CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,787 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 8 of 116
- CVE-2025-15127CRITICALCVSS 9.8EG 9.82025-12-28
A security vulnerability has been detected in FantasticLBP Hotels_Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. Affected by this issue is some unknown functionality of the file /controller/api/Room.php. Such manipulation of the ar…
- CVE-2025-15078CRITICALCVSS 9.8EG 9.82025-12-25
A vulnerability was detected in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /list_report.php. The manipulation of the argument sy results in sql injection. The attack may be launched …
- CVE-2025-15077CRITICALCVSS 9.8EG 9.82025-12-25
A security vulnerability has been detected in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /form137.php. The manipulation of the argument ID leads to sql injection. The attack may be i…
- CVE-2025-15075CRITICALCVSS 9.8EG 9.82025-12-25
A security flaw has been discovered in itsourcecode Student Management System 1.0. This issue affects some unknown processing of the file /student_p.php. Performing manipulation of the argument ID results in sql injection. The attack can b…
- CVE-2025-15074CRITICALCVSS 9.8EG 9.82025-12-25
A vulnerability was identified in itsourcecode Online Frozen Foods Ordering System 1.0. This vulnerability affects unknown code of the file /customer_details.php. Such manipulation leads to sql injection. It is possible to launch the attac…
- CVE-2025-15073CRITICALCVSS 9.8EG 9.82025-12-24
A vulnerability was determined in itsourcecode Online Frozen Foods Ordering System 1.0. This affects an unknown part of the file /contact_us.php. This manipulation of the argument Name causes sql injection. It is possible to initiate the a…
- CVE-2025-15012CRITICALCVSS 9.8EG 9.82025-12-22
A vulnerability was determined in code-projects Refugee Food Management System 1.0. The affected element is an unknown function of the file /home/home.php. This manipulation of the argument a causes sql injection. The attack is possible to…
- CVE-2025-14711CRITICALCVSS 9.8EG 9.82025-12-15
A flaw has been found in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This vulnerability affects unknown code of the file /controller/api/hotelList.php. This manipulation of the argument pickedHotelName/type c…
- CVE-2025-14710CRITICALCVSS 9.8EG 9.82025-12-15
A vulnerability was detected in FantasticLBP Hotels Server up to 67b44df162fab26df209bd5d5d542875fcbec1d0. This affects an unknown part of the file /controller/api/OrderList.php. The manipulation of the argument telephone results in sql in…
- CVE-2025-14707CRITICALCVSS 9.8EG 9.82025-12-15
A security flaw has been discovered in Shiguangwu sgwbox N3 2.0.25. Affected is an unknown function of the file /usr/sbin/http_eshell_server of the component DOCKER Feature. Performing manipulation of the argument params results in command…
- CVE-2025-14706CRITICALCVSS 9.8EG 9.82025-12-15
A vulnerability was identified in Shiguangwu sgwbox N3 2.0.25. This impacts an unknown function of the file /usr/sbin/http_eshell_server of the component NETREBOOT Interface. Such manipulation leads to command injection. The attack can be …
- CVE-2025-14705CRITICALCVSS 9.8EG 9.82025-12-15
A vulnerability was determined in Shiguangwu sgwbox N3 2.0.25. This affects an unknown function of the component SHARESERVER Feature. This manipulation of the argument params causes command injection. The attack can be initiated remotely. …
- CVE-2025-14668CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was detected in campcodes Advanced Online Examination System 1.0. This affects an unknown function of the file /query/loginExe.php. Performing a manipulation of the argument Username results in sql injection. It is possible…
- CVE-2025-14667CRITICALCVSS 9.8EG 9.82025-12-14
A security vulnerability has been detected in itsourcecode COVID Tracking System 1.0. The impacted element is an unknown function of the file /admin/?page=system_info. Such manipulation of the argument meta_value leads to sql injection. Th…
- CVE-2025-14666CRITICALCVSS 9.8EG 9.82025-12-14
A weakness has been identified in itsourcecode COVID Tracking System 1.0. The affected element is an unknown function of the file /admin/?page=user. This manipulation of the argument Username causes sql injection. The attack is possible to…
- CVE-2025-14664CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was identified in Campcodes Supplier Management System 1.0. This issue affects some unknown processing of the file /admin/view_unit.php. The manipulation of the argument chkId[] leads to sql injection. Remote exploitation o…
- CVE-2025-14661CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability has been found in itsourcecode Student Managemen System 1.0. Affected by this issue is some unknown functionality of the file /advisers.php. Such manipulation of the argument sy leads to sql injection. The attack can be lau…
- CVE-2025-14659CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was detected in D-Link DIR-860LB1 and DIR-868LB1 203b01/203b03. Affected is an unknown function of the component DHCP Daemon. The manipulation of the argument Hostname results in command injection. It is possible to launch …
- CVE-2025-14653CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was determined in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /addrecord.php. This manipulation of the argument ID causes sql injection. Remote exploitation of the attack is possi…
- CVE-2025-14652CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was found in itsourcecode Online Cake Ordering System 1.0. This issue affects some unknown processing of the file /admindetail.php?action=edit. The manipulation of the argument ID results in sql injection. The attack may be…
- CVE-2025-14650CRITICALCVSS 9.8EG 9.82025-12-14
A flaw has been found in itsourcecode Online Cake Ordering System 1.0. This affects an unknown part of the file /cakeshop/product.php. Executing manipulation of the argument Product can lead to sql injection. The attack can be launched rem…
- CVE-2025-14649CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was detected in itsourcecode Online Cake Ordering System 1.0. Affected by this issue is some unknown functionality of the file /cakeshop/supplier.php. Performing manipulation of the argument supplier results in sql injectio…
- CVE-2025-14647CRITICALCVSS 9.8EG 9.82025-12-14
A weakness has been identified in code-projects Computer Book Store 1.0. Affected is an unknown function of the file /admin_delete.php. This manipulation of the argument bookisbn causes sql injection. It is possible to initiate the attack …
- CVE-2025-14646CRITICALCVSS 9.8EG 9.82025-12-14
A security flaw has been discovered in code-projects Student File Management System 1.0. This impacts an unknown function of the file /admin/delete_student.php. The manipulation of the argument stud_id results in sql injection. The attack …
- CVE-2025-14645CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown function of the file /admin/delete_user.php. The manipulation of the argument user_id leads to sql injection. The attack is possibl…
- CVE-2025-14644CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was determined in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /update_subject.php. Executing manipulation of the argument ID can lead to sql injection. The attack can …
- CVE-2025-14643CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was found in code-projects Simple Attendance Record System 2.0. The affected element is an unknown function of the file /check.php. Performing manipulation of the argument student results in sql injection. Remote exploitati…
- CVE-2025-14640CRITICALCVSS 9.8EG 9.82025-12-14
A flaw has been found in code-projects Student File Management System 1.0. The affected element is an unknown function of the file /admin/save_student.php. Executing manipulation of the argument stud_no can lead to sql injection. The attac…
- CVE-2025-14639CRITICALCVSS 9.8EG 9.82025-12-14
A vulnerability was detected in itsourcecode Student Management System 1.0. Impacted is an unknown function of the file /uprec.php. Performing manipulation of the argument ID results in sql injection. The attack may be initiated remotely. …
- CVE-2025-14638CRITICALCVSS 9.8EG 9.82025-12-14
A security vulnerability has been detected in itsourcecode Online Pet Shop Management System 1.0. This issue affects some unknown processing of the file /pet1/update_cnp.php. Such manipulation of the argument ID leads to sql injection. The…
- CVE-2025-14637CRITICALCVSS 9.8EG 9.82025-12-13
A weakness has been identified in itsourcecode Online Pet Shop Management System 1.0. This vulnerability affects unknown code of the file /pet1/addcnp.php. This manipulation of the argument cnpname causes sql injection. The attack can be i…
- CVE-2025-14623CRITICALCVSS 9.8EG 9.82025-12-13
A weakness has been identified in code-projects Student File Management System 1.0. This issue affects some unknown processing of the file /admin/update_student.php. This manipulation of the argument stud_id causes sql injection. The attac…
- CVE-2025-14622CRITICALCVSS 9.8EG 9.82025-12-13
A security flaw has been discovered in code-projects Student File Management System 1.0. This vulnerability affects unknown code of the file /admin/save_user.php. The manipulation of the argument firstname results in sql injection. The att…
- CVE-2025-14621CRITICALCVSS 9.8EG 9.82025-12-13
A vulnerability was identified in code-projects Student File Management System 1.0. This affects an unknown part of the file /admin/update_user.php. The manipulation of the argument user_id leads to sql injection. Remote exploitation of th…
- CVE-2025-14620CRITICALCVSS 9.8EG 9.82025-12-13
A vulnerability was determined in code-projects Student File Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/login_query.php. Executing manipulation of the argument Username can lead to sql in…
- CVE-2025-14619CRITICALCVSS 9.8EG 9.82025-12-13
A vulnerability was found in code-projects Student File Management System 1.0. Affected by this vulnerability is an unknown functionality of the file login_query.php. Performing manipulation of the argument stud_no results in sql injection…
- CVE-2025-14590CRITICALCVSS 9.8EG 9.82025-12-13
A security vulnerability has been detected in code-projects Prison Management System 2.0. Impacted is an unknown function of the file /admin/search1.php. The manipulation of the argument keyname leads to sql injection. It is possible to in…
- CVE-2025-14588CRITICALCVSS 9.8EG 9.82025-12-13
A security flaw has been discovered in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /update_program.php. Performing manipulation of the argument ID results in sql injection. The attack is …
- CVE-2025-14587CRITICALCVSS 9.8EG 9.82025-12-13
A vulnerability was identified in itsourcecode Online Pet Shop Management System 1.0. This affects an unknown part of the file /pet1/available.php. Such manipulation of the argument Name leads to sql injection. The attack can be executed r…
- CVE-2025-14585CRITICALCVSS 9.8EG 9.82025-12-12
A vulnerability was found in itsourcecode COVID Tracking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/?page=zone. The manipulation of the argument ID results in sql injection. The attack may be …
- CVE-2025-14584CRITICALCVSS 9.8EG 9.82025-12-12
A vulnerability has been found in itsourcecode COVID Tracking System 1.0. Affected is an unknown function of the file /admin/login.php of the component Admin Login. The manipulation of the argument Username leads to sql injection. The atta…
- CVE-2025-14578CRITICALCVSS 9.8EG 9.82025-12-12
A weakness has been identified in itsourcecode Student Management System 1.0. The affected element is an unknown function of the file /update_account.php. This manipulation of the argument ID causes sql injection. It is possible to initiat…
- CVE-2025-14571CRITICALCVSS 9.8EG 9.82025-12-12
A vulnerability has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /borrow_book.php. Such manipulation of the argument roll_number leads to sql injection…
- CVE-2025-14570CRITICALCVSS 9.8EG 9.82025-12-12
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /view_admin.php. This manipulation of the argument admin_id causes sql injection. The att…
- CVE-2025-14566CRITICALCVSS 9.8EG 9.82025-12-12
A security flaw has been discovered in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The impacted element is an unknown function of the file /Profilers/SProfile/reg.php. Performing a manipulation of the argum…
- CVE-2025-14565CRITICALCVSS 9.8EG 9.82025-12-12
A vulnerability was identified in kidaze CourseSelectionSystem up to 42cd892b40a18d50bd4ed1905fa89f939173a464. The affected element is an unknown function of the file /Profilers/SProfile/login1.php. Such manipulation of the argument Userna…
- CVE-2025-14537CRITICALCVSS 9.8EG 9.82025-12-11
A weakness has been identified in code-projects Class and Exam Timetable Management 1.0. Affected by this issue is some unknown functionality of the file /preview7.php. This manipulation of the argument course_year_section/semester causes …
- CVE-2025-14536CRITICALCVSS 9.8EG 9.82025-12-11
A security flaw has been discovered in code-projects Class and Exam Timetable Management 1.0. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Login. The manipulation of the argument userna…
- CVE-2025-14529CRITICALCVSS 9.8EG 9.82025-12-11
A flaw has been found in Campcodes Retro Basketball Shoes Online Store 1.0. The affected element is an unknown function of the file /admin/admin_running.php. This manipulation of the argument pid causes sql injection. It is possible to ini…
- CVE-2025-14527CRITICALCVSS 9.8EG 9.82025-12-11
A weakness has been identified in projectworlds Advanced Library Management System 1.0. This vulnerability affects unknown code of the file /view_book.php. Executing a manipulation of the argument book_id can lead to sql injection. The att…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →