CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,502 vulnerabilities with CWE-94
CVE-2025-24959
LOW
zx <8.3.2 - Command Injection
CVE-2025-0972
LOW
Zenvia Movidesk <= 25.01.22 - Stored Cross-Site Scripting via New Ticket Subject
CVSS 3.5
CVE-2025-0971
LOW
Zenvia Movidesk < 25.01.22 - Cross-Site Scripting via Profile Editing Username Parameter
CVSS 3.5
CVE-2025-0961
LOW
Job Recruitment 1.0 - Cross-Site Scripting via business_stream_name/company_website_url Parameter
CVSS 3.5
CVE-2025-0871
LOW
Maybecms 1.2 - Cross-Site Scripting via data_info[content] Parameter
CVSS 3.5
CVE-2025-0869
MEDIUM
Cianet ONU GW24AC <= 20250127 - Cross-Site Scripting via Login browserLang Parameter
CVSS 4.3
CVE-2025-0844
MEDIUM
needyamin Library Card System 1.0 - Stored Cross-Site Scripting via Registration Page
CVSS 4.3
CVE-2025-0806
MEDIUM
code-projects Job Recruitment 1.0 - XSS
CVSS 4.3
CVE-2025-0800
LOW
SourceCodester Online Courseware 1.0 - XSS
CVSS 2.4
CVE-2025-0795
LOW
ESAFENET CDG V5 - Cross-Site Scripting via todolistjump.jsp flowId Parameter
CVSS 3.5
CVE-2025-0794
LOW
ESAFENET CDG V5 - Cross-Site Scripting via curpage Parameter in todoDetail.jsp
CVSS 3.5
CVE-2025-0790
LOW
ESAFENET CDG V5 - Cross-Site Scripting via curpage Parameter in /doneDetail.jsp
CVSS 3.5
CVE-2025-0787
LOW
ESAFENET CDG V5 - Cross-Site Scripting via curpage Parameter in /appDetail.jsp
CVSS 3.5
CVE-2025-0785
LOW
ESAFENET CDG V5 - Cross-Site Scripting via SysConfig.jsp Help Parameter
CVSS 3.5
CVE-2025-24482
HIGH
Product Version - Local Code Injection
CVE-2025-23211
CRITICAL
Tandoor Recipes < 1.5.24 - Authenticated Server-Side Template Injection via Jinja2
CVSS 9.9
CVE-2025-24159
HIGH
iPadOS < 17.7.4 - Arbitrary Code Execution with Kernel Privileges
CVSS 7.8
CVE-2025-0721
MEDIUM
needyamin image_gallery 1.0 - Cross-Site Scripting via Username Parameter in view.php
CVSS 4.3
CVE-2025-0710
LOW
CampCodes School Management Software 1.0 - XSS
CVSS 3.5
CVE-2025-0709
LOW
Dcat-Admin 2.2.1-beta - Cross-Site Scripting in Roles Page
CVSS 2.4
CVE-2025-0708
LOW
fumiao opencms 2.2 - Cross-Site Scripting via Add Model Management Page Template Prefix
CVSS 3.5
CVE-2025-0706
LOW
JoeyBling bootplus <247d5f6c209be1a5cf10cd0fa18e1d8cc63cf55d - XSS
CVSS 2.4
CVE-2025-0581
LOW
CampCodes School Management Software 1.0 - XSS
CVSS 3.5
CVE-2025-0578
LOW
Facile Sistemas Cloud Apps <20250107 - XSS
CVSS 3.5
CVE-2025-0576
MEDIUM
Mobotix M15 4.3.4.83 - Cross-Site Scripting via p_qual Argument
CVSS 4.3
Details
Vulnerabilities
6,502
Exploit Likelihood
Medium