CWE-74
High likelihoodImproper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,807 vulnerabilities with CWE-74
CVE-2025-6450
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6449
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via transaction_id Parameter
CVSS 7.3
CVE-2025-6448
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/delete_room.php room_id Parameter
CVSS 7.3
CVE-2025-6447
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6446
HIGH
Client Details System 1.0 - SQL Injection via Username Parameter
CVSS 7.3
CVE-2025-6421
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via /admin/add_account.php name/admin_id Parameter
CVSS 7.3
CVE-2025-6420
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6419
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via room_type Parameter
CVSS 7.3
CVE-2025-6418
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via Name Parameter in Edit Query Account
CVSS 7.3
CVE-2025-6417
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via Award Details Parameter
CVSS 6.3
CVE-2025-6416
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6415
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6414
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6413
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6412
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6411
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via /admin/changepropic.php imageid Parameter
CVSS 6.3
CVE-2025-6410
MEDIUM
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via editid Parameter
CVSS 6.3
CVE-2025-6409
HIGH
PHPGurukul Art Gallery Management System 1.1 - SQL Injection via Forgot Password Email Parameter
CVSS 7.3
CVE-2025-6408
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-6407
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Username Parameter in /user-login.php
CVSS 7.3
CVE-2025-6406
HIGH
Campcodes Online Hospital Management System 1.0 - SQL Injection via Forgot Password Fullname Parameter
CVSS 7.3
CVE-2025-6405
HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via editid Parameter
CVSS 7.3
CVE-2025-6404
HIGH
Campcodes Online Teacher Record Management System 1.0 - SQL Injection via searchdata Parameter
CVSS 7.3
CVE-2025-6403
HIGH
School Fees Payment System 1.0 - SQL Injection via /student.php ID Parameter
CVSS 7.3
CVE-2025-6394
HIGH
Simple Online Hotel Reservation System 1.0 - SQL Injection via firstname Parameter
CVSS 7.3
Details
Vulnerabilities
4,807
Exploit Likelihood
High