CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,501 vulnerabilities with CWE-94
CVE-2025-28146 CRITICAL
Edimax BR-6478AC V3 Firmware 1.0.15 - OS Command Injection via fota_url Parameter
CVSS 9.8
CVE-2025-3219 LOW
Perfex CRM 3.2.1 - Stored Cross-Site Scripting in Project Discussions Module
CVSS 3.5
CVE-2025-29064 CRITICAL
TOTOLINK X18 v.9.1.0cu.2024_B20220329 - Remote Code Execution via cstecgi.cgi sub_410E54 Function
CVSS 9.8
CVE-2025-26818 CRITICAL
Netwrix Password Secure <= 9.2 - OS Command Injection
CVSS 9.8
CVE-2025-3164 MEDIUM
Tencent Music Entertainment SuperSonic <= 0.9.8 - Remote Code Execution via H2 Database Connection Handler
CVSS 4.7
CVE-2025-3163 MEDIUM
InternLM LMDeploy <= 0.7.1 - Code Injection in Open Function
CVSS 5.3
CVE-2025-3157 LOW
Intelbras WRN 150 1.0.15_pt_ITB01 - XSS
CVSS 2.4
CVE-2025-2945 CRITICAL
pgAdmin Query Tool authenticated RCE (CVE-2025-2945)
CVSS 9.9
CVE-2025-3152 LOW
caipeichao ThinkOX 1.0 - Cross-Site Scripting via Search Keywords Parameter
CVSS 3.5
CVE-2025-3149 LOW
itning Student Homework Management System <= 1.2.7 - Cross-Site Scripting via Edit Job Page Course Parameter
CVSS 2.4
CVE-2025-31722 HIGH
Jenkins Templating Engine Plugin <2.5.3 - RCE
CVSS 8.8
CVE-2025-30580 CRITICAL
DigiWidgets Image Editor <1.10 - Code Injection
CVSS 10.0
CVE-2025-30911 CRITICAL
Rometheme RomethemeKit For Elementor <1.5.4 - Code Injection
CVSS 9.9
CVE-2025-24243 HIGH
Apple iPadOS < 17.7.6 - Remote Code Execution via Maliciously Crafted File
CVSS 7.8
CVE-2025-3036 LOW
yzk2356911358 StudentServlet-JSP - Cross-Site Scripting via Name Argument
CVSS 2.4
CVE-2025-3005 LOW
ForestBlog < 2025-03-21 - Cross-Site Scripting in Friend Link Handler
CVSS 3.5
CVE-2025-3004 LOW
ForestBlog < 2025-03-21 - Cross-Site Scripting via Search Keywords Parameter
CVSS 3.5
CVE-2025-2981 LOW
Legrand SMS PowerView 1.x - Cross-Site Scripting via Redirect Parameter
CVSS 3.5
CVE-2025-2979 LOW
WCMS 11 - Stored Cross-Site Scripting via Username Parameter in Registration
CVSS 2.4
CVE-2025-2977 LOW
GFI KerioConnect 10.0.6 - Cross-Site Scripting in PDF File Handler
CVSS 3.5
CVE-2025-2976 LOW
GFI KerioConnect 10.0.6 - Stored Cross-Site Scripting via File Upload
CVSS 3.5
CVE-2025-2975 LOW
GFI KerioConnect 10.0.6 - Stored Cross-Site Scripting in Signature Handler
CVSS 3.5
CVE-2025-2974 LOW
Perfex CRM < 3.2.1 - Stored Cross-Site Scripting in Contracts Module
CVSS 3.5
CVE-2025-2803 HIGH
So-Called Air Quotes <= 0.1 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 7.3
CVE-2025-2878 LOW
Kentico CMS < 13.0.178 - Cross-Site Scripting via New Database Parameter in Install Wizard
CVSS 2.4
Details
Vulnerabilities 6,501
Exploit Likelihood Medium