CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,477 vulnerabilities with CWE-94
CVE-2025-13450
LOW
SourceCodester Online Shop Project 1.0 - Cross-Site Scripting via f_name Parameter
CVSS 3.5
CVE-2025-13415
LOW
easyimages2.0 < 2.8.6 - Cross-Site Scripting via SVG Image Handler File Parameter
CVSS 3.5
CVE-2025-13412
LOW
Campcodes Retro Basketball Shoes Online Store 1.0 - Cross-Site Scripting via product_name Argument
CVSS 2.4
CVE-2025-65099
CRITICAL
Claude Code < 1.0.39 - Unauthenticated Code Execution via Yarn Plugin
CVSS 9.8
CVE-2025-65026
MEDIUM
esm.sh < 136 - Remote Code Execution via CSS Module Conversion Template Literal Injection
CVSS 6.1
CVE-2025-10703
HIGH
Progress DataDirect - Code Injection
CVE-2025-10702
HIGH
Progress DataDirect - Code Injection
CVE-2025-13035
HIGH
WordPress Code Snippets <3.9.1 - Code Injection
CVSS 8.0
CVE-2025-63693
MEDIUM
DzzOffice < 2.3.7 - Stored Cross-Site Scripting in Comment Editing Template
CVSS 5.4
CVE-2025-37157
MEDIUM
ArubaOS-CX 10.10.0000-10.10.1169 - Authenticated Remote Code Execution via Command Injection
CVSS 6.7
CVE-2025-33184
HIGH
NVIDIA Isaac-GR00T - Code Injection
CVSS 7.8
CVE-2025-33183
HIGH
NVIDIA Isaac-GR00T - Code Injection
CVSS 7.8
CVE-2025-13349
LOW
SourceCodester Student Grades Management System 1.0 - Stored Cross-Site Scripting in Grades.php Remarks Field
CVSS 3.5
CVE-2025-13343
LOW
SourceCodester Interview Management System 1.0 - Cross-Site Scripting via Question Parameter in editQuestion.php
CVSS 3.5
CVE-2025-7711
MEDIUM
The Classified Listing - Classified ads & Business Directory Plugin...
CVSS 5.4
CVE-2025-13245
LOW
Student Information System 2.0 - Cross-Site Scripting in /editprofile.php
CVSS 3.5
CVE-2025-13244
MEDIUM
Student Information System 2.0 - Cross-Site Scripting in /register.php
CVSS 4.3
CVE-2025-13232
LOW
ProjectSend < r1720 - Cross-Site Scripting in File Editor/Custom Download Aliases
CVSS 3.5
CVE-2025-13202
LOW
Simple Cafe Ordering System 1.0 - Cross-Site Scripting via product_name Parameter
CVSS 3.5
CVE-2025-13186
LOW
bdtask isshue < 4.0 - Cross-Site Scripting via Search Argument in Customer Management
CVSS 2.4
CVE-2025-13182
LOW
h3blog 1.0 - Cross-Site Scripting via Title Parameter in Category Add Function
CVSS 3.5
CVE-2025-13181
LOW
h3blog 1.0 - Cross-Site Scripting via Name Argument in /admin/cms/material/add
CVSS 3.5
CVE-2025-12762
CRITICAL
pgAdmin 4 < 9.10 - Remote Code Execution via PLAIN-format Dump File Restore
CVSS 9.1
CVE-2025-12733
HIGH
WP All Import <3.9.6 - Authenticated RCE
CVSS 8.8
CVE-2025-13058
LOW
extplorer < 2.1.15 - Cross-Site Scripting in Filename Handler
CVSS 3.5
Details
Vulnerabilities
6,477
Exploit Likelihood
Medium