017d65b1ddef384f8 - SQL...
CVSS 6.3
CVE-2025-6766
MEDIUM
sfturing hosp_order < 2021-09-03 - SQL Injection via OfficeServiceImpl.java getOfficeName Function
CVSS 6.3
CVE-2025-6753
MEDIUM
huija bicycleSharingServer 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6749
MEDIUM
huija bicycleSharingServer - SQL Injection
CVSS 6.3
CVE-2025-6738
MEDIUM
huija bicycleSharingServer <7b8a3ba48ad618604abd4797d2e7cf3b5ac7625...
CVSS 6.3
CVE-2025-6668
HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandId Parameter
CVSS 7.3
CVE-2025-6665
HIGH
code-projects Inventory Management System 1.0 - SQL Injection via editBrandStatus Parameter
CVSS 7.3
CVE-2025-6612
HIGH
code-projects Inventory Management System 1.0 - SQL Injection via categoriesId Parameter
CVSS 7.3
CVE-2025-6611
HIGH
code-projects Inventory Management System 1.0 - SQL Injection via brandStatus Parameter
CVSS 7.3
CVE-2025-20281
CRITICAL
KEV
Cisco Identity Services Engine - Unauthenticated Remote Code Execution via API Request
CVSS 10.0
CVE-2025-6610
MEDIUM
Employee Management System <= 1.0 - SQL Injection via FirstName Parameter in editempprofile.php
CVSS 4.7
CVE-2025-6609
MEDIUM
Best Salon Management System 1.0 - SQL Injection via fromdate/todate Parameter
CVSS 6.3
CVE-2025-6608
MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6607
MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/stock.php ID Parameter
CVSS 6.3
CVE-2025-6606
MEDIUM
Best Salon Management System 1.0 - SQL Injection via /panel/add-services.php Type Parameter
CVSS 6.3
CVE-2025-6605
MEDIUM
Best Salon Management System 1.0 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6604
MEDIUM
Best Salon Management System 1.0 - SQL Injection via Name Parameter in add-staff.php
CVSS 6.3
CVE-2025-6583
MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6582
MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6581
MEDIUM
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 6.3
CVE-2025-6580
HIGH
SourceCodester Best Salon Management System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6579
HIGH
code-projects Car Rental System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6578
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection
CVSS 7.3
CVE-2025-6570
MEDIUM
PHPGurukul Hospital Management System 4.0 - SQL Injection
CVSS 6.3
Details
Vulnerabilities
4,807
Exploit Likelihood
High