CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,502 vulnerabilities with CWE-94
CVE-2025-2209
LOW
aitangbao springboot-manager 3.0 - Cross-Site Scripting via /sysDict/add Name Parameter
CVSS 2.4
CVE-2025-2208
LOW
aitangbao springboot-manager 3.0 - Cross-Site Scripting via Filename Handler
CVSS 2.4
CVE-2025-2207
LOW
aitangbao springboot-manager 3.0 - Cross-Site Scripting via /sys/dept Name Parameter
CVSS 2.4
CVE-2025-2206
LOW
aitangbao springboot-manager 3.0 - Cross-Site Scripting via /sys/permission Name Parameter
CVSS 2.4
CVE-2025-25680
HIGH
LSC Indoor PTZ Camera 7.6.32 - Remote Code Execution via Crafted QR Code in Wi-Fi Configuration
CVSS 7.7
CVE-2025-2196
LOW
MRCMS 3.1.2 - Cross-Site Scripting via File Upload Path Parameter
CVSS 3.5
CVE-2025-2195
LOW
MRCMS 3.1.2 - Cross-Site Scripting in File Rename Function
CVSS 3.5
CVE-2025-2194
LOW
MRCMS 3.1.2 - Cross-Site Scripting in File Controller Path Parameter
CVSS 3.5
CVE-2025-2191
LOW
Claro A7600-A1 RNR4-A72T-2x16_v2110403_CLA_32_160817 - XSS
CVSS 2.4
CVE-2025-1550
CRITICAL
Keras 3.0.0-3.8.0 and 3.9.0 - Remote Code Execution via Malicious .keras Archive
CVSS 9.8
CVE-2025-2169
HIGH
WPCS - WordPress Currency Switcher Professional <1.2.0.4 - RCE
CVSS 7.3
CVE-2025-26936
CRITICAL
NotFound Fresh Framework <1.70.0 - Code Injection
CVSS 10.0
CVE-2025-1497
CRITICAL
PlotAI < 0.0.7 - Remote Code Execution via Unvalidated LLM Output
CVSS 9.8
CVE-2025-2133
LOW
ftcms 2.1 - Cross-Site Scripting via News Edit Title Parameter
CVSS 2.4
CVE-2025-2131
LOW
xunruicms < 4.6.3 - Cross-Site Scripting via Friendly Links Handler Website Address
CVSS 2.4
CVE-2025-2130
LOW
OpenXE < 1.12 - Cross-Site Scripting via Ticket Notizen Parameter
CVSS 3.5
CVE-2025-2127
MEDIUM
JoomlaUX JUX Real Estate 3.4.0 - XSS
CVSS 4.3
CVE-2025-2124
LOW
Control iD RH iD 25.2.25.0 - Cross-Site Scripting via Change Password API Message Parameter
CVSS 3.5
CVE-2025-2123
LOW
GeSHi < 1.0.9.1 - Cross-Site Scripting via CSS Handler get_var Function
CVSS 3.5
CVE-2025-2087
LOW
starsea-mall 1.0 - Cross-Site Scripting via goodsName Parameter
CVSS 3.5
CVE-2025-2086
LOW
starsea-mall 1.0 - Cross-Site Scripting via redirectUrl Parameter
CVSS 3.5
CVE-2025-2085
LOW
starsea-mall 1.0 - Cross-Site Scripting via redirectUrl Parameter
CVSS 3.5
CVE-2025-2084
LOW
PHPGurukul Human Metapneumovirus Testing Management System 1.0 - Cross-Site Scripting in Search Report Page
CVSS 3.5
CVE-2025-2061
MEDIUM
Online Ticket Reservation System 1.0 - Cross-Site Scripting via Passenger Name Parameter
CVSS 4.3
CVE-2025-2049
LOW
code-projects Blood Bank System 1.0 - Cross-Site Scripting via Bloodname Parameter in AB+.php
CVSS 3.5
Details
Vulnerabilities
6,502
Exploit Likelihood
Medium