CWE-74: Injection
The product constructs all or part of a command, data structure, or record using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify how it is parsed or interpreted when it is sent to a downstream component.
4,530 tracked CVEs are classified under this weakness.
Highest-risk vulnerabilities
- CVE-2026-22200 — osTicket (1.18.x < 1.18.3, 1.17.x < 1.17.7) PDF Export Arbitrary File Read
- CVE-2025-20281 — Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
- CVE-2024-22319 — IBM Operational Decision Manager JDNI injection
- CVE-2025-20337 — Cisco ISE API Unauthenticated Remote Code Execution Vulnerability
- CVE-2024-49380 — Plenti arbitrary file write vulnerability
- CVE-2024-10697 — Tenda AC6 API Endpoint WriteFacMac formWriteFacMac command injection
- CVE-2026-4164 — Wavlink WL-WN578W2 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-4163 — Wavlink WL-WN579A3 POST Request wireless.cgi GuestWifi command injection
- CVE-2026-25586 — SandboxJS has a Sandbox Escape via Prototype Whitelist Bypass and Host Prototype Pollution
- CVE-2026-25520 — SandboxJS has a Sandbox Escape
- CVE-2025-20265 — Cisco Secure Firewall Management Center Software Radius Remote Code Execution Vulnerability
- CVE-2025-14707 — Shiguangwu sgwbox N3 DOCKER Feature http_eshell_server command injection
- CVE-2025-14706 — Shiguangwu sgwbox N3 NETREBOOT http_eshell_server command injection
- CVE-2025-14705 — Shiguangwu sgwbox N3 SHARESERVER Feature command injection
- CVE-2024-46986 — Arbitrary file write leading to RCE in Camaleon CMS
- CVE-2024-42489 — Pro Macros Remote Code Execution via Viewpdf and similar macros
- CVE-2024-42472 — Flatpak may allow access to files outside sandbox for certain apps
- CVE-2024-38366 — CoacoaPods trunk RCE in email verification system rfc-822
- CVE-2025-6095 — codesiddhant Jasmin Ransomware checklogin.php sql injection
- CVE-2026-34041 — act: Unrestricted set-env and add-path command processing enables environment injection
Recently published
- CVE-2026-87572 — Injection in DevTools in Google Chrome prior to 153.0.8010.36 allowed a remote attacker who had compromised the renderer
- CVE-2026-86675 — itsourcecode Sales and Inventory System us_edit.php sql injection
- CVE-2026-86667 — aircheng-org iWebShop-5 member.php member_list sql injection
- CVE-2026-86518 — code-projects Student Crud Operation edit.php sql injection
- CVE-2026-86517 — itsourcecode Sales and Inventory System us_searchfrm.php mysqli_query sql injection
- CVE-2026-86310 — itsourcecode Sales and Inventory System cust_edit1.php sql injection
- CVE-2026-86309 — itsourcecode Sales and Inventory System pro_searchfrm.php sql injection
- CVE-2026-86298 — SourceCodester Class and Exam Timetabling System delete_subject.php sql injection
- CVE-2026-86295 — D-Link DIR-895L udhcpcd serverpacket.c sendACK command injection
- CVE-2026-86291 — itsourcecode Sales and Inventory System us_edit1.php sql injection
- CVE-2026-86290 — SourceCodester Online Voting System ajax.php save_category sql injection
- CVE-2026-86282 — jaychouchannel Tourism-Management-System CommonDao CommonController.java sql injection
- CVE-2026-79698 — Advantech WISE-6610-NB Node-RED nodered_lib_apply command injection
- CVE-2026-79697 — Advantech WISE-6610-NB Basic Station Certificate-Deletion basicstation_apply command injection
- CVE-2026-86270 — itsourcecode Sales and Inventory System settings_edit.php sql injection
- CVE-2026-86269 — itsourcecode Sales and Inventory System emp_edit1.php sql injection
- CVE-2026-86268 — itsourcecode School Management System User_Login.php sql injection
- CVE-2026-86267 — itsourcecode Information System Society Membership System check_student.php sql injection
- CVE-2026-86265 — itsourcecode Sales and Inventory System us_transac.php sql injection
- CVE-2026-86245 — itsourcecode Sales and Inventory System sup_transac.php sql injection
More specific weaknesses
- CWE-1236 — Improper Neutralization of Formula Elements in a CSV File
- CWE-75 — Special Element Injection
- CWE-77 — Command Injection
- CWE-79 — Cross-site Scripting
- CWE-91 — aka Blind XPath Injection
- CWE-93 — CRLF Injection
- CWE-94 — Code Injection
- CWE-943 — Improper Neutralization of Special Elements in Data Query Logic
- CWE-99 — Resource Injection