CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,492 vulnerabilities with CWE-94
CVE-2025-50123
HIGH
EcoStruxure IT Data Center Expert >=8.3 - Remote Code Execution via Hostname Input
CVE-2025-5392
CRITICAL
GB Forms DB <= 1.0.2 - Unauthenticated Remote Code Execution via gbfdb_talk_to_front()
CVSS 9.8
CVE-2025-7435
LOW
LiveHelperChat lhc-php-resque Extension - Cross-Site Scripting
CVSS 3.5
CVE-2025-53626
MEDIUM
pdfme 5.2.0-5.4.0 - Prototype Pollution and Cross-Site Scripting via Expression Evaluation
CVSS 6.1
CVE-2025-7408
LOW
SourceCodester Zoo Management System 1.0 - XSS
CVSS 3.5
CVE-2025-34077
CRITICAL
WordPress Pie Register <3.7.1.4 - Auth Bypass
CVE-2025-53547
HIGH
Helm <3.18.4 - Local Code Execution
CVSS 8.5
CVE-2025-49704
HIGH
KEV
Microsoft SharePoint Server - Remote Code Execution
CVSS 8.8
CVE-2025-47988
HIGH
Azure Monitor Agent < 1.35.1 - Unauthenticated Remote Code Execution
CVSS 7.5
CVE-2025-7182
MEDIUM
Student Transcript Processing System 1.0 - Cross-Site Scripting via edit.php pre Parameter
CVSS 4.3
CVE-2025-6744
HIGH
Woodmart <= 8.2.3 - Unauthenticated Arbitrary Shortcode Execution via woodmart_get_products_shortcode()
CVSS 7.3
CVE-2025-42967
CRITICAL
SAP S/4HANA and SCM Characteristic Propagation - User-Level Report Code Execution
CVSS 9.9
CVE-2025-7153
LOW
CodeAstro Simple Hospital Management System 1.0 - Stored Cross-Site Scripting via Doctor Profile POST Parameters
CVSS 3.5
CVE-2025-7148
LOW
CodeAstro Simple Hospital Management System 1.0 - Stored Cross-Site Scripting via Patient POST Parameter
CVSS 3.5
CVE-2025-7144
LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Admin Name Parameter in Admin Profile Page
CVSS 2.4
CVE-2025-7143
LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Tax Name Parameter in Update Tax Page
CVSS 2.4
CVE-2025-7142
LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Search Appointment Panel
CVSS 2.4
CVE-2025-7141
LOW
Best Salon Management System 1.0 - Cross-Site Scripting in Update Staff Page
CVSS 2.4
CVE-2025-7140
LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Staff Name Parameter in Update Staff Page
CVSS 2.4
CVE-2025-7139
LOW
Best Salon Management System 1.0 - Cross-Site Scripting via Update Customer Details Page Name Parameter
CVSS 2.4
CVE-2025-36014
HIGH
IBM Integration Bus for z/OS 10.1.0.0-10.1.0.5 - Code Injection via IIB Install Directory
CVSS 8.2
CVE-2025-45479
CRITICAL
educoder challenges 1.0 - Remote Code Execution via Container Injection
CVSS 9.8
CVE-2025-7113
LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Curricular Components Module Nome Parameter
CVSS 3.5
CVE-2025-7112
LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Function Management Module
CVSS 3.5
CVE-2025-7111
LOW
Portabilis i-Educar 2.9.0 - Cross-Site Scripting via Curso Parameter in Course Module
CVSS 3.5
Details
Vulnerabilities
6,492
Exploit Likelihood
Medium