CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 52 of 105
- CVE-2025-2385HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability has been found in code-projects Modern Bag 1.0 and classified as critical. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument userEmail/userPassword leads to sql injection. The …
- CVE-2025-2386HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in PHPGurukul Local Services Search Engine Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /serviceman-search.php. The manipulation of the argument location…
- CVE-2025-2387HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability was found in SourceCodester Online Food Ordering System 2.0. It has been classified as critical. Affected is an unknown function of the file /admin/ajax.php?action=add_to_cart. The manipulation of the argument pid leads to …
- CVE-2025-2389MEDIUMCVSS 4.7EG 4.72025-03-17
A vulnerability was found in code-projects Blood Bank Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /admin/add_city.php. The manipulation leads to sql injection. The …
- CVE-2025-2390MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability classified as critical has been found in code-projects Blood Bank Management System 1.0. This affects an unknown part of the file /user_dashboard/add_donor.php. The manipulation leads to sql injection. It is possible to ini…
- CVE-2025-2391HIGHCVSS 7.3EG 7.32025-03-17
A vulnerability classified as critical was found in code-projects Blood Bank Management System 1.0. This vulnerability affects unknown code of the file /admin/admin_login.php of the component Admin Login Page. The manipulation leads to sql…
- CVE-2025-2392MEDIUMCVSS 4.7EG 4.72025-03-17
A vulnerability, which was classified as critical, has been found in code-projects Online Class and Exam Scheduling System 1.0. This issue affects some unknown processing of the file /pages/activate.php. The manipulation of the argument id…
- CVE-2025-2393MEDIUMCVSS 4.7EG 4.72025-03-17
A vulnerability, which was classified as critical, was found in code-projects Online Class and Exam Scheduling System 1.0. Affected is an unknown function of the file /pages/salut_del.php. The manipulation of the argument id leads to sql i…
- CVE-2025-2419MEDIUMCVSS 6.3EG 6.32025-03-17
A vulnerability classified as critical has been found in code-projects Real Estate Property Management System 1.0. Affected is an unknown function of the file /InsertFeedback.php. The manipulation of the argument txtName/txtEmail/txtMobile…
- CVE-2025-24291MEDIUMCVSS 6.1EG 6.12025-06-19
The Versa Director SD-WAN orchestration platform provides functionality to upload various types of files. However, the Java code handling file uploads contains an argument injection vulnerability. By appending additional arguments to the f…
- CVE-2025-24364HIGHCVSS 7.2EG 7.22025-01-27
vaultwarden is an unofficial Bitwarden compatible server written in Rust, formerly known as bitwarden_rs. Attacker with authenticated access to the vaultwarden admin panel can execute arbitrary code in the system. The attacker could then c…
- CVE-2025-24374MEDIUMCVSS 4.3EG 4.32025-01-29
Twig is a template language for PHP. When using the ?? operator, output escaping was missing for the expression on the left side of the operator. This vulnerability is fixed in 3.19.0.
- CVE-2025-2471MEDIUMCVSS 6.3EG 6.32025-03-18
A vulnerability, which was classified as critical, was found in PHPGurukul Boat Booking System 1.0. Affected is an unknown function of the file /boat-details.php. The manipulation of the argument bid leads to sql injection. It is possible …
- CVE-2025-2472HIGHCVSS 7.3EG 7.32025-03-18
A vulnerability has been found in PHPGurukul Apartment Visitors Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /index.php of the component Sign In. The manipulation …
- CVE-2025-2473HIGHCVSS 7.3EG 7.32025-03-18
A vulnerability was found in PHPGurukul Company Visitor Management System 2.0 and classified as critical. Affected by this issue is some unknown functionality of the file /index.php of the component Sign In. The manipulation of the argumen…
- CVE-2025-24904HIGHCVSS 8.5EG 8.52025-02-13
libsignal-service-rs is a Rust version of the libsignal-service-java library which implements the core functionality to communicate with Signal servers. Prior to commit 82d70f6720e762898f34ae76b0894b0297d9b2f8, plaintext content envelopes …
- CVE-2025-24962HIGHCVSS 8.8EG 8.82025-02-03
reNgine is an automated reconnaissance framework for web applications. In affected versions a user can inject commands via the nmap_cmd parameters. This issue has been addressed in commit `c28e5c8d` and is expected in the next versioned re…
- CVE-2025-25477HIGHCVSS 8.1EG 8.12025-02-28
A host header injection vulnerability in SysPass 3.2x allows an attacker to load malicious JS files from an arbitrary domain which would be executed in the victim's browser.
- CVE-2025-2587MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability, which was classified as critical, was found in Jinher OA C6 1.0. This affects an unknown part of the file IncentivePlanFulfillAppprove.aspx. The manipulation of the argument httpOID leads to sql injection. It is possible t…
- CVE-2025-2593MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability has been found in FastCMS up to 0.1.5 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /api/client/article/list. The manipulation of the argument orderBy leads to sql inject…
- CVE-2025-2601MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability, which was classified as critical, was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This affects an unknown part of the file activate_reg.php. The manipulation of the argument ID leads to sql i…
- CVE-2025-2602MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability has been found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file deactivate_reg.php. The manipulation of the argument ID lead…
- CVE-2025-2603MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0 and classified as critical. This issue affects some unknown processing of the file deactivate.php. The manipulation of the argument ID leads to s…
- CVE-2025-2604MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. It has been classified as critical. Affected is an unknown function of the file edit_act.php. The manipulation of the argument ID leads to sql i…
- CVE-2025-2608MEDIUMCVSS 6.3EG 6.32025-03-21
A vulnerability classified as critical has been found in PHPGurukul Banquet Booking System 1.2. This affects an unknown part of the file /admin/view-user-queries.php. The manipulation of the argument viewid leads to sql injection. It is po…
- CVE-2025-2624MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability was found in westboy CicadasCMS 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /system/cms/content/save. The manipulation of the argument content/fujian/laiyuan leads to…
- CVE-2025-2625MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability classified as critical has been found in westboy CicadasCMS 1.0. This affects an unknown part of the file /system/cms/content/page. The manipulation of the argument orderField/orderDirection leads to sql injection. It is po…
- CVE-2025-2626MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability classified as critical was found in SourceCodester Kortex Lite Advocate Office Management System 1.0. This vulnerability affects unknown code of the file edit_case.php. The manipulation of the argument ID leads to sql injec…
- CVE-2025-2627MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. This issue affects some unknown processing of the file /admin/contactus.php. The manipulation of the argument pagetitle lead…
- CVE-2025-2628MEDIUMCVSS 6.3EG 6.32025-03-22
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.1. Affected is an unknown function of the file /art-enquiry.php. The manipulation of the argument eid leads to sql injection. It is …
- CVE-2025-2640HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in PHPGurukul Doctor Appointment Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /doctor/appointment-bwdates-reports-details.php. The manipulation of the ar…
- CVE-2025-2641HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability, which was classified as critical, has been found in PHPGurukul Art Gallery Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit-artist-detail.php?editid=1. The manipulation of…
- CVE-2025-2642HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability, which was classified as critical, was found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/edit-art-product-detail.php?editid=2. The manipulation of the argument editide/sp…
- CVE-2025-2643HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability has been found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/edit-art-type-detail.php?editid=1. The manipulation of the argument artty…
- CVE-2025-2644HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /admin/add-art-product.php. The manipulation of the argument arttype leads to sql …
- CVE-2025-2646HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/admin-profile.php. The manipulation of the argument …
- CVE-2025-2647HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /search.php. The manipulation of the argument Search leads to sql in…
- CVE-2025-2648HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability classified as critical has been found in PHPGurukul Art Gallery Management System 1.0. This affects an unknown part of the file /admin/view-enquiry-detail.php. The manipulation of the argument viewid leads to sql injection.…
- CVE-2025-2649HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability classified as critical was found in PHPGurukul Doctor Appointment Management System 1.0. This vulnerability affects unknown code of the file /check-appointment.php. The manipulation of the argument searchdata leads to sql i…
- CVE-2025-2654HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in SourceCodester AC Repair and Services System 1.0. It has been classified as critical. This affects an unknown part of the file /admin/services/manage_service.php. The manipulation of the argument ID leads to sq…
- CVE-2025-2655HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was detected in SourceCodester AC Repair and Services System 1.0. The affected element is the function save_users/delete_users of the file /classes/Users.php. Performing manipulation of the argument ID results in sql inject…
- CVE-2025-2656HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability classified as critical has been found in PHPGurukul Zoo Management System 2.1. Affected is an unknown function of the file /admin/login.php. The manipulation of the argument Username leads to sql injection. It is possible t…
- CVE-2025-2657HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability classified as critical was found in projectworlds Apartment Visitors Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /front.php. The manipulation of the argument rid leads to sq…
- CVE-2025-2658HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability, which was classified as critical, has been found in PHPGurukul Online Security Guards Hiring System 1.0. Affected by this issue is some unknown functionality of the file /search-request.php. The manipulation of the argumen…
- CVE-2025-2659HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability, which was classified as critical, was found in Project Worlds Online Time Table Generator 1.0. This affects an unknown part of the file /student/index.php. The manipulation of the argument e leads to sql injection. It is p…
- CVE-2025-2660HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability has been found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/index.php. The manipulation of the argument e leads to sql injection. T…
- CVE-2025-2661HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability was found in Project Worlds Online Time Table Generator 1.0 and classified as critical. This issue affects some unknown processing of the file /staff/index.php. The manipulation of the argument e leads to sql injection. The…
- CVE-2025-2662MEDIUMCVSS 6.3EG 6.32025-03-23
A vulnerability was found in Project Worlds Online Time Table Generator 1.0. It has been classified as critical. Affected is an unknown function of the file student/studentdashboard.php. The manipulation of the argument course leads to sql…
- CVE-2025-2663HIGHCVSS 7.3EG 7.32025-03-23
A vulnerability has been found in PHPGurukul Bank Locker Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /search-locker-details.php. The manipulation of the argument …
- CVE-2025-2664MEDIUMCVSS 4.7EG 4.72025-03-23
A vulnerability was found in CodeZips Hospital Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /suadpeted.php. The manipulation of the argument ID leads to sql injection. T…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →