CWE-74
CVEs classified under CWE-74, newest first.
437 CVEsRSS
CVE-2026-54661High· 8.3swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
swagger-typescript-api vulnerable to code injection via unescaped `servers[0].url` in axios http-client template
CVE-2026-54664High· 8.3swagger-typescript-api vulnerable to code injection via unescaped enum string values
swagger-typescript-api vulnerable to code injection via unescaped enum string values
CVE-2026-54666High· 8.3swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
swagger-typescript-api vulnerable to code injection via unescaped OpenAPI path strings in generated method bodies
CVE-2026-55404High· 7.5yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
yt-dlp: Downstream command injection via improper sanitization of yt-dlp --write-link output
GHSA-3rp5-jjmw-4wv2High· 7.0GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
GitPython: git-config section-name injection enables arbitrary config directives (core.sshCommand RCE)
CVE-2026-16228High· 7.3A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was detected in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_schoolyr.php. Performing a manipulation of the argument ID results in sql injection. It is possible t…
CVE-2026-16227High· 7.3A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0
A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This impacts an unknown function of the file /edit_subject.php. Such manipulation of the argument ID leads to sql injection. The attack m…
CVE-2026-16204Medium· 6.3A security flaw has been discovered in zevorn rt-claw up to 0.2.0
A security flaw has been discovered in zevorn rt-claw up to 0.2.0. This affects the function tool_run_script_execute of the file claw/services/tools/script.c of the component Telegram-to-AI Tool Execution Flow. Performing a manipulation …
CVE-2026-16154High· 7.3A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_room1.php. Executing a manipulation of the argument ID can lead to…
CVE-2026-16152High· 7.3A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /edit_rooma.php. Performing a manipulation of the argument ID results in sql injection. The attack is possible…
CVE-2026-16133Medium· 5.0A flaw has been found in LiuMengxuan04 MiniCode 0.1.0
A flaw has been found in LiuMengxuan04 MiniCode 0.1.0. Affected by this vulnerability is the function child_process.spawn of the file mcp.ts. Executing a manipulation can lead to command injection. The attack can be launched remotely. Th…
CVE-2026-16131Medium· 6.3A weakness has been identified in itsourcecode Hospital Management System 1.0
A weakness has been identified in itsourcecode Hospital Management System 1.0. This affects an unknown function of the file /prescriptionrecord.php. This manipulation of the argument delid causes sql injection. It is possible to initiate…
GHSA-rjwr-m7qx-3fjrLowoapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
oapi-codegen: OpenAPI Server Description Escapes Generated Go Comment and Injects Executable Code
GHSA-vwjc-v7x7-cm6gHighArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
ArcadeDB: Scripting authorization gate (GHSA-48qw-824m-86pr) bypassed via SQL DEFINE FUNCTION ... LANGUAGE js
GHSA-pqg7-v6wh-3pfpHigh· 8.5TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
TsDProxy: X-Forwarded-For header injection allows IP spoofing in proxied requests to backend services
CVE-2026-15537High· 7.3A security flaw has been discovered in SourceCodester Online Book Store System 1.0
A security flaw has been discovered in SourceCodester Online Book Store System 1.0. This vulnerability affects unknown code of the file admin/login.php. The manipulation of the argument Username results in sql injection. The attack can b…
CVE-2026-15536Medium· 6.3A vulnerability was identified in itsourcecode Hospital Management System 1.0
A vulnerability was identified in itsourcecode Hospital Management System 1.0. This affects an unknown part of the file /patviewprescription.php. The manipulation of the argument delid leads to sql injection. Remote exploitation of the a…
CVE-2026-15533Medium· 4.7A security flaw has been discovered in DedeCMS 5.7.118
A security flaw has been discovered in DedeCMS 5.7.118. Impacted is an unknown function of the file /plus/search.php of the component Column Management. Performing a manipulation of the argument Column Name results in code injection. The…
CVE-2026-15523Medium· 6.3A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0
A weakness has been identified in CodeAstro Simple Online Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /SimpleOnlineLeave/admin/dashboard.php. This manipulation of the argument Name causes…
CVE-2026-15517High· 7.3A flaw has been found in Jinher OA 1.0
A flaw has been found in Jinher OA 1.0. The affected element is an unknown function of the file /C6/JHSoft.Web.PlanSummarize/PlanGiveOut.aspx. This manipulation of the argument httpOID causes sql injection. Remote exploitation of the att…
CVE-2026-15514High· 7.3A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06
A weakness has been identified in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This vulnerability affects the function RPCService.query of the file /customizemt/xkq/rpc.jsp of the component PHPRPC Remote Call Interface. Executing a manipula…
CVE-2026-15512Medium· 6.3A vulnerability was identified in pig-mesh Pig up to 3.9.2
A vulnerability was identified in pig-mesh Pig up to 3.9.2. Affected by this issue is some unknown functionality of the file \pig-master\pig-visual\pig-codegen\src\main\java\com\pig4cloud\pig\codegen\service\impl\GeneratorServiceImpl.jav…
CVE-2026-15502Medium· 6.3PoCA vulnerability was detected in AojiaoZero Antaris 1.0
A vulnerability was detected in AojiaoZero Antaris 1.0. This affects the function _rewardPurchase of the file /ipn.php of the component PayPal IPN Payment Handler. The manipulation of the argument item_number results in sql injection. Th…
CVE-2026-15498High· 7.3A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c
A vulnerability was identified in sergomanov SmartHomeAdatum up to cf495353d81b680675eb8d9aa14a318aa45ce12c. This impacts an unknown function of the file users.php of the component Login. Such manipulation of the argument Login leads to …
CVE-2026-15497High· 7.3A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2
A vulnerability was determined in SonicCloudOrg sonic-agent up to 2.7.2. This affects an unknown function of the file sonic-server-controller/src/main/java/org/cloud/sonic/controller/controller/ExchangeController.java of the component JW…
CVE-2026-15494Medium· 4.7A flaw has been found in AMTT Hotel Broadband Operation System 1.0
A flaw has been found in AMTT Hotel Broadband Operation System 1.0. Impacted is an unknown function of the file manager/network/switch_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to l…
CVE-2026-15490High· 7.3A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
A security flaw has been discovered in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this issue is some unknown functionality of the file proses/add.php. The manipulation of the argument kode_produk…
CVE-2026-15489High· 7.3A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99
A vulnerability was identified in RafyMrX TOKO-ONLINE-ROTI up to ddfe1cd587be0a0b5135d8b6e85cce2ec3aece99. Affected by this vulnerability is an unknown functionality of the file proses/login.php. The manipulation of the argument Username…
CVE-2026-15482High· 7.3A weakness has been identified in Aster Telecom Azcall 10/11
A weakness has been identified in Aster Telecom Azcall 10/11. This issue affects some unknown processing of the file /azcall/adm/gestao_loja/sis.php?t=consultar of the component HTTP Handler. Executing a manipulation of the argument nome…
CVE-2026-15481High· 8.8A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03
A security flaw has been discovered in Trendnet TEW-635BRM up to 1.00.03. This vulnerability affects the function ipoa_test of the file /sbin/rc of the component IPoA WAN Connection Setup. Performing a manipulation of the argument ipoa_i…