CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,506 vulnerabilities with CWE-94
CVE-2024-56803 MEDIUM
ghostty 1.0.0 - Command Injection via Terminal Window Title Escape Sequence
CVE-2024-13083 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13082 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13081 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13080 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13077 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13076 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13075 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13074 LOW
PHPGurukul Land Record System 1.0 - XSS
CVSS 3.5
CVE-2024-13069 LOW
SourceCodester Multi Role Login System 1.0 - XSS
CVSS 3.5
CVE-2024-13034 LOW
code-projects Chat System 1.0 - XSS
CVSS 3.5
CVE-2024-13033 LOW
code-projects Chat System 1.0 - XSS
CVSS 3.5
CVE-2024-13031 LOW
Antabot White-Jotter <= 0.2.2 - Cross-Site Scripting in Article Content Editor
CVSS 2.4
CVE-2024-13023 LOW
PHPGurukul Maid Hiring Management System 1.0 - XSS
CVSS 2.4
CVE-2024-13021 LOW
SourceCodester Road Accident Map Marker 1.0 - XSS
CVSS 3.5
CVE-2024-13019 LOW
code-projects Chat System 1.0 - XSS
CVSS 3.5
CVE-2024-13018 LOW
PHPGurukul Maid Hiring Management System 1.0 - XSS
CVSS 2.4
CVE-2024-13017 LOW
PHPGurukul Maid Hiring Management System 1.0 - XSS
CVSS 2.4
CVE-2024-13015 LOW
PHPGurukul Maid Hiring Management System 1.0 - XSS
CVSS 2.4
CVE-2024-13013 LOW
PHPGurukul Maid Hiring Management System 1.0 - XSS
CVSS 2.4
CVE-2024-13012 LOW
Hostel Management System 1.0 - Cross-Site Scripting via Registration Form Input
CVSS 3.5
CVE-2024-12238 MEDIUM
Ninja Forms < 3.8.22 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 6.3
CVE-2024-12998 MEDIUM
Online Car Rental System 1.0 - Cross-Site Scripting via GET Parameter Handler
CVSS 4.3
CVE-2024-12995 LOW
ruifang-tech Rebuild 3.8.6 - Stored Cross-Site Scripting in Project Tasks Section
CVSS 3.5
CVE-2024-50715 HIGH
Smart Agent 1.1.0 - Remote Code Execution via /youtubeInfo.php Parameter Injection
CVSS 7.5
Details
Vulnerabilities 6,506
Exploit Likelihood Medium