CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,506 vulnerabilities with CWE-94
CVE-2024-12991
LOW
DBShop 3.3 Release 231225 - Cross-Site Scripting via orderStatus Parameter
CVSS 3.5
CVE-2024-12983
LOW
Hospital Management System 1.0 - Cross-Site Scripting via Doctor Name Parameter
CVSS 2.4
CVE-2024-12982
LOW
PHPGurukul Blood Bank & Donor Management System 2.4 - Cross-Site Scripting via Address Parameter
CVSS 2.4
CVE-2024-12980
MEDIUM
Job Recruitment 1.0 - Cross-Site Scripting via fname/lname Argument in fln_update Function
CVSS 4.3
CVE-2024-12979
MEDIUM
Job Recruitment 1.0 - Cross-Site Scripting via cname Argument in cn_update Function
CVSS 4.3
CVE-2024-54907
HIGH
TOTOLINK A3002R V4.0.0-B20230531.1404 - Remote Code Execution via formWsc
CVSS 8.8
CVE-2024-12908
MEDIUM
Delinea Secret Server < 11.9.000006 - Remote Code Execution via Protocol Handler URI Normalization Bypass
CVSS 6.9
CVE-2024-12952
MEDIUM
melMass comfy_mtb <0.1.4 - Code Injection
CVSS 6.3
CVE-2024-12933
LOW
code-projects Simple Admin Panel 1.0 - Cross-Site Scripting via updateItemController.php p_name/p_desc Parameters
CVSS 3.5
CVE-2024-12652
HIGH
SmartRobot's Conversational AI Platform <7.2.0 - Code Injection
CVSS 8.8
CVE-2024-12932
LOW
code-projects Simple Admin Panel 1.0 - Cross-Site Scripting via addSizeController.php Size Argument
CVSS 3.5
CVE-2024-12930
LOW
code-projects Simple Admin Panel 1.0 - Cross-Site Scripting via c_name Parameter in addCatController.php
CVSS 3.5
CVE-2024-12900
MEDIUM
FoxCMS < 1.2 - Remote Code Injection via Database Password Parameter
CVSS 6.3
CVE-2024-12893
LOW
Portabilis i-educar < 2.9 - Stored Cross-Site Scripting via Tipo de Usurio Page
CVSS 2.4
CVE-2024-12892
LOW
Online Exam Mastering System 1.0 - Cross-Site Scripting via sign.php name/gender/college Parameters
CVSS 3.5
CVE-2024-12883
MEDIUM
Job Recruitment 1.0 - Cross-Site Scripting via Email Parameter in _email.php
CVSS 4.3
CVE-2024-11977
HIGH
kk Star Ratings - WordPress <=5.4.10 - RCE
CVSS 7.3
CVE-2024-12846
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/link.php siteurl/icon Parameter
CVSS 4.3
CVE-2024-12845
LOW
emlog < 2.4.1 - Cross-Site Scripting via msg Argument in common.php
CVSS 3.5
CVE-2024-56334
HIGH
systeminformation < 5.23.7 - OS Command Injection via SSID Parameter in getWindowsIEEE8021x
CVSS 7.8
CVE-2024-12844
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/store.php Tag Parameter
CVSS 4.3
CVE-2024-12843
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/plugin.php filter Parameter
CVSS 4.3
CVE-2024-56333
CRITICAL
Onyxia-API <4.2.0-<2.8.2 - Authenticated RCE
CVE-2024-12842
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/user.php Keyword Parameter
CVSS 4.3
CVE-2024-12841
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/tag.php Keyword Parameter
CVSS 4.3
Details
Vulnerabilities
6,506
Exploit Likelihood
Medium