CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,184 vulnerabilities with CWE-94
CVE-2026-7110
LOW
code-projects Invoice System in Laravel item cross site scripting
CVSS 3.5
CVE-2026-7095
MEDIUM
code-projects Employee Management System edit.php cross site scripting
CVSS 4.3
CVE-2026-7090
LOW
code-projects Chat System send_message.php cross site scripting
CVSS 2.4
CVE-2026-7089
MEDIUM
code-projects Home Service System Appointment Booking booking.php cross site scripting
CVSS 4.3
CVE-2026-7027
LOW
D-Link DSL-2740R Wireless Setup Section cross site scripting
CVSS 2.4
CVE-2026-7026
MEDIUM
D-Link DGS-3420 System Information Settings cross site scripting
CVSS 4.5
CVE-2026-7016
LOW
MaxSite CMS ushki Plugin cross site scripting
CVSS 2.4
CVE-2026-7015
LOW
MaxSite CMS Guestbook Plugin cross site scripting
CVSS 2.4
CVE-2026-7014
LOW
MaxSite CMS down_count Plugin cross site scripting
CVSS 2.4
CVE-2026-7013
LOW
MaxSite CMS mail_send Plugin cross site scripting
CVSS 2.4
CVE-2026-7012
LOW
MaxSite CMS Redirect Plugin cross site scripting
CVSS 2.4
CVE-2026-7011
LOW
MaxSite CMS Antispam Plugin plugin_antispam cross site scripting
CVSS 2.4
CVE-2026-7001
LOW
Datacom DM4100 Ethernet Configuration cross site scripting
CVSS 2.4
CVE-2026-7000
LOW
Datacom DM4100 VLAN Page cross site scripting
CVSS 2.4
CVE-2026-6999
LOW
BIVOCOM TR321 Wireless Setting cross site scripting
CVSS 2.4
CVE-2026-6998
LOW
BDCOM P3310D New RMON Statistics cross site scripting
CVSS 2.4
CVE-2026-6997
LOW
BDCOM P3310D New RMON History cross site scripting
CVSS 2.4
CVE-2026-6996
LOW
BDCOM P3310D rmon event Tab cross site scripting
CVSS 2.4
CVE-2026-6995
LOW
BDCOM P3310D New User index.asp cross site scripting
CVSS 2.4
CVE-2026-6990
LOW
projeto-siga novo cross site scripting
CVSS 3.5
CVE-2026-6951
CRITICAL
Simple-git < 3.36.0 - Remote Code Execution
CVSS 9.8
CVE-2026-41414
HIGH
Skim: Arbitrary code execution via pull_request_target fork checkout in pr.yml
CVSS 7.4
CVE-2026-41044
HIGH
Apache ActiveMQ, Apache ActiveMQ Broker, Apache ActiveMQ All: Authenticated user can perform RCE via DestinationView MBean exposed by Jolokia
CVSS 8.8
CVE-2026-40466
HIGH
Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ: Possible bypass of CVE-2026-34197 via HTTP discovery second-stage URI
CVSS 8.8
CVE-2026-41138
HIGH
Flowise: Remote code execution vulnerability in AirtableAgent.ts caused by lack of input verification when using Pandas.
CVSS 8.8
Details
Vulnerabilities
6,184
Exploit Likelihood
Medium