CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,477 vulnerabilities with CWE-94
CVE-2025-46295 CRITICAL
Claris FileMaker Server - Apache Commons Text Interpolation Code Execution
CVSS 9.8
CVE-2025-37164 CRITICAL KEV
HPE OneView unauthenticated RCE
CVSS 10.0
CVE-2025-67748 HIGH
fickling < 0.1.6 - Unsafe Pickle Misclassification via pty Module Import Bypass
CVSS 7.8
CVE-2025-67744 CRITICAL
deepchat < 0.5.3 - Remote Code Execution via Mermaid Diagram Rendering
CVSS 9.6
CVE-2025-14730 MEDIUM
CTCMS < 2.1.2 - Remote Code Injection via Cj_Add/Cj_Edit Argument
CVSS 4.7
CVE-2025-14729 MEDIUM
CTCMS < 2.1.2 - Remote Code Execution via CT_App_Paytype Argument
CVSS 4.7
CVE-2025-14722 LOW
vion707 DMadmin <3403cafdb42537a648c30bf8cbc8148ec60437d1 - XSS
CVSS 2.4
CVE-2025-66438 HIGH
ERPNext < 15.89.0 - Authenticated Server-Side Template Injection via Print Format HTML Field
CVSS 8.8
CVE-2025-66437 HIGH
Frappe ERPNext <= 15.89.0 - Authenticated Server-Side Template Injection via Address Template
CVSS 8.8
CVE-2025-66436 MEDIUM
Frappe ERPNext < 15.89.0 - Authenticated Server-Side Template Injection via get_terms_and_conditions
CVSS 4.3
CVE-2025-66435 MEDIUM
Frappe ERPNext < 15.89.0 - Authenticated Server-Side Template Injection via Contract Template
CVSS 4.3
CVE-2025-66434 HIGH
Frappe ERPNext < 15.89.0 - Authenticated Server-Side Template Injection via get_dunning_letter_text
CVSS 8.8
CVE-2025-14691 MEDIUM
Mayan EDMS < 4.10.2 - Cross-Site Scripting in Authentication Endpoint
CVSS 4.3
CVE-2025-14663 LOW
Student File Management System 1.0 - XSS
CVSS 2.4
CVE-2025-14662 LOW
Code-projects Student File Management System 1.0 - XSS
CVSS 2.4
CVE-2025-14539 MEDIUM
Shortcode Ajax <= 1.0 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 5.4
CVE-2025-67750 HIGH
lightning-flow-scanner < 6.10.6 - Remote Code Execution via Malicious Flow Metadata
CVSS 8.4
CVE-2025-14580 LOW
Qualitor < 8.20.78 - Cross-Site Scripting via cdscript Parameter
CVSS 3.5
CVE-2025-65854 CRITICAL
MineAdmin v3.x - OS Command Injection via Scheduled Tasks Feature
CVSS 9.8
CVE-2025-12843 MEDIUM
waveterm 0.12.2 - Code Injection via Electron Fuses
CVSS 5.5
CVE-2025-67727 CRITICAL
parse-server < 8.6.0-alpha.2 - Improper Privilege Management in GitHub CI Workflow
CVSS 9.8
CVE-2025-14166 MEDIUM
WPMasterToolKit <2.13.0 - Code Injection
CVSS 5.3
CVE-2025-14538 LOW
yangshare warehouseManager 1.1.0 - XSS
CVSS 3.5
CVE-2025-13780 CRITICAL
pgAdmin < 9.10 - Remote Code Execution via PLAIN-Format Dump File Restore
CVSS 9.1
CVE-2025-55313 HIGH
Foxit PDF & Editor <13.2,2025.2 - RCE
CVSS 7.8
Details
Vulnerabilities 6,477
Exploit Likelihood Medium