CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,503 vulnerabilities with CWE-94
CVE-2025-0342
LOW
CampCodes Computer Laboratory Management System 1.0 - XSS
CVSS 3.5
CVE-2025-0339
LOW
code-projects Online Bike Rental 1.0 - XSS
CVSS 3.5
CVE-2025-22136
HIGH
Tabby < 1.0.217 - Remote Code Execution via Electron Fuses
CVE-2025-22133
CRITICAL
WeGIA < 3.2.8 - Unrestricted Upload of File with Dangerous Type via controla_xlsx.php Endpoint
CVSS 9.9
CVE-2025-0301
LOW
code-projects Online Book Shop 1.0 - XSS
CVSS 3.5
CVE-2025-0295
LOW
code-projects Online Book Shop 1.0 - XSS
CVSS 3.5
CVE-2025-0228
LOW
Code-projects Local Storage Todo App 1.0 - XSS
CVSS 2.4
CVE-2025-0220
LOW
Trimble SPS851 488.01 - Cross-Site Scripting via Hostname Argument
CVSS 2.4
CVE-2025-0219
LOW
Trimble SPS851 488.01 - Cross-Site Scripting via System Name Argument
CVSS 2.4
CVE-2025-0175
LOW
code-projects Online Shop 1.0 - XSS
CVSS 3.5
CVE-2024-58351
CRITICAL
Flowise - Remote Code Execution via overrideConfig Parameter
CVSS 9.8
CVE-2024-46507
HIGH
Yeti Platform < 2.1.12 - Server-Side Template Injection
CVSS 7.3
CVE-2024-1490
HIGH
Wago: Vulnerability in WBM through Open VPN
CVSS 7.2
CVE-2024-36057
CRITICAL
Koha Library <23.05.10 - Command Injection
CVSS 9.8
CVE-2024-40489
CRITICAL
jeecg boot 3.0.0-3.5.3 - Code Injection
CVSS 9.8
CVE-2024-13785
MEDIUM
Contact Form, Survey, Quiz & Popup Form Builder – ARForms <= 1.7.2 - Unauthenticated Blind Arbitrary Shortcode Execution
CVSS 5.6
CVE-2024-44722
CRITICAL
SysAK < 2.0 - OS Command Injection via Command Parameter
CVSS 9.8
CVE-2024-55022
HIGH
Weintek cMT-3072XH2 v2.1.53 - Command Injection
CVSS 8.8
CVE-2024-56373
HIGH
Airflow 2 - Privilege Escalation to RCE
CVSS 8.4
CVE-2024-11976
HIGH
BuddyPress <= 14.3.3 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 7.3
CVE-2024-14020
MEDIUM
carbone < 3.5.6 - Prototype Pollution in Formatter Handler
CVSS 5.0
CVE-2024-58284
HIGH
PopojiCMS 2.0.1 - Authenticated Remote Code Execution via Metadata Settings
CVSS 7.2
CVE-2024-32641
CRITICAL
masacms < 7.2.8 - Unauthenticated Remote Code Execution via m Tag in criteria Parameter
CVSS 9.8
CVE-2024-39148
HIGH
KerOS < 5.12 - Unauthenticated Remote Code Execution via Magic URL Validation Flaw
CVSS 8.1
CVE-2024-48829
MEDIUM
Dell SmartFabric OS10 < 10.6.1.0 - Authenticated Code Injection
CVSS 6.7
Details
Vulnerabilities
6,503
Exploit Likelihood
Medium