CWE-74— Improper Neutralization of Special Elements in Output Used by a Downstream Component (Injection)
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.— MITRE CWE catalog
5,223 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-74page 54 of 105
- CVE-2025-3039MEDIUMCVSS 6.3EG 6.32025-03-31
A vulnerability was found in code-projects Payroll Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /add_employee.php. The manipulation of the argument lname/fname leads to sql injectio…
- CVE-2025-3045MEDIUMCVSS 6.3EG 6.32025-04-01
A vulnerability, which was classified as critical, was found in oretnom23/SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /remove-apartment.php. The manipulation of the argument ID leads …
- CVE-2025-30664MEDIUMCVSS 6.6EG 6.62025-05-14
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via local access.
- CVE-2025-3118MEDIUMCVSS 6.3EG 6.32025-04-02
A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been classified as critical. This affects an unknown part of the file /tutor/courses/view_course.php. The manipulation of the argument ID leads to sql injection. I…
- CVE-2025-3119MEDIUMCVSS 6.3EG 6.32025-04-02
A vulnerability was found in SourceCodester Online Tutor Portal 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /tutor/courses/manage_course.php. The manipulation of the argument ID leads to sql i…
- CVE-2025-3120MEDIUMCVSS 6.3EG 6.32025-04-02
A vulnerability was found in SourceCodester Apartment Visitors Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument apartmentno le…
- CVE-2025-3134MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability classified as critical has been found in code-projects Payroll Management System 1.0. This affects an unknown part of the file /add_overtime.php. The manipulation of the argument rate leads to sql injection. It is possible …
- CVE-2025-3135MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability classified as critical was found in fcba_zzm ics-park Smart Park Management System 2.1. This vulnerability affects unknown code of the file /api/system/dept/update. The manipulation leads to sql injection. The attack can be…
- CVE-2025-3137HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, was found in PHPGurukul Online Security Guards Hiring System 1.0. Affected is an unknown function of the file /admin/changeimage.php. The manipulation of the argument editid leads to sql i…
- CVE-2025-3138HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability has been found in PHPGurukul Online Security Guards Hiring System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-guard-detail.php. The manipulation of the …
- CVE-2025-3140MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been classified as critical. This affects an unknown part of the file /view_category.php. The manipulation of the argument ID leads to sql injection. I…
- CVE-2025-3141MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability was found in SourceCodester Online Medicine Ordering System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /manage_category.php. The manipulation of the argument ID leads to sql i…
- CVE-2025-3142MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability was found in SourceCodester Apartment Visitor Management System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /add-apartment.php. The manipulation of the argument buildingno lead…
- CVE-2025-3143MEDIUMCVSS 6.3EG 6.32025-04-03
A vulnerability classified as critical has been found in SourceCodester Apartment Visitor Management System 1.0. Affected is an unknown function of the file /visitor-entry.php. The manipulation of the argument visname/address leads to sql …
- CVE-2025-3146HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, was found in PHPGurukul Bus Pass Management System 1.0. This affects an unknown part of the file /view-pass-detail.php. The manipulation of the argument viewid leads to sql injection. It i…
- CVE-2025-3147HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability has been found in PHPGurukul Boat Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /add-subadmin.php. The manipulation of the argument sadminusername leads to sql injection.…
- CVE-2025-3151HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in SourceCodester Gym Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /signup.php. The manipulation of the argument user_name leads to sql inj…
- CVE-2025-3163MEDIUMCVSS 5.3EG 5.32025-04-03
A vulnerability was found in InternLM LMDeploy up to 0.7.1. It has been declared as critical. Affected by this vulnerability is the function Open of the file lmdeploy/docs/en/conf.py. The manipulation leads to code injection. It is possibl…
- CVE-2025-3164MEDIUMCVSS 4.7EG 4.72025-04-03
A vulnerability was found in Tencent Music Entertainment SuperSonic up to 0.9.8. It has been rated as critical. Affected by this issue is some unknown functionality of the file /api/semantic/database/testConnect of the component H2 Databas…
- CVE-2025-3168HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in PHPGurukul Time Table Generator System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/edit-class.php. The manipulation of the argument editi…
- CVE-2025-3170HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability classified as critical has been found in Project Worlds Online Lawyer Management System 1.0. This affects an unknown part of the file /admin_user.php. The manipulation of the argument block_id/unblock_id leads to sql inject…
- CVE-2025-3171HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability classified as critical was found in Project Worlds Online Lawyer Management System 1.0. This vulnerability affects unknown code of the file /approve_lawyer.php. The manipulation of the argument unblock_id leads to sql injec…
- CVE-2025-3172HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, has been found in Project Worlds Online Lawyer Management System 1.0. This issue affects some unknown processing of the file /lawyer_booking.php. The manipulation of the argument unblock_i…
- CVE-2025-3173HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, was found in Project Worlds Online Lawyer Management System 1.0. Affected is an unknown function of the file /save_booking.php. The manipulation of the argument lawyer_id/description leads…
- CVE-2025-3174HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability has been found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this vulnerability is an unknown functionality of the file /searchLawyer.php. The manipulation of the argument exp…
- CVE-2025-3175HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in Project Worlds Online Lawyer Management System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /save_user_edit_profile.php. The manipulation of the argument firs…
- CVE-2025-3176HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in Project Worlds Online Lawyer Management System 1.0. It has been classified as critical. This affects an unknown part of the file /single_lawyer.php. The manipulation of the argument u_id leads to sql injection.…
- CVE-2025-3178HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been rated as critical. This issue affects some unknown processing of the file /doctor/deleteappointment.php. The manipulation of the argument …
- CVE-2025-3179HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability classified as critical has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected is an unknown function of the file /doctor/deletepatient.php. The manipulation of the argument ic leads to sql in…
- CVE-2025-3180HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability classified as critical was found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /doctor/deleteschedule.php. The manipulation of the argu…
- CVE-2025-3181HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, has been found in projectworlds Online Doctor Appointment Booking System 1.0. Affected by this issue is some unknown functionality of the file /patient/appointment.php?scheduleDate=1&appid…
- CVE-2025-3182HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability, which was classified as critical, was found in projectworlds Online Doctor Appointment Booking System 1.0. This affects an unknown part of the file /patient/getschedule.php. The manipulation of the argument q leads to sql …
- CVE-2025-3183HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability has been found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This vulnerability affects unknown code of the file /patient/patientupdateprofile.php. The manipulation of the argumen…
- CVE-2025-3184HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0 and classified as critical. This issue affects some unknown processing of the file /patient/profile.php?patientId=1. The manipulation of the argument p…
- CVE-2025-3185HIGHCVSS 7.3EG 7.32025-04-03
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been classified as critical. Affected is an unknown function of the file /patient/patientupdateprofile.php. The manipulation of the argument pa…
- CVE-2025-3186HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in projectworlds Online Doctor Appointment Booking System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /patient/invoice.php. The manipulation of the…
- CVE-2025-3187HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument logindetail leads to sql in…
- CVE-2025-3188HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical has been found in PHPGurukul e-Diary Management System 1.0. This affects an unknown part of the file /add-notes.php. The manipulation of the argument Category leads to sql injection. It is possible to…
- CVE-2025-3195HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability, which was classified as critical, has been found in itsourcecode Online Blood Bank Management System 1.0. This issue affects some unknown processing of the file /bbms.php. The manipulation of the argument Search leads to s…
- CVE-2025-3204MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability, which was classified as critical, has been found in CodeAstro Car Rental System 1.0. Affected by this issue is some unknown functionality of the file /returncar.php. The manipulation of the argument ID leads to sql injecti…
- CVE-2025-3205MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability, which was classified as critical, was found in CodeAstro Student Grading System 1.0. This affects an unknown part of the file studentsubject.php. The manipulation of the argument studentId leads to sql injection. It is pos…
- CVE-2025-3206MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability has been found in code-projects Hospital Management System 1.0 and classified as critical. This vulnerability affects unknown code of the file /admin/doctor-specilization.php. The manipulation of the argument doctorspeciliz…
- CVE-2025-3207MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in code-projects Patient Record Management System 1.0 and classified as critical. This issue affects some unknown processing of the file /birthing_form.php. The manipulation of the argument birth_id leads to sql i…
- CVE-2025-3208MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been classified as critical. Affected is an unknown function of the file /xray_print.php. The manipulation of the argument itr_no leads to sql injectio…
- CVE-2025-3209MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /add_patient.php. The manipulation of the argument it…
- CVE-2025-3210MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in code-projects Patient Record Management System 1.0. It has been rated as critical. Affected by this issue is some unknown functionality of the file /birthing_pending.php. The manipulation of the argument birth_…
- CVE-2025-3211MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability classified as critical has been found in code-projects Patient Record Management System 1.0. This affects an unknown part of the file /birthing_print.php. The manipulation of the argument itr_no/birth_id leads to sql inject…
- CVE-2025-3213HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability classified as critical was found in PHPGurukul e-Diary Management System 1.0. This vulnerability affects unknown code of the file /view-note.php?noteid=11. The manipulation of the argument remark leads to sql injection. The…
- CVE-2025-3215MEDIUMCVSS 6.3EG 6.32025-04-04
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as critical. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname lea…
- CVE-2025-3216HIGHCVSS 7.3EG 7.32025-04-04
A vulnerability was found in PHPGurukul e-Diary Management System 1.0. It has been classified as critical. This affects an unknown part of the file /password-recovery.php. The manipulation of the argument username/contactno leads to sql in…
Map vulnerabilities like CWE-74 to your infrastructure
EchelonGraph correlates every CVE — across CWE-74 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →