CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,502 vulnerabilities with CWE-94
CVE-2025-2047
LOW
PHPGurukul Art Gallery Management System 1.0 - Cross-Site Scripting via Search Parameter
CVSS 3.5
CVE-2025-25362
CRITICAL
spacy-llm < 0.7.3 - Server-Side Template Injection via Template Field
CVSS 9.8
CVE-2025-27678
CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Remote Code Execution
CVSS 9.8
CVE-2025-27657
CRITICAL
Vasion Print < 20.0.1923 and Virtual Appliance < 22.0.843 - Remote Code Execution
CVSS 9.8
CVE-2025-1967
LOW
Blood Bank Management System 1.0 - XSS
CVSS 3.5
CVE-2025-1957
LOW
code-projects Blood Bank System 1.0 - Cross-Site Scripting via Bloodname Parameter
CVSS 3.5
CVE-2025-1955
LOW
code-projects Online Class and Exam Scheduling System 1.0 - XSS
CVSS 3.5
CVE-2025-1949
MEDIUM
ZZCMS 2025 - Cross-Site Scripting via $_SERVER['PHP_SELF'] in register_nodb.php
CVSS 4.3
CVE-2025-26182
MEDIUM
novel-plus < 4.4.0 - Remote Code Execution via PageController.java
CVSS 6.5
CVE-2025-1905
LOW
SourceCodester Employee Management System 1.0 - XSS
CVSS 3.5
CVE-2025-1904
LOW
code-projects Blood Bank System 1.0 - XSS
CVSS 3.5
CVE-2025-1892
LOW
shishuocms 1.1 - Stored Cross-Site Scripting via folderName Parameter
CVSS 2.4
CVE-2025-26970
CRITICAL
Ark Theme Core < 1.71.0 - Unauthenticated Remote Code Execution
CVSS 10.0
CVE-2025-1842
MEDIUM
FITSTATS Technologies AthleteMonitoring <20250302 - XSS
CVSS 4.3
CVE-2025-1830
LOW
zframeworks zz < 2024-8 - Cross-Site Scripting via Customer Name Argument
CVSS 2.4
CVE-2025-1817
LOW
Mini-Tmall < 2025-02-11 - Cross-Site Scripting in Admin Name Handler
CVSS 2.4
CVE-2025-1810
MEDIUM
Pixsoft Vivaz 6.0.11 - Cross-Site Scripting via Login Endpoint Sistema Parameter
CVSS 4.3
CVE-2025-27554
CRITICAL
ToDesktop < 2024-10-03 - Remote Code Execution via Postinstall Script
CVSS 9.9
CVE-2025-26264
HIGH
GeoVision GV-ASWeb <= 6.1.2.0 - Authenticated Remote Code Execution via Notification Settings
CVSS 8.8
CVE-2025-1742
MEDIUM
PiHome MaxAir 2.0 - Stored Cross-Site Scripting via /home.php page_name Parameter
CVSS 4.3
CVE-2025-25789
CRITICAL
FoxCMS v1.2.5 - Remote Code Execution via Sitemap Controller Index Method
CVSS 9.8
CVE-2025-1618
MEDIUM
vtiger CRM 6.4.0-6.5.0 - Cross-Site Scripting via _operation Parameter
CVSS 4.3
CVE-2025-1617
LOW
Netis WF2780 2.1.41925 - Cross-Site Scripting via Wireless 2.4G Menu SSID Parameter
CVSS 2.4
CVE-2025-1615
LOW
FiberHome AN5506-01A ONU GPON RP2511 - Cross-Site Scripting via NAT Submenu Description Parameter
CVSS 2.4
CVE-2025-1614
LOW
FiberHome AN5506-01A ONU GPON RP2511 - Cross-Site Scripting via Port Forwarding Submenu pf_Description Parameter
CVSS 2.4
Details
Vulnerabilities
6,502
Exploit Likelihood
Medium