CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,492 vulnerabilities with CWE-94
CVE-2025-50123 HIGH
EcoStruxure IT Data Center Expert >=8.3 - Remote Code Execution via Hostname Input
CVE-2025-5392 CRITICAL
GB Forms DB <= 1.0.2 - Unauthenticated Remote Code Execution via gbfdb_talk_to_front()
CVSS 9.8
CVE-2025-7435 LOW
LiveHelperChat lhc-php-resque Extension - Cross-Site Scripting
CVSS 3.5
CVE-2025-53626 MEDIUM
pdfme 5.2.0-5.4.0 - Prototype Pollution and Cross-Site Scripting via Expression Evaluation
CVSS 6.1
CVE-2025-7408 LOW
SourceCodester Zoo Management System 1.0 - XSS
CVSS 3.5
CVE-2025-34077 CRITICAL
WordPress Pie Register <3.7.1.4 - Auth Bypass
CVE-2025-53547 HIGH
Helm <3.18.4 - Local Code Execution
CVSS 8.5
CVE-2025-49704 HIGH KEV
Microsoft SharePoint Server - Remote Code Execution
CVSS 8.8
CVE-2025-47988 HIGH
Azure Monitor Agent < 1.35.1 - Unauthenticated Remote Code Execution
CVSS 7.5
CVE-2025-7182 MEDIUM
Student Transcript Processing System 1.0 - Cross-Site Scripting via edit.php pre Parameter
CVSS 4.3
CVE-2025-6744 HIGH
Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution via woodmart_get_products_shortcode()
CVSS 7.3
CVE-2025-42967 CRITICAL
SAP S/4HANA and SCM Characteristic Propagation - User-Level Report Code Execution
CVSS 9.9
CVE-2025-7153 LOW
CodeAstro Simple Hospital Management System 1.0 - Stored Cross-Site Scripting via Doctor Profile POST Parameters
CVSS 3.5
CVE-2025-7148 LOW
CodeAstro Simple Hospital Management System 1.0 - Stored Cross-Site Scripting via Patient POST Parameter
CVSS 3.5
CVE-2025-7144 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Admin Name Parameter in Admin Profile Page
CVSS 2.4
CVE-2025-7143 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Tax Name Parameter in Update Tax Page
CVSS 2.4
CVE-2025-7142 LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Search Appointment Panel
CVSS 2.4
CVE-2025-7141 LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Update Staff Page
CVSS 2.4
CVE-2025-7140 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Staff Name Parameter in Update Staff Page
CVSS 2.4
CVE-2025-7139 LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Update Customer Details Page Name Parameter
CVSS 2.4
CVE-2025-36014 HIGH
IBM Integration Bus for z/OS 10.1.0.0-10.1.0.5 - Code Injection via IIB Install Directory
CVSS 8.2
CVE-2025-45479 CRITICAL
educoder challenges 1.0 - Remote Code Execution via Container Injection
CVSS 9.8
CVE-2025-7113 LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Curricular Components Module Nome Parameter
CVSS 3.5
CVE-2025-7112 LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Function Management Module
CVSS 3.5
CVE-2025-7111 LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Curso Parameter in Course Module
CVSS 3.5
Details
Vulnerabilities 6,492
Exploit Likelihood Medium