CWE-707— Improper Neutralization
The product does not ensure or incorrectly ensures that structured messages or data are well-formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.— MITRE CWE catalog
263 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-707page 1 of 6
- CVE-2024-43572CRITICALCVSS 7.8EG 9.0⚠ KEV2024-10-08
Microsoft Management Console Remote Code Execution Vulnerability
- CVE-2025-26633CRITICALCVSS 7.0EG 9.0⚠ KEV2025-03-11
Improper neutralization in Microsoft Management Console allows an unauthorized attacker to bypass a security feature locally.
- CVE-2026-20330CRITICALCVSS 9.9EG 9.92026-09-16
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Adaptive Security Appliance Software, Cisco Secure Firewall Threat Defense Software and Cisco Secure Firewall Management Center Software engi…
- CVE-2026-76284CRITICALCVSS 9.8EG 9.82026-10-07
Improper Neutralization. Splunk addressed multiple internally identified vulnerabilities in Splunk Enterprise versions 10.4.3, 10.2.7, 10.0.10, and 9.4.15. The vulnerabilities are grouped by Common Weakness Enumeration (CWE), with one Comm…
- CVE-2026-76499CRITICALCVSS 9.8EG 9.82026-10-07
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Application Policy Infrastructure Controller (APIC) engineering team has conducted a comprehensive internal security review. This review resulted in…
- CVE-2026-76443CRITICALCVSS 9.8EG 9.82026-09-14
As part of Cisco's ongoing commitment to proactive security and product quality, the Cisco Secure Email Gateway and Cisco Secure Email and Web Manager engineering team has conducted a comprehensive internal security review. This review res…
- CVE-2026-18613CRITICALCVSS 9.8EG 9.82026-08-03
A vulnerability has been found in GL-iNet GL-MT3000 up to 4.4.5. This issue affects the function plugins.set_config of the file /cgi-bin/glc of the component plugins.so Native Plugin. Such manipulation leads to injection. The attack can be…
- CVE-2026-3813CRITICALCVSS 9.8EG 9.82026-03-09
A vulnerability was identified in opencc JFlow up to 5badc00db382d7cb82dad231e6a866b18e0addfe. Affected by this vulnerability is the function Calculate of the file src/main/java/bp/wf/httphandler/WF_CCForm.java. Such manipulation leads to …
- CVE-2026-2954CRITICALCVSS 9.8EG 9.82026-02-22
A vulnerability was found in Dromara UJCMS 10.0.2. Impacted is the function importChanel of the file /api/backend/ext/import-data/import-channel of the component ImportDataController. Performing a manipulation of the argument driverClassNa…
- CVE-2022-4088CRITICALCVSS 7.3EG 9.82022-11-24
A vulnerability was found in rickxy Stock Management System and classified as critical. Affected by this issue is some unknown functionality of the file /pages/processlogin.php. The manipulation of the argument user/password leads to sql i…
- CVE-2022-3973CRITICALCVSS 7.3EG 9.82022-11-13
A vulnerability classified as critical has been found in Pingkon HMS-PHP. Affected is an unknown function of the file /admin/admin.php of the component Data Pump Metadata. The manipulation of the argument uname/pass leads to sql injection.…
- CVE-2022-3972CRITICALCVSS 7.3EG 9.82022-11-13
A vulnerability was found in Pingkon HMS-PHP. It has been rated as critical. This issue affects some unknown processing of the file admin/adminlogin.php. The manipulation of the argument uname/pass leads to sql injection. The attack may be…
- CVE-2022-3955CRITICALCVSS 7.3EG 9.82022-11-11
A vulnerability was found in tholum crm42. It has been rated as critical. This issue affects some unknown processing of the file crm42\class\class.user.php of the component Login. The manipulation of the argument user_name leads to sql inj…
- CVE-2022-3878CRITICALCVSS 7.3EG 9.82022-11-07
A vulnerability classified as critical has been found in Maxon ERP. This affects an unknown part of the file /index.php/purchase_order/browse_data. The manipulation of the argument tb_search leads to sql injection. It is possible to initia…
- CVE-2022-3583CRITICALCVSS 7.3EG 9.82022-10-18
A vulnerability was found in SourceCodester Canteen Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file login.php. The manipulation of the argument business leads to sql injection. T…
- CVE-2022-4011CRITICALCVSS 6.5EG 9.82022-11-16
A vulnerability was found in Simple History Plugin. It has been rated as critical. This issue affects some unknown processing of the component Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutra…
- CVE-2022-4726CRITICALCVSS 6.3EG 9.82022-12-27
A vulnerability classified as critical was found in SourceCodester Sanitization Management System 1.0. Affected by this vulnerability is an unknown functionality of the component Admin Login. The manipulation of the argument username/passw…
- CVE-2021-4261CRITICALCVSS 6.3EG 9.82022-12-19
A vulnerability classified as critical has been found in pacman-canvas up to 1.0.5. Affected is the function addHighscore of the file data/db-handler.php. The manipulation leads to sql injection. It is possible to launch the attack remotel…
- CVE-2022-4592CRITICALCVSS 6.3EG 9.82022-12-18
A vulnerability was found in luckyshot CRMx and classified as critical. This issue affects the function get/save/delete/comment/commentdelete of the file index.php. The manipulation leads to sql injection. The attack may be initiated remot…
- CVE-2021-4246CRITICALCVSS 6.3EG 9.82022-12-17
A vulnerability was found in roxlukas LMeve and classified as critical. Affected by this issue is some unknown functionality of the component Login Page. The manipulation of the argument X-Forwarded-For leads to sql injection. The attack m…
- CVE-2022-4277CRITICALCVSS 6.3EG 9.82022-12-03
A vulnerability was found in Shaoxing Background Management System. It has been declared as critical. This vulnerability affects unknown code of the file /Default/Bd. The manipulation of the argument id leads to sql injection. The attack c…
- CVE-2022-4275CRITICALCVSS 6.3EG 9.82022-12-03
A vulnerability has been found in House Rental System and classified as critical. Affected by this vulnerability is an unknown functionality of the file search-property.php of the component POST Request Handler. The manipulation of the arg…
- CVE-2022-4274CRITICALCVSS 6.3EG 9.82022-12-03
A vulnerability, which was classified as critical, was found in House Rental System. Affected is an unknown function of the file /view-property.php. The manipulation of the argument property_id leads to sql injection. It is possible to lau…
- CVE-2022-4257CRITICALCVSS 6.3EG 9.82022-12-01
A vulnerability was found in C-DATA Web Management System. It has been rated as critical. This issue affects some unknown processing of the file cgi-bin/jumpto.php of the component GET Parameter Handler. The manipulation of the argument ho…
- CVE-2022-4247CRITICALCVSS 6.3EG 9.82022-12-01
A vulnerability classified as critical was found in Movie Ticket Booking System. This vulnerability affects unknown code of the file booking.php. The manipulation of the argument id leads to sql injection. The attack can be initiated remot…
- CVE-2022-4051CRITICALCVSS 6.3EG 9.82022-11-17
A vulnerability has been found in Hostel Searching Project and classified as critical. This vulnerability affects unknown code of the file view-property.php. The manipulation of the argument property_id leads to sql injection. The attack c…
- CVE-2022-4012CRITICALCVSS 6.3EG 9.82022-11-16
A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the …
- CVE-2022-3998CRITICALCVSS 6.3EG 9.82022-11-15
A vulnerability, which was classified as critical, was found in MonikaBrzica scm. This affects an unknown part of the file uredi_korisnika.php. The manipulation of the argument id leads to sql injection. It is possible to initiate the atta…
- CVE-2022-3956CRITICALCVSS 6.3EG 9.82022-11-11
A vulnerability classified as critical has been found in tsruban HHIMS 2.1. Affected is an unknown function of the component Patient Portrait Handler. The manipulation of the argument PID leads to sql injection. It is possible to launch th…
- CVE-2022-3948CRITICALCVSS 6.3EG 9.82022-11-11
A vulnerability classified as critical was found in eolinker goku_lite. This vulnerability affects unknown code of the file /plugin/getList. The manipulation of the argument route/keyword leads to sql injection. The attack can be initiated…
- CVE-2022-3947CRITICALCVSS 6.3EG 9.82022-11-11
A vulnerability classified as critical has been found in eolinker goku_lite. This affects an unknown part of the file /balance/service/list. The manipulation of the argument route/keyword leads to sql injection. It is possible to initiate …
- CVE-2022-3732CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability was found in seccome Ehoney and classified as critical. Affected by this issue is some unknown functionality of the file /api/v1/bait/set. The manipulation of the argument Payload leads to sql injection. The attack may be l…
- CVE-2022-3731CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability has been found in seccome Ehoney and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/v1/attack/token. The manipulation of the argument Payload leads to sql injection. The …
- CVE-2022-3730CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability, which was classified as critical, was found in seccome Ehoney. Affected is an unknown function of the file /api/v1/attack/falco. The manipulation of the argument Payload leads to sql injection. It is possible to launch the…
- CVE-2022-3729CRITICALCVSS 6.3EG 9.82022-10-28
A vulnerability, which was classified as critical, has been found in seccome Ehoney. This issue affects some unknown processing of the file /api/v1/attack. The manipulation of the argument AttackIP leads to sql injection. The attack may be…
- CVE-2022-3671CRITICALCVSS 6.3EG 9.82022-10-26
A vulnerability classified as critical was found in SourceCodester eLearning System 1.0. This vulnerability affects unknown code of the file /admin/students/manage.php. The manipulation of the argument id leads to sql injection. The attack…
- CVE-2022-3504CRITICALCVSS 6.3EG 9.82022-10-14
A vulnerability was found in SourceCodester Sanitization Management System and classified as critical. This issue affects some unknown processing of the file /php-sms/?p=services/view_service. The manipulation of the argument id leads to s…
- CVE-2022-3332CRITICALCVSS 6.3EG 9.82022-09-28
A vulnerability classified as critical has been found in SourceCodester Food Ordering Management System. This affects an unknown part of the file router.php of the component POST Parameter Handler. The manipulation of the argument username…
- CVE-2021-4262CRITICALCVSS 5.5EG 9.82022-12-19
A vulnerability classified as critical was found in laravel-jqgrid. Affected by this vulnerability is the function getRows of the file src/Mgallegos/LaravelJqgrid/Repositories/EloquentRepositoryAbstract.php. The manipulation leads to sql i…
- CVE-2022-4566CRITICALCVSS 5.5EG 9.82022-12-16
A vulnerability, which was classified as critical, has been found in y_project RuoYi 4.7.5. This issue affects some unknown processing of the file com/ruoyi/generator/controller/GenController. The manipulation leads to sql injection. The n…
- CVE-2022-4454CRITICALCVSS 5.5EG 9.82022-12-13
A vulnerability, which was classified as critical, has been found in m0ver bible-online. Affected by this issue is the function query of the file src/main/java/custom/application/search.java of the component Search Handler. The manipulatio…
- CVE-2022-4399CRITICALCVSS 5.5EG 9.82022-12-10
A vulnerability was found in TicklishHoneyBee nodau. It has been rated as critical. Affected by this issue is some unknown functionality of the file src/db.c. The manipulation of the argument value/name leads to sql injection. The name of …
- CVE-2022-3789CRITICALCVSS 5.5EG 9.82022-11-01
A vulnerability has been found in Tim Campus Confession Wall and classified as critical. Affected by this vulnerability is an unknown functionality of the file share.php. The manipulation of the argument post_id leads to sql injection. The…
- CVE-2022-3467CRITICALCVSS 5.5EG 9.82022-10-12
A vulnerability classified as critical was found in Jiusi OA. Affected by this vulnerability is an unknown functionality of the file /jsoa/hntdCustomDesktopActionContent. The manipulation of the argument inforid leads to sql injection. The…
- CVE-2022-3941CRITICALCVSS 5.3EG 9.82022-11-11
A vulnerability has been found in Activity Log Plugin and classified as critical. This vulnerability affects unknown code of the component HTTP Header Handler. The manipulation of the argument X-Forwarded-For leads to improper output neutr…
- CVE-2022-4248CRITICALCVSS 5.0EG 9.82022-12-01
A vulnerability, which was classified as critical, has been found in Movie Ticket Booking System. This issue affects some unknown processing of the file editBooking.php. The manipulation of the argument id leads to sql injection. The attac…
- CVE-2022-4222CRITICALCVSS 5.0EG 9.82022-11-30
A vulnerability was found in SourceCodester Canteen Management System. It has been rated as critical. This issue affects the function query of the file ajax_invoice.php of the component POST Request Handler. The manipulation of the argumen…
- CVE-2022-3714CRITICALCVSS 5.0EG 9.82022-10-27
A vulnerability classified as critical has been found in SourceCodester Online Medicine Ordering System 1.0. Affected is an unknown function of the file admin/?page=orders/view_order. The manipulation of the argument id leads to sql inject…
- CVE-2022-3414CRITICALCVSS 5.0EG 9.82022-10-07
A vulnerability was found in SourceCodester Web-Based Student Clearance System. It has been classified as critical. Affected is an unknown function of the file /Admin/login.php of the component POST Parameter Handler. The manipulation of t…
- CVE-2022-4015CRITICALCVSS 4.7EG 9.82022-11-16
A vulnerability, which was classified as critical, was found in Sports Club Management System 119. This affects an unknown part of the file admin/make_payments.php. The manipulation of the argument m_id/plan leads to sql injection. It is p…
Map vulnerabilities like CWE-707 to your infrastructure
EchelonGraph correlates every CVE — across CWE-707 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →