CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,787 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 9 of 116
- CVE-2025-14515CRITICALCVSS 9.8EG 9.82025-12-11
A vulnerability has been found in Campcodes Supplier Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_unit.php. Such manipulation of the argument txtunitDetails leads to sql injection…
- CVE-2025-14514CRITICALCVSS 9.8EG 9.82025-12-11
A flaw has been found in Campcodes Supplier Management System 1.0. Affected is an unknown function of the file /admin/add_distributor.php. This manipulation of the argument txtDistributorAddress causes sql injection. The attack can be init…
- CVE-2025-14285CRITICALCVSS 9.8EG 9.82025-12-09
A vulnerability was found in code-projects Employee Profile Management System 1.0. Affected is an unknown function of the file edit_personnel.php. The manipulation of the argument per_id results in sql injection. The attack can be launched…
- CVE-2025-14258CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability has been found in itsourcecode Student Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /newsubject.php. The manipulation of the argument sub leads to sql injection. The attack m…
- CVE-2025-14257CRITICALCVSS 9.8EG 9.82025-12-08
A flaw has been found in itsourcecode Student Management System 1.0. Affected is an unknown function of the file /newrecord.php. Executing manipulation of the argument ID can lead to sql injection. The attack can be launched remotely. The …
- CVE-2025-14256CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was detected in itsourcecode Student Management System 1.0. This impacts an unknown function of the file /newcurriculm.php. Performing manipulation of the argument ID results in sql injection. The attack can be initiated re…
- CVE-2025-14251CRITICALCVSS 9.8EG 9.82025-12-08
A security vulnerability has been detected in code-projects Online Ordering System 1.0. This affects an unknown function of the file /admin/ of the component Admin Login. Such manipulation of the argument Username leads to sql injection. I…
- CVE-2025-14250CRITICALCVSS 9.8EG 9.82025-12-08
A weakness has been identified in code-projects Online Ordering System 1.0. The impacted element is an unknown function of the file /user_contact.php. This manipulation of the argument Name causes sql injection. It is possible to initiate …
- CVE-2025-14249CRITICALCVSS 9.8EG 9.82025-12-08
A security flaw has been discovered in code-projects Online Ordering System 1.0. The affected element is an unknown function of the file /user_school.php. The manipulation of the argument product_id results in sql injection. The attack may…
- CVE-2025-14248CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was identified in code-projects Simple Shopping Cart 1.0. Impacted is an unknown function of the file /adminlogin.php. The manipulation of the argument admin_username leads to sql injection. The attack is possible to be car…
- CVE-2025-14247CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was determined in code-projects Simple Shopping Cart 1.0. This issue affects some unknown processing of the file /Admin/additems.php. Executing manipulation of the argument item_name can lead to sql injection. The attack ca…
- CVE-2025-14246CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was found in code-projects Simple Shopping Cart 1.0. This vulnerability affects unknown code of the file /Customers/settings.php. Performing manipulation of the argument user_id results in sql injection. Remote exploitation…
- CVE-2025-14227CRITICALCVSS 9.8EG 9.82025-12-08
A security flaw has been discovered in Philipinho Simple-PHP-Blog up to 94b5d3e57308bce5dfbc44c3edafa9811893d958. This issue affects some unknown processing of the file /edit.php. The manipulation results in sql injection. The attack may b…
- CVE-2025-14226CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was identified in itsourcecode Student Management System 1.0. This vulnerability affects unknown code of the file /edit_user.php. The manipulation of the argument fname leads to sql injection. The attack is possible to be c…
- CVE-2025-14223CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability has been found in code-projects Simple Leave Manager 1.0. Affected by this vulnerability is an unknown functionality of the file /request.php. Such manipulation of the argument staff_id leads to sql injection. The attack ma…
- CVE-2025-14218CRITICALCVSS 9.8EG 9.82025-12-08
A security flaw has been discovered in code-projects Currency Exchange System 1.0. The affected element is an unknown function of the file /editotheraccount.php. Performing manipulation of the argument ID results in sql injection. It is po…
- CVE-2025-14217CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was identified in code-projects Currency Exchange System 1.0. Impacted is an unknown function of the file /edittrns.php. Such manipulation of the argument ID leads to sql injection. The attack may be performed from remote. …
- CVE-2025-14216CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was determined in code-projects Currency Exchange System 1.0. This issue affects some unknown processing of the file /viewserial.php. This manipulation of the argument ID causes sql injection. The attack is possible to be c…
- CVE-2025-14215CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was found in code-projects Currency Exchange System 1.0. This vulnerability affects unknown code of the file /edit.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The …
- CVE-2025-14212CRITICALCVSS 9.8EG 9.82025-12-08
A flaw has been found in projectworlds Advanced Library Management System 1.0. Affected by this issue is some unknown functionality of the file /member_search.php. Executing a manipulation of the argument roll_number can lead to sql inject…
- CVE-2025-14211CRITICALCVSS 9.8EG 9.82025-12-08
A vulnerability was detected in projectworlds Advanced Library Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /delete_book.php. Performing a manipulation of the argument book_id results in sql…
- CVE-2025-14210CRITICALCVSS 9.8EG 9.82025-12-08
A security vulnerability has been detected in projectworlds Advanced Library Management System 1.0. Affected is an unknown function of the file /delete_member.php. Such manipulation of the argument user_id leads to sql injection. The attac…
- CVE-2025-14209CRITICALCVSS 9.8EG 9.82025-12-08
A weakness has been identified in Campcodes School File Management System 1.0. This impacts an unknown function of the file /update_query.php. This manipulation of the argument stud_id causes sql injection. The attack can be initiated remo…
- CVE-2025-13800CRITICALCVSS 9.8EG 9.82025-12-01
A vulnerability was found in ADSLR NBR1005GPEV2 250814-r037c. This issue affects the function set_mesh_disconnect of the file /send_order.cgi. The manipulation of the argument mac results in command injection. It is possible to launch the …
- CVE-2025-13799CRITICALCVSS 9.8EG 9.82025-12-01
A vulnerability has been found in ADSLR NBR1005GPEV2 250814-r037c. This vulnerability affects the function ap_macfilter_del of the file /send_order.cgi. The manipulation of the argument mac leads to command injection. It is possible to ini…
- CVE-2025-13797CRITICALCVSS 9.8EG 9.82025-12-01
A vulnerability was detected in ADSLR B-QE2W401 250814-r037c. Affected by this issue is the function parameterdel_swifimac of the file /send_order.cgi. Performing manipulation of the argument del_swifimac results in command injection. The …
- CVE-2025-13788CRITICALCVSS 9.8EG 9.82025-11-30
A vulnerability has been found in Chanjet CRM up to 20251106. The impacted element is an unknown function of the file /tools/upgradeattribute.php. The manipulation of the argument gblOrgID leads to sql injection. The attack can be initiate…
- CVE-2025-13786CRITICALCVSS 9.8EG 9.82025-11-30
A vulnerability was detected in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Impacted is the function fetch of the file /index.php. Performing manipulation of the argument content results in code injection. It is possible t…
- CVE-2025-13782CRITICALCVSS 9.8EG 9.82025-11-30
A vulnerability was identified in taosir WTCMS up to 01a5f68a3dfc2fdddb44eed967bb2d4f60487665. Affected by this issue is the function delete of the file application/Admin/Controller/SlideController.class.php of the component SlideControlle…
- CVE-2025-13585CRITICALCVSS 9.8EG 9.82025-11-24
A vulnerability was detected in itsourcecode COVID Tracking System 1.0. This issue affects some unknown processing of the file /login.php. The manipulation of the argument code results in sql injection. The attack may be performed from rem…
- CVE-2025-13583CRITICALCVSS 9.8EG 9.82025-11-24
A weakness has been identified in code-projects Question Paper Generator 1.0. This affects an unknown part of the file /signupscript.php of the component POST Parameter Handler. Executing manipulation of the argument Fname can lead to sql …
- CVE-2025-13582CRITICALCVSS 9.8EG 9.82025-11-24
A security flaw has been discovered in code-projects Jonnys Liquor 1.0. Affected by this issue is some unknown functionality of the file /detail.php of the component GET Parameter Handler. Performing manipulation of the argument Product re…
- CVE-2025-13578CRITICALCVSS 9.8EG 9.82025-11-24
A vulnerability has been found in code-projects Library System 1.0. This affects an unknown function of the file /index.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiat…
- CVE-2025-13572CRITICALCVSS 9.8EG 9.82025-11-23
A vulnerability was identified in projectworlds Advanced Library Management System 1.0. This affects an unknown part of the file /delete_admin.php. The manipulation of the argument admin_id leads to sql injection. Remote exploitation of th…
- CVE-2025-13562CRITICALCVSS 9.8EG 9.82025-11-23
A vulnerability was identified in D-Link DIR-852 1.00. This issue affects some unknown processing of the file /gena.cgi. Such manipulation of the argument service leads to command injection. The attack can be executed remotely. The exploit…
- CVE-2025-13561CRITICALCVSS 9.8EG 9.82025-11-23
A vulnerability was determined in SourceCodester Company Website CMS 1.0. This vulnerability affects unknown code of the file /admin/index.php. This manipulation of the argument Username causes sql injection. Remote exploitation of the att…
- CVE-2025-13485CRITICALCVSS 9.8EG 9.82025-11-21
A security flaw has been discovered in itsourcecode Online File Management System 1.0. This issue affects some unknown processing of the file /ajax.php?action=login. The manipulation of the argument Username results in sql injection. The a…
- CVE-2025-64428CRITICALCVSS 9.8EG 9.82025-11-20
Dataease is an open source data visualization analysis tool. Versions prior to 2.10.17 are vulnerable to JNDI injection. A blacklist was added in the patch for version 2.10.14. However, JNDI injection remains possible via the iiop, corbana…
- CVE-2025-13303CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was determined in code-projects Courier Management System 1.0. Affected by this issue is some unknown functionality of the file /search-edit.php. This manipulation of the argument Consignment causes sql injection. The attac…
- CVE-2025-13302CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was identified in code-projects Courier Management System 1.0. This affects an unknown part of the file /add-new-officer.php. Such manipulation of the argument ManagerName leads to sql injection. The attack can be launched …
- CVE-2025-13301CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /subject/controller.php. The manipulation results in sql injection. It is…
- CVE-2025-13300CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. Affected is an unknown function of the file /settings/controller.php. The manipulation leads to sql injection. It is possible to initiate t…
- CVE-2025-13299CRITICALCVSS 9.8EG 9.82025-11-17
A flaw has been found in itsourcecode Web-Based Internet Laboratory Management System 1.0. This impacts an unknown function of the file /user/controller.php. Executing a manipulation can lead to sql injection. The attack may be performed f…
- CVE-2025-13298CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. This affects an unknown function of the file /enrollment/controller.php. Performing a manipulation results in sql injection. The attack is po…
- CVE-2025-13297CRITICALCVSS 9.8EG 9.82025-11-17
A security vulnerability has been detected in itsourcecode Web-Based Internet Laboratory Management System 1.0. The impacted element is an unknown function of the file /course/controller.php. Such manipulation leads to sql injection. The a…
- CVE-2025-13291CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was found in Campcodes Supplier Management System 1.0. This affects an unknown part of the file /manufacturer/confirm_order.php. Performing a manipulation of the argument ID results in sql injection. The attack can be initi…
- CVE-2025-13285CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was identified in itsourcecode Online Voting System 1.0. The affected element is an unknown function of the file /login.php. Such manipulation of the argument Username leads to sql injection. The attack may be launched remo…
- CVE-2025-13280CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was determined in CodeAstro Simple Inventory System 1.0. The impacted element is an unknown function of the file /index.php of the component Login. Executing a manipulation of the argument Username can lead to sql injection…
- CVE-2025-13277CRITICALCVSS 9.8EG 9.82025-11-17
A flaw has been found in code-projects Nero Social Networking Site 1.0. This issue affects some unknown processing of the file /friendsphoto.php. This manipulation of the argument ID causes sql injection. The attack can be initiated remote…
- CVE-2025-13272CRITICALCVSS 9.8EG 9.82025-11-17
A vulnerability was identified in Campcodes School Fees Payment Management System 1.0. Affected is an unknown function of the file /manage_course.php. Such manipulation of the argument ID leads to sql injection. The attack can be executed …
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →