CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,136 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 101 of 143
- CVE-2025-2371LOWCVSS 3.5EG 3.52025-03-17
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /registered-user-testing.php of the component R…
- CVE-2025-2375LOWCVSS 3.5EG 3.52025-03-17
A vulnerability, which was classified as problematic, was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. Affected is an unknown function of the file /profile.php of the component Admin Profile Page. The manipulati…
- CVE-2025-2377LOWCVSS 3.5EG 3.52025-03-17
A vulnerability was found in SourceCodester Vehicle Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /confirmbooking.php. The manipulation of the argument id leads to cro…
- CVE-2025-24159HIGHCVSS 7.8EG 7.82025-01-27
A validation issue was addressed with improved logic. This issue is fixed in iOS 18.3 and iPadOS 18.3, iPadOS 17.7.4, macOS Sequoia 15.3, macOS Sonoma 14.7.3, tvOS 18.3, visionOS 2.3, watchOS 11.3. An app may be able to execute arbitrary c…
- CVE-2025-2421CRITICALCVSS 9.8EG 9.82025-05-02
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Informatics SambaBox allows Code Injection. This issue affects SambaBox: before 5.1.
- CVE-2025-24243HIGHCVSS 7.8EG 7.82025-03-31
The issue was addressed with improved memory handling. This issue is fixed in iOS 18.4 and iPadOS 18.4, iPadOS 17.7.6, macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5, tvOS 18.4, visionOS 2.4, watchOS 11.4. Processing a malic…
- CVE-2025-24287MEDIUMCVSS 6.1EG 6.12025-06-19
A vulnerability allowing local system users to modify directory contents, allowing for arbitrary code execution on the local system with elevated permissions.
- CVE-2025-24293HIGHCVSS 8.1EG 8.12026-01-30
# Active Storage allowed transformation methods potentially unsafe Active Storage attempts to prevent the use of potentially unsafe image transformation methods and parameters by default. The default allowed list contains three meth…
- CVE-2025-24482HIGHCVSS 7.0EG 7.02025-01-28
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
- CVE-2025-24677CRITICALCVSS 9.9EG 9.92025-02-04
Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a …
- CVE-2025-24893CRITICALCVSS 9.8EG 9.8⚠ KEV2025-02-20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity a…
- CVE-2025-2490LOWCVSS 2.4EG 2.42025-03-18
A vulnerability was found in Dromara ujcms 9.7.5. It has been rated as problematic. Affected by this issue is the function uploadZip/upload of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileUploadController.java of the compone…
- CVE-2025-2491LOWCVSS 2.4EG 2.42025-03-18
A vulnerability classified as problematic has been found in Dromara ujcms 9.7.5. This affects the function update of the file /main/java/com/ujcms/cms/ext/web/backendapi/WebFileTemplateController.java of the component Edit Template File Pa…
- CVE-2025-24959LOWCVSS 1.0EG 1.02025-02-03
zx is a tool for writing better scripts. An attacker with control over environment variable values can inject unintended environment variables into `process.env`. This can lead to arbitrary command execution or unexpected behavior in appli…
- CVE-2025-24977CRITICALCVSS 9.1EG 9.12025-05-05
OpenCTI is an open cyber threat intelligence (CTI) platform. Prior to version 6.4.11 any user with the capability `manage customizations` can execute commands on the underlying infrastructure where OpenCTI is hosted and can access internal…
- CVE-2025-25021HIGHCVSS 7.2EG 7.22025-06-03
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.
- CVE-2025-25246HIGHCVSS 8.1EG 8.12025-02-05
NETGEAR XR1000 before 1.0.0.74, XR1000v2 before 1.1.0.22, and XR500 before 2.3.2.134 allow remote code execution by unauthenticated users.
- CVE-2025-25362CRITICALCVSS 9.8EG 9.82025-03-05
A Server-Side Template Injection (SSTI) vulnerability in Spacy-LLM v0.7.2 allows attackers to execute arbitrary code via injecting a crafted payload into the template field.
- CVE-2025-25467CRITICALCVSS 9.8EG 9.82025-02-18
Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.
- CVE-2025-25507MEDIUMCVSS 6.5EG 6.52025-02-21
There is a RCE vulnerability in Tenda AC6 15.03.05.16_multi. In the formexeCommand function, the parameter cmdinput will cause remote command execution.
- CVE-2025-25675CRITICALCVSS 9.8EG 9.82025-02-20
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is direct…
- CVE-2025-25680HIGHCVSS 7.7EG 7.72025-03-11
LSC Smart Connect LSC Indoor PTZ Camera 7.6.32 is contains a RCE vulnerability in the tuya_ipc_direct_connect function of the anyka_ipc process. The vulnerability allows arbitrary code execution through the Wi-Fi configuration process when…
- CVE-2025-25789CRITICALCVSS 9.8EG 9.82025-02-26
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
- CVE-2025-2582LOWCVSS 3.5EG 3.52025-03-21
A vulnerability was found in SimpleMachines SMF 2.1.4 and classified as problematic. Affected by this issue is some unknown functionality of the file ManageAttachments.php. The manipulation of the argument Notice leads to cross site script…
- CVE-2025-2583LOWCVSS 3.5EG 3.52025-03-21
A vulnerability was found in SimpleMachines SMF 2.1.4. It has been classified as problematic. This affects an unknown part of the file ManageNews.php. The manipulation of the argument subject/message leads to cross site scripting. It is po…
- CVE-2025-2590LOWCVSS 2.4EG 2.42025-03-21
A vulnerability was found in code-projects Human Resource Management System 1.0.1. It has been classified as problematic. Affected is the function UpdateRecruitmentById of the file \handler\recruitment.go. The manipulation of the argument …
- CVE-2025-25943HIGHCVSS 7.8EG 7.82025-02-19
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the AP4_Stz2Atom::AP4_Stz2Atom component located in Ap4Stz2Atom.cpp.
- CVE-2025-25944HIGHCVSS 7.3EG 7.32025-02-19
Buffer Overflow vulnerability in Bento4 v.1.6.0-641 allows a local attacker to execute arbitrary code via the Ap4RtpAtom.cpp, specifically in AP4_RtpAtom::AP4_RtpAtom, during the execution of mp4fragment with a crafted MP4 input file.
- CVE-2025-26003CRITICALCVSS 9.8EG 9.82025-03-26
Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.
- CVE-2025-26014CRITICALCVSS 9.8EG 9.82025-02-21
A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.
- CVE-2025-2616LOWCVSS 2.4EG 2.42025-03-22
A vulnerability classified as problematic has been found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected is an unknown function of the component Role Management Page. The manipulation leads to cross site scripting. I…
- CVE-2025-2617LOWCVSS 2.4EG 2.42025-03-22
A vulnerability classified as problematic was found in yangyouwang 杨有旺 crud 简约后台管理系统 1.0.0. Affected by this vulnerability is an unknown functionality of the component Department Page. The manipulation leads to cross …
- CVE-2025-26182MEDIUMCVSS 6.5EG 6.52025-03-04
An issue in xxyopen novel plus v.4.4.0 and before allows a remote attacker to execute arbitrary code via the PageController.java file
- CVE-2025-2623LOWCVSS 3.5EG 3.52025-03-22
A vulnerability was found in westboy CicadasCMS 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /system/cms/content/save. The manipulation of the argument title/content/laiyu…
- CVE-2025-26238HIGHCVSS 8.1EG 8.12026-08-24
In D-Link DI-8100G 17.12.20A1, the flag parameter in msp_info can be exploited to execute arbitrary code.
- CVE-2025-26260HIGHCVSS 8.8EG 8.82025-03-12
Plenti <= 0.7.16 is vulnerable to code execution. Users uploading '.svelte' files with the /postLocal endpoint can define the file name as javascript codes. The server executes the uploaded file name in host, and cause code execution.
- CVE-2025-26264HIGHCVSS 8.8EG 8.82025-02-27
GeoVision GV-ASWeb with the version 6.1.2.0 or less (fixed in 6.2.0), contains a Remote Code Execution (RCE) vulnerability within its Notification Settings feature. An authenticated attacker with "System Settings" privileges in ASWeb can e…
- CVE-2025-2645LOWCVSS 3.5EG 3.52025-03-23
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /product.php. The manipulation of the argument artname leads to cross site script…
- CVE-2025-2650LOWCVSS 3.5EG 3.52025-03-23
A vulnerability, which was classified as problematic, has been found in PHPGurukul Medical Card Generation System 1.0. This issue affects some unknown processing of the file /download-medical-cards.php. The manipulation of the argument sea…
- CVE-2025-26621HIGHCVSS 7.6EG 7.62025-05-19
OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to version 6.5.2, any user with the capability manage customizations can edit webhook that will execute javascript code. This can be…
- CVE-2025-2673LOWCVSS 3.5EG 3.52025-03-24
A vulnerability classified as problematic has been found in code-projects Payroll Management System 1.0. Affected is an unknown function of the file /home_employee.php. The manipulation of the argument division leads to cross site scriptin…
- CVE-2025-26818CRITICALCVSS 9.8EG 9.82025-04-03
Netwrix Password Secure through 9.2 allows command injection.
- CVE-2025-26845CRITICALCVSS 9.8EG 9.82025-05-08
An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.
- CVE-2025-26924MEDIUMCVSS 6.5EG 6.52025-03-15
Improper Control of Generation of Code ('Code Injection') vulnerability in colabrio Ohio Extra ohio-extra allows Code Injection.This issue affects Ohio Extra: from n/a through <= 3.4.7.
- CVE-2025-26936CRITICALCVSS 10.0EG 10.02025-03-10
Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Fresh Framework fresh-framework allows Code Injection.This issue affects Fresh Framework: from n/a through <= 1.70.0.
- CVE-2025-26970CRITICALCVSS 10.0EG 10.02025-03-03
Improper Control of Generation of Code ('Code Injection') vulnerability in FRESHFACE Ark Theme Core ark-core allows Code Injection.This issue affects Ark Theme Core: from n/a through < 1.71.0.
- CVE-2025-2699LOWCVSS 3.5EG 3.52025-03-24
A vulnerability was found in GetmeUK ContentTools up to 1.6.16. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Image Handler. The manipulation of the argument onload leads to cross s…
- CVE-2025-26996MEDIUMCVSS 6.5EG 6.52025-04-15
Improper Control of Generation of Code ('Code Injection') vulnerability in Fetch Designs Sign-up Sheets sign-up-sheets allows Code Injection.This issue affects Sign-up Sheets: from n/a through <= 2.3.0.1.
- CVE-2025-2700LOWCVSS 3.5EG 3.52025-03-24
A vulnerability classified as problematic has been found in michelson Dante Editor up to 0.4.4. This affects an unknown part of the component Insert Link Handler. The manipulation leads to cross site scripting. It is possible to initiate t…
- CVE-2025-2709MEDIUMCVSS 4.3EG 4.32025-03-24
A vulnerability has been found in Yonyou UFIDA ERP-NC 5.0 and classified as problematic. This vulnerability affects unknown code of the file /login.jsp. The manipulation of the argument key/redirect leads to cross site scripting. The attac…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →