CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 51 of 105
- CVE-2025-20283MEDIUMCVSS 6.5EG 6.52025-07-16
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of…
- CVE-2025-20284MEDIUMCVSS 6.5EG 6.52025-07-16
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system as root. This vulnerability is due to insufficient validation of…
- CVE-2025-2030HIGHCVSS 7.3EG 7.32025-03-06
A vulnerability was found in Seeyon Zhiyuan Interconnect FE Collaborative Office Platform up to 20250224. It has been rated as critical. Affected by this issue is some unknown functionality of the file /security/addUser.jsp. The manipulati…
- CVE-2025-2033MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability, which was classified as critical, was found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /user_dashboard/view_donor.php. The manipulation of the argument donor_id leads to …
- CVE-2025-20337CRITICALCVSS 10.0EG 10.0⚠ KEV2025-07-16
A vulnerability in a specific API of Cisco ISE and Cisco ISE-PIC could allow an unauthenticated, remote attacker to execute arbitrary code on the underlying operating system as root. The attacker does not require any valid credentials to e…
- CVE-2025-2034HIGHCVSS 7.3EG 7.32025-03-06
A vulnerability has been found in PHPGurukul Pre-School Enrollment System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php?cid=1. The manipulation of the argument …
- CVE-2025-2036MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability was found in s-a-zhd Ecommerce-Website-using-PHP 1.0. It has been classified as critical. This affects an unknown part of the file details.php. The manipulation of the argument pro_id leads to sql injection. It is possible …
- CVE-2025-2037MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_dashboard/delete_requester.php. The manipulation of the argument reque…
- CVE-2025-2039MEDIUMCVSS 4.7EG 4.72025-03-06
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. Affected is an unknown function of the file /admin/delete_members.php. The manipulation of the argument member_id leads to sql injecti…
- CVE-2025-2041MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability, which was classified as critical, has been found in s-a-zhd Ecommerce-Website-using-PHP 1.0. Affected by this issue is some unknown functionality of the file /shop.php. The manipulation of the argument p_cat leads to sql i…
- CVE-2025-2044MEDIUMCVSS 4.7EG 4.72025-03-06
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/delete_bloodGroup.php. The manipulation of the arg…
- CVE-2025-2046MEDIUMCVSS 6.3EG 6.32025-03-06
A vulnerability was found in SourceCodester Best Employee Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/print1.php. The manipulation of the argument id leads to sq…
- CVE-2025-2050HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability classified as critical was found in PHPGurukul User Registration & Login and User Management System 3.3. Affected by this vulnerability is an unknown functionality of the file /login.php. The manipulation of the argument em…
- CVE-2025-2051MEDIUMCVSS 6.3EG 6.32025-03-07
A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /search-visitor.php. The manipulation of the argument searchdata leads to…
- CVE-2025-2052MEDIUMCVSS 6.3EG 6.32025-03-07
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /forgot-password.php. The manipulation of the argument contactno leads to s…
- CVE-2025-2053MEDIUMCVSS 6.3EG 6.32025-03-07
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /visitor-detail.php. The manipulation of the argument editid leads to sql inj…
- CVE-2025-2054MEDIUMCVSS 4.7EG 4.72025-03-07
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit_state.php. The manipulation of the argument s…
- CVE-2025-2057HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability, which was classified as critical, was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. Affected is an unknown function of the file /admin/about-us.php. The manipulation of the argument pagedes leads to sql inject…
- CVE-2025-2058HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability has been found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/search.php. The manipulation of the argument searc…
- CVE-2025-2059HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/booking-details.php. The manipulation of the argument ambulan…
- CVE-2025-2060HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability was found in PHPGurukul Emergency Ambulance Hiring Portal 1.0. It has been classified as critical. This affects an unknown part of the file /admin/admin-profile.php. The manipulation of the argument contactnumber leads to s…
- CVE-2025-2062HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability classified as critical has been found in projectworlds Life Insurance Management System 1.0. Affected is an unknown function of the file /clientStatus.php. The manipulation of the argument client_id leads to sql injection. …
- CVE-2025-2063HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability classified as critical was found in projectworlds Life Insurance Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /deleteNominee.php. The manipulation of the argument nominee_id …
- CVE-2025-2064HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability, which was classified as critical, has been found in projectworlds Life Insurance Management System 1.0. Affected by this issue is some unknown functionality of the file /deletePayment.php. The manipulation of the argument …
- CVE-2025-2065HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability, which was classified as critical, was found in projectworlds Life Insurance Management System 1.0. This affects an unknown part of the file /editAgent.php. The manipulation of the argument agent_id leads to sql injection. …
- CVE-2025-2066HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability has been found in projectworlds Life Insurance Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /updateAgent.php. The manipulation of the argument agent_id leads to sql i…
- CVE-2025-2067HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability was found in projectworlds Life Insurance Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /search.php. The manipulation of the argument key leads to sql injection. Th…
- CVE-2025-2088HIGHCVSS 7.3EG 7.32025-03-07
A vulnerability, which was classified as critical, was found in PHPGurukul Pre-School Enrollment System up to 1.0. Affected is an unknown function of the file /admin/profile.php. The manipulation of the argument fullname/emailid/mobileNumb…
- CVE-2025-2112MEDIUMCVSS 6.3EG 6.32025-03-08
A vulnerability was found in user-xiangpeng yaoqishan up to a47fec4a31cbd13698c592dfdc938c8824dd25e4. It has been declared as critical. Affected by this vulnerability is the function getMediaLisByFilter of the file cn/javaex/yaoqishan/serv…
- CVE-2025-2113HIGHCVSS 7.3EG 7.32025-03-09
A vulnerability was found in AT Software Solutions ATSVD up to 3.4.1. It has been rated as critical. Affected by this issue is some unknown functionality of the component Esqueceu a senha. The manipulation of the argument txtCPF leads to s…
- CVE-2025-2117MEDIUMCVSS 6.3EG 6.32025-03-09
A vulnerability was found in Beijing Founder Electronics Founder Enjoys All-Media Acquisition and Editing System 3.0 and classified as critical. Affected by this issue is the function electricDocList of the file /newsedit/report/reportCent…
- CVE-2025-2118HIGHCVSS 7.3EG 7.32025-03-09
A vulnerability was found in Quantico Tecnologia PRMV 6.48. It has been classified as critical. This affects an unknown part of the file /admin/login.php of the component Login Endpoint. The manipulation of the argument username leads to s…
- CVE-2025-2126MEDIUMCVSS 6.3EG 6.32025-03-09
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla and classified as critical. This issue affects some unknown processing of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties of the com…
- CVE-2025-2132MEDIUMCVSS 4.7EG 4.72025-03-09
A vulnerability classified as critical has been found in ftcms 2.1. Affected is an unknown function of the file /admin/index.php/web/ajax_all_lists of the component Search. The manipulation of the argument name leads to sql injection. It i…
- CVE-2025-2217MEDIUMCVSS 6.3EG 6.32025-03-12
A vulnerability, which was classified as critical, was found in zzskzy Warehouse Refinement Management System 1.3. This affects the function ProcessRequest of the file /getAdyData.ashx. The manipulation of the argument showid leads to sql …
- CVE-2025-22978CRITICALCVSS 9.8EG 9.82025-02-03
eladmin <=2.7 is vulnerable to CSV Injection in the exception log download module.
- CVE-2025-2351HIGHCVSS 7.3EG 7.32025-03-16
A vulnerability classified as critical was found in DayCloud StudentManage 1.0. This vulnerability affects unknown code of the file /admin/adminScoreUrl of the component Login Endpoint. The manipulation of the argument query leads to sql i…
- CVE-2025-2353HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability, which was classified as critical, was found in VAM Virtual Airlines Manager up to 2.6.2. Affected is an unknown function of the file /vam/index.php of the component HTTP GET Parameter Handler. The manipulation of the argum…
- CVE-2025-2358MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability was found in Shenzhen Mingyuan Cloud Technology Mingyuan Real Estate ERP System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /Kfxt/Service.asmx of the component HTTP Header Hand…
- CVE-2025-2362HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in PHPGurukul Pre-School Enrollment System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin/contact-us.php. The manipulation of the argument mobnum leads to sql inj…
- CVE-2025-2372HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This affects an unknown part of the file /password-recovery.php of the component Password Recovery Page. The manipulat…
- CVE-2025-2373MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability classified as critical was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This vulnerability affects unknown code of the file /check_availability.php. The manipulation of the argument mobnumber/emp…
- CVE-2025-2374MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability, which was classified as critical, has been found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. This issue affects some unknown processing of the file /profile.php. The manipulation of the argument aid/…
- CVE-2025-2378HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in PHPGurukul Medical Card Generation System 1.0. It has been classified as critical. This affects an unknown part of the file /download-medical-cards.php. The manipulation of the argument searchdata leads to sql …
- CVE-2025-2379HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /create-pass.php. The manipulation of the argument visname leads to sql…
- CVE-2025-2380HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in PHPGurukul Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /admin-profile.php. The manipulation of the argument mobilenumber leads…
- CVE-2025-2381HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical has been found in PHPGurukul Curfew e-Pass Management System 1.0. Affected is an unknown function of the file /admin/search-pass.php. The manipulation of the argument searchdata leads to sql injection…
- CVE-2025-2382HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical was found in PHPGurukul Online Banquet Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/booking-search.php. The manipulation of the argument searchdata…
- CVE-2025-2383HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability, which was classified as critical, has been found in PHPGurukul Doctor Appointment Management System 1.0. Affected by this issue is some unknown functionality of the file /doctor/search.php. The manipulation of the argument…
- CVE-2025-2384MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability, which was classified as critical, was found in code-projects Real Estate Property Management System 1.0. This affects an unknown part of the file /InsertCustomer.php of the component Parameter Handler. The manipulation of …
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →