CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,136 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 100 of 143
- CVE-2025-2209LOWCVSS 2.4EG 2.42025-03-11
A vulnerability, which was classified as problematic, was found in aitangbao springboot-manager 3.0. Affected is an unknown function of the file /sysDict/add. The manipulation of the argument name leads to cross site scripting. It is possi…
- CVE-2025-2210LOWCVSS 2.4EG 2.42025-03-11
A vulnerability has been found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /sysJob/add. The manipulation of the argument name leads to cross site…
- CVE-2025-2211LOWCVSS 2.4EG 2.42025-03-11
A vulnerability was found in aitangbao springboot-manager 3.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sysDictDetail/add. The manipulation of the argument name leads to cross site scr…
- CVE-2025-2212LOWCVSS 2.4EG 2.42025-03-11
A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been classified as problematic. This affects an unknown part of the file /RgSwInfo.asp. The manipulation of the argument Description with the input <img/src/onerror=pr…
- CVE-2025-2213LOWCVSS 2.4EG 2.42025-03-11
A vulnerability was found in Castlenet CBW383G2N up to 20250301. It has been declared as problematic. This vulnerability affects unknown code of the file /wlanPrimaryNetwork.asp of the component Wireless Menu. The manipulation of the argum…
- CVE-2025-22133CRITICALCVSS 9.9EG 9.92025-01-07
WeGIA is a web manager for charitable institutions. Prior to 3.2.8, a critical vulnerability was identified in the /WeGIA/html/socio/sistema/controller/controla_xlsx.php endpoint. The endpoint accepts file uploads without proper validation…
- CVE-2025-22136HIGHCVSS 8.6EG 8.62025-01-08
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fu…
- CVE-2025-2214LOWCVSS 3.5EG 3.52025-03-12
A vulnerability was found in Microweber 2.0.19. It has been rated as problematic. This issue affects some unknown processing of the file userfiles/modules/settings/group/website_group/index.php of the component Settings Handler. The manipu…
- CVE-2025-22152CRITICALCVSS 9.1EG 9.12025-01-10
Atheos is a self-hosted browser-based cloud IDE. Prior to v600, the $path and $target parameters are not properly validated across multiple components, allowing an attacker to read, modify, or execute arbitrary files on the server. These v…
- CVE-2025-22204CRITICALCVSS 9.8EG 9.82025-02-04
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
- CVE-2025-22905CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
- CVE-2025-22906CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
- CVE-2025-22912CRITICALCVSS 9.8EG 9.82025-01-16
RE11S v1.11 was discovered to contain a command injection vulnerability via the component /goform/formAccept.
- CVE-2025-22968CRITICALCVSS 9.8EG 9.82025-01-15
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions
- CVE-2025-2303HIGHCVSS 8.8EG 8.82025-03-22
The Block Logic – Full Gutenberg Block Display Control plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.8 via the block_logic_check_logic function. This is due to the unsafe evaluation…
- CVE-2025-23051HIGHCVSS 7.2EG 7.22025-01-14
An authenticated parameter injection vulnerability exists in the web-based management interface of the AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated user to leverage parameter injection to over…
- CVE-2025-23061CRITICALCVSS 9.0EG 9.02025-01-15
Mongoose before 8.9.5 can improperly use a nested $where filter with a populate() match, leading to search injection. NOTE: this issue exists because of an incomplete fix for CVE-2024-53900.
- CVE-2025-23121CRITICALCVSS 8.8EG 9.92025-06-19
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user
- CVE-2025-2313CRITICALCVSS 9.4EG 9.42025-08-27
In the Print.pl service, the "uhcPrintServerPrint" function allows execution of arbitrary code via the "CopyCounter" parameter.
- CVE-2025-23186HIGHCVSS 8.5EG 8.52025-04-08
In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These cre…
- CVE-2025-23209CRITICALCVSS 8.0EG 9.0⚠ KEV2025-01-18
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been comprom…
- CVE-2025-23211CRITICALCVSS 9.9EG 9.92025-01-28
Tandoor Recipes is an application for managing recipes, planning meals, and building shopping lists. A Jinja2 SSTI vulnerability allows any user to execute commands on the server. In the case of the provided Docker Compose file as root. Th…
- CVE-2025-23251HIGHCVSS 7.6EG 7.62025-04-22
NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.
- CVE-2025-23264HIGHCVSS 7.8EG 7.82025-06-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Es…
- CVE-2025-23265HIGHCVSS 7.8EG 7.82025-06-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in a python component where an attacker may cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability may lead to Code Execution, Es…
- CVE-2025-23295HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA Apex for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue by providing a malicious file. A successful exploit of this vulnerability might lead to code execution, escal…
- CVE-2025-23296HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA Isaac-GR00T for all platforms contains a vulnerability in a Python component where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, in…
- CVE-2025-23298HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA Merlin Transformers4Rec for all platforms contains a vulnerability in a python dependency, where an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution, escalation of …
- CVE-2025-23304HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA NeMo library for all platforms contains a vulnerability in the model loading component, where an attacker could cause code injection by loading .nemo files with maliciously crafted metadata. A successful exploit of this vulnerabilit…
- CVE-2025-23305HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tools component, where an attacker may exploit a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of privileges, in…
- CVE-2025-23306HIGHCVSS 7.8EG 7.82025-08-13
NVIDIA Megatron-LM for all platforms contains a vulnerability in the megatron/training/ arguments.py component where an attacker could cause a code injection issue by providing a malicious input. A successful exploit of this vulnerability …
- CVE-2025-23307HIGHCVSS 7.8EG 7.82025-08-26
NVIDIA NeMo Curator for all platforms contains a vulnerability where a malicious file created by an attacker could allow code injection. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, inf…
- CVE-2025-23312HIGHCVSS 7.8EG 7.82025-08-26
NVIDIA NeMo Framework for all platforms contains a vulnerability in the retrieval services component, where malicious data created by an attacker could cause a code injection. A successful exploit of this vulnerability might lead to code e…
- CVE-2025-23313HIGHCVSS 7.8EG 7.82025-08-26
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution,…
- CVE-2025-23314HIGHCVSS 7.8EG 7.82025-08-26
NVIDIA NeMo Framework for all platforms contains a vulnerability in the NLP component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to code execution,…
- CVE-2025-23315HIGHCVSS 7.8EG 7.82025-08-26
NVIDIA NeMo Framework for all platforms contains a vulnerability in the export and deploy component, where malicious data created by an attacker could cause a code injection issue. A successful exploit of this vulnerability might lead to c…
- CVE-2025-23348HIGHCVSS 7.8EG 7.82025-09-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in the pretrain_gpt script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, …
- CVE-2025-23349HIGHCVSS 7.8EG 7.82025-09-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in the tasks/orqa/unsupervised/nq.py component, where an attacker may cause a code injection. A successful exploit of this vulnerability may lead to code execution, escalation o…
- CVE-2025-2335LOWCVSS 3.5EG 3.52025-03-16
A vulnerability classified as problematic was found in Drivin Soluções up to 20250226. This vulnerability affects unknown code of the file /api/school/registerSchool of the component API Handler. The manipulation of the argument message …
- CVE-2025-23353HIGHCVSS 7.8EG 7.82025-09-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in the msdp preprocessing script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escal…
- CVE-2025-23354HIGHCVSS 7.8EG 7.82025-09-24
NVIDIA Megatron-LM for all platforms contains a vulnerability in the ensemble_classifer script where malicious data created by an attacker may cause an injection. A successful exploit of this vulnerability may lead to code execution, escal…
- CVE-2025-23357HIGHCVSS 7.8EG 7.82025-11-11
NVIDIA Megatron-LM for all platforms contains a vulnerability in a script, where malicious data created by an attacker may cause a code injection issue. A successful exploit of this vulnerability may lead to code execution, escalation of p…
- CVE-2025-23361HIGHCVSS 7.8EG 7.82025-11-11
NVIDIA NeMo Framework for all platforms contains a vulnerability in a script, where malicious input created by an attacker may cause improper control of code generation. A successful exploit of this vulnerability may lead to code execution…
- CVE-2025-23376LOWCVSS 2.3EG 2.32025-04-28
Dell PowerProtect Data Manager Reporting, version(s) 19.16, 19.17, 19.18, contain(s) an Improper Neutralization of Special Elements Used in a Template Engine vulnerability. A high privileged attacker with local access could potentially exp…
- CVE-2025-2340LOWCVSS 2.4EG 2.42025-03-16
A vulnerability was found in otale Tale Blog 2.0.5. It has been declared as problematic. This vulnerability affects the function saveOptions of the file /options/save of the component Site Settings. The manipulation of the argument Site Ti…
- CVE-2025-2352LOWCVSS 2.4EG 2.42025-03-16
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/indexConfigs/save of the component Backend. The manipulation of the argument …
- CVE-2025-2354MEDIUMCVSS 4.3EG 4.32025-03-17
A vulnerability has been found in VAM Virtual Airlines Manager 2.6.2 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /vam/index.php. The manipulation of the argument registry_id/plane_i…
- CVE-2025-2361MEDIUMCVSS 4.3EG 4.32025-03-17
A vulnerability was found in Mercurial SCM 4.5.3/71.19.145.211. It has been declared as problematic. This vulnerability affects unknown code of the component Web Interface. The manipulation of the argument cmd leads to cross site scripting…
- CVE-2025-2364LOWCVSS 3.5EG 3.52025-03-17
A vulnerability classified as problematic was found in lenve VBlog up to 1.0.0. Affected by this vulnerability is the function addNewArticle of the file blogserver/src/main/java/org/sang/service/ArticleService.java. The manipulation of the…
- CVE-2025-2366LOWCVSS 2.4EG 2.42025-03-17
A vulnerability, which was classified as problematic, was found in gougucms 4.08.18. This affects the function add of the file /admin/department/add of the component Add Department Page. The manipulation of the argument title leads to cros…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →