CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,501 vulnerabilities with CWE-94
CVE-2025-29306
CRITICAL
FoxCMS v.1.2.5 - Remote Code Execution
CVSS 9.8
CVE-2025-30067
HIGH
Apache Kylin <5.0.1 - Code Injection
CVSS 7.2
CVE-2025-2867
MEDIUM
GitLab 17.8.0-17.8.5, 17.9.0-17.9.2, 17.10.0 - Unauthorized Sensitive Data Exposure via AI-Assisted Development Feature
CVSS 4.4
CVE-2025-2787
HIGH
KNIME Business Hub 1.10.0-1.10.3 - Authenticated Remote Code Execution via Ingress-nginx Component
CVSS 8.8
CVE-2025-26003
CRITICAL
Telesquare TLR-2005KSH 1.1.4 - Unauthenticated Remote Code Execution via admin.cgi setAutorest Parameter
CVSS 9.8
CVE-2025-28893
CRITICAL
Visual Text Editor <1.2.1 - Code Injection
CVSS 9.9
CVE-2025-2715
LOW
timschofield webERP <5.0.0.rc+13 - XSS
CVSS 3.5
CVE-2025-2714
MEDIUM
JoomlaUX JUX Real Estate 3.4.0 - Cross-Site Scripting via Plan ID Parameter
CVSS 4.3
CVE-2025-2712
MEDIUM
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
CVSS 4.3
CVE-2025-2711
MEDIUM
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
CVSS 4.3
CVE-2025-2710
MEDIUM
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
CVSS 4.3
CVE-2025-2709
MEDIUM
Yonyou UFIDA ERP-NC V5.0 - Cross-Site Scripting
CVSS 4.3
CVE-2025-2700
LOW
dante3 0.4.0-0.4.4 - Cross-Site Scripting in Insert Link Handler
CVSS 3.5
CVE-2025-2699
LOW
GetmeUK ContentTools < 1.6.16 - Cross-Site Scripting via Image Handler onload Argument
CVSS 3.5
CVE-2025-2673
LOW
code-projects Payroll Management System 1.0 - XSS
CVSS 3.5
CVE-2025-29806
MEDIUM
Microsoft Edge Chromium < 129.0.2792.52 - Remote Code Execution via Type Confusion
CVSS 6.5
CVE-2025-2650
LOW
PHPGurukul Medical Card Generation System 1.0 - XSS
CVSS 3.5
CVE-2025-2645
LOW
PHPGurukul Art Gallery Management System 1.0 - XSS
CVSS 3.5
CVE-2025-2623
LOW
westboy CicadasCMS 1.0 - Cross-Site Scripting via Title/Content/Laiyuan Argument
CVSS 3.5
CVE-2025-2617
LOW
crud 1.0.0 - Cross-Site Scripting in Department Page
CVSS 2.4
CVE-2025-2616
LOW
crud 1.0.0 - Cross-Site Scripting in Role Management Page
CVSS 2.4
CVE-2025-2303
HIGH
Block Logic - Full Gutenberg Block Display Control <1.0.9 - RCE
CVSS 8.8
CVE-2025-2590
LOW
code-projects Human Resource Management System 1.0.1 - Cross-Site Scripting in UpdateRecruitmentById Function
CVSS 2.4
CVE-2025-2583
LOW
SimpleMachines SMF 2.1.4 - Cross-Site Scripting in ManageNews.php
CVSS 3.5
CVE-2025-2582
LOW
SimpleMachines SMF 2.1.4 - Cross-Site Scripting in ManageAttachments.php
CVSS 3.5
Details
Vulnerabilities
6,501
Exploit Likelihood
Medium