CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,136 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 104 of 143
- CVE-2025-3387LOWCVSS 3.5EG 3.52025-04-07
A vulnerability classified as problematic has been found in renrenio renren-security up to 5.4.0. This affects an unknown part of the component JSON Handler. The manipulation leads to cross site scripting. It is possible to initiate the at…
- CVE-2025-3388MEDIUMCVSS 4.3EG 4.32025-04-07
A vulnerability classified as problematic was found in hailey888 oa_system up to 2025.01.01. This vulnerability affects the function loginCheck of the file cn/gson/oasys/controller/login/LoginsController.java of the component Frontend. The…
- CVE-2025-3389LOWCVSS 3.5EG 3.52025-04-08
A vulnerability, which was classified as problematic, has been found in hailey888 oa_system up to 2025.01.01. This issue affects the function testMess of the file cn/gson/oasys/controller/inform/InformManageController.java of the component…
- CVE-2025-3390LOWCVSS 3.5EG 3.52025-04-08
A vulnerability, which was classified as problematic, was found in hailey888 oa_system up to 2025.01.01. Affected is the function addandchangeday of the file cn/gson/oass/controller/daymanager/DaymanageController.java of the component Back…
- CVE-2025-3391LOWCVSS 3.5EG 3.52025-04-08
A vulnerability has been found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this vulnerability is the function outAddress of the file cn/gson/oass/controller/address/AddrController. java of the compone…
- CVE-2025-3392LOWCVSS 3.5EG 3.52025-04-08
A vulnerability was found in hailey888 oa_system up to 2025.01.01 and classified as problematic. Affected by this issue is the function Save of the file cn/gson/oasys/controller/mail/MailController.java of the component Backend. The manipu…
- CVE-2025-3393LOWCVSS 3.5EG 3.52025-04-08
A vulnerability was found in mrcen springboot-ucan-admin up to 5f35162032cbe9288a04e429ef35301545143509. It has been classified as problematic. This affects an unknown part of the file /ucan-admin/index of the component Personal Settings I…
- CVE-2025-3397MEDIUMCVSS 4.3EG 4.32025-04-08
A vulnerability classified as problematic has been found in YzmCMS 7.1. Affected is an unknown function of the file message.tpl. The manipulation of the argument gourl leads to cross site scripting. It is possible to launch the attack remo…
- CVE-2025-34046CRITICALCVSS 10.0EG 10.02025-06-26
An unauthenticated file upload vulnerability exists in the Fanwei E-Office <= v9.4 web management interface. The vulnerability affects the /general/index/UploadFile.php endpoint, which improperly validates uploaded files when invoked with …
- CVE-2025-34061CRITICALCVSS 9.3EG 9.32025-07-03
A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of in…
- CVE-2025-34074CRITICALCVSS 9.4EG 9.42025-07-02
An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled jo…
- CVE-2025-34077CRITICALCVSS 10.0EG 10.02025-07-09
An authentication bypass vulnerability exists in the WordPress Pie Register plugin ≤ 3.7.1.4 that allows unauthenticated attackers to impersonate arbitrary users by submitting a crafted POST request to the login endpoint. By setting soci…
- CVE-2025-34079HIGHCVSS 7.8EG 7.82025-07-02
An authenticated remote code execution vulnerability exists in NSClient++ version 0.5.2.35 when the web interface and ExternalScripts module are enabled. A remote attacker with the administrator password can authenticate to the web interfa…
- CVE-2025-34086HIGHCVSS 8.8EG 8.82025-07-03
Bolt CMS versions 3.7.0 and earlier contain a chain of vulnerabilities that together allow an authenticated user to achieve remote code execution. A user with valid credentials can inject arbitrary PHP code into the displayname field of th…
- CVE-2025-34089CRITICALCVSS 9.3EG 9.32025-07-03
An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disab…
- CVE-2025-34114HIGHCVSS 8.4EG 8.42025-07-25
A client-side security misconfiguration vulnerability exists in OpenBlow whistleblowing platform across multiple versions and default deployments, due to the absence of critical HTTP response headers including Content-Security-Policy, Refe…
- CVE-2025-34123HIGHCVSS 8.4EG 8.42025-07-16
A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, l…
- CVE-2025-34124HIGHCVSS 8.4EG 8.42025-07-16
A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in…
- CVE-2025-34127CRITICALCVSS 9.3EG 9.32025-07-16
A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds che…
- CVE-2025-34128HIGHCVSS 8.6EG 8.62025-07-16
A buffer overflow vulnerability exists in the X360 VideoPlayer ActiveX control (VideoPlayer.ocx) version 2.6 when handling overly long arguments to the ConvertFile() method. An attacker can exploit this vulnerability by supplying crafted i…
- CVE-2025-34159HIGHCVSS 8.8EG 8.82025-08-27
Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Dock…
- CVE-2025-3422MEDIUMCVSS 5.4EG 5.42025-04-11
The The Everest Forms – Contact Form, Quiz, Survey, Newsletter & Payment Form Builder for WordPress plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.1.1. This is due to the softw…
- CVE-2025-34277CRITICALCVSS 9.8EG 9.82025-10-30
Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard…
- CVE-2025-34433CRITICALCVSS 9.3EG 9.32025-12-19
AVideo versions 14.3.1 prior to 20.1 contain an unauthenticated remote code execution vulnerability caused by predictable generation of an installation salt using PHP uniqid(). The installation timestamp is exposed via a public endpoint, a…
- CVE-2025-3472MEDIUMCVSS 6.5EG 6.52025-04-22
The Ocean Extra plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.4.6. This is due to the software allowing users to execute an action that does not properly validate a value before…
- CVE-2025-3489MEDIUMCVSS 4.3EG 4.32025-04-10
A vulnerability was found in Nababur Simple-User-Management-System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /register.php. The manipulation of the argument name/username leads …
- CVE-2025-3491HIGHCVSS 7.2EG 7.22025-04-26
The Add custom page template plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'acpt_validate_setting' function. This is due to insufficient saniti…
- CVE-2025-35036HIGHCVSS 7.3EG 7.32025-06-03
Hibernate Validator before 6.2.0 and 7.0.0, by default and depending how it is used, may interpolate user-supplied input in a constraint violation message with Expression Language. This could allow an attacker to access sensitive informati…
- CVE-2025-3509HIGHCVSS 7.2EG 7.22025-04-17
A Remote Code Execution (RCE) vulnerability was identified in GitHub Enterprise Server that allowed attackers to execute arbitrary code by exploiting the pre-receive hook functionality, potentially leading to privilege escalation and syste…
- CVE-2025-3531MEDIUMCVSS 4.3EG 4.32025-04-13
A vulnerability classified as problematic has been found in YouDianCMS 9.5.21. This affects an unknown part of the file /App/Tpl/Admin/Default/Log/index.html. The manipulation of the argument UserName/LogType leads to cross site scripting.…
- CVE-2025-3532MEDIUMCVSS 4.3EG 4.32025-04-13
A vulnerability classified as problematic was found in YouDianCMS 9.5.21. This vulnerability affects unknown code of the file /App/Tpl/Member/Default/Order/index.html.Attackers. The manipulation of the argument OrderNumber leads to cross s…
- CVE-2025-3533MEDIUMCVSS 4.3EG 4.32025-04-13
A vulnerability, which was classified as problematic, has been found in YouDianCMS 9.5.21. This issue affects some unknown processing of the file /App/Tpl/Admin/Default/Channel/index.html.Attackers. The manipulation of the argument Parent …
- CVE-2025-3554MEDIUMCVSS 4.3EG 4.32025-04-14
A vulnerability was found in phpshe 1.8. It has been rated as problematic. This issue affects some unknown processing of the file api.php?mod=cron&act=buyer. The manipulation of the argument act leads to cross site scripting. The attack ma…
- CVE-2025-3560LOWCVSS 3.5EG 3.52025-04-14
A vulnerability was found in ghostxbh uzy-ssm-mall 1.0.0 and classified as problematic. This issue affects some unknown processing of the file /product. The manipulation of the argument product_name leads to cross site scripting. The attac…
- CVE-2025-3563MEDIUMCVSS 4.7EG 4.72025-04-14
A vulnerability was found in WuzhiCMS 4.1. It has been rated as critical. Affected by this issue is the function Set of the file /index.php?m=attachment&f=index&_su=wuzhicms&v=set&submit=1 of the component Setting Handler. The manipulation…
- CVE-2025-3568LOWCVSS 3.5EG 3.52025-04-14
A vulnerability has been found in Webkul Krayin CRM up to 2.1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/settings/users/edit/ of the component SVG File Handler. The manipu…
- CVE-2025-3570LOWCVSS 3.5EG 3.52025-04-14
A vulnerability was found in JamesZBL/code-projects db-hospital-drug 1.0. It has been classified as problematic. This affects the function Save of the file ContentController.java. The manipulation of the argument content leads to cross sit…
- CVE-2025-3579CRITICALCVSS 9.3EG 9.32025-04-15
In versions prior to Aidex 1.7, an authenticated malicious user, taking advantage of an open registry, could execute unauthorised commands within the system. This includes executing operating system (Unix) commands, interacting with intern…
- CVE-2025-3591LOWCVSS 3.5EG 3.52025-04-14
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/v1/blog/edit. The manipulation leads to cross site scripting. Th…
- CVE-2025-3592LOWCVSS 3.5EG 3.52025-04-14
A vulnerability was found in ZHENFENG13/code-projects My-Blog-layui 1.0. It has been classified as problematic. This affects an unknown part of the file /admin/v1/link/edit. The manipulation leads to cross site scripting. It is possible to…
- CVE-2025-36014HIGHCVSS 8.2EG 8.22025-07-07
IBM Integration Bus for z/OS 10.1.0.0 through 10.1.0.5 is vulnerable to code injection by a privileged user with access to the IIB install directory.
- CVE-2025-3612MEDIUMCVSS 4.3EG 4.32025-04-15
A vulnerability, which was classified as problematic, was found in Demtec Graphytics 5.0.7. This affects an unknown part of the file /visualization of the component HTTP GET Parameter Handler. The manipulation leads to cross site scripting…
- CVE-2025-3613LOWCVSS 3.5EG 3.52025-04-15
A vulnerability has been found in Demtec Graphytics 5.0.7 and classified as problematic. This vulnerability affects unknown code of the file /visualization. The manipulation of the argument description leads to cross site scripting. The at…
- CVE-2025-3641HIGHCVSS 8.8EG 8.82025-04-25
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS Dropbox repository. By default, this was only available to teachers and managers on sites with the Dropbox repository enabled.
- CVE-2025-3642HIGHCVSS 8.8EG 8.82025-04-25
A flaw was found in Moodle. A remote code execution risk was identified in the Moodle LMS EQUELLA repository. By default, this was only available to teachers and managers on sites with the EQUELLA repository enabled.
- CVE-2025-3688LOWCVSS 2.4EG 2.42025-04-16
A vulnerability, which was classified as problematic, was found in mirweiye Seven Bears Library CMS 2023. This affects an unknown part of the component Background Management Page. The manipulation leads to cross site scripting. It is possi…
- CVE-2025-3692LOWCVSS 2.4EG 2.42025-04-16
A vulnerability was found in SourceCodester Online Eyewear Shop 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /oews/classes/Master.php?f=save_product. The manipulation lead…
- CVE-2025-36938MEDIUMCVSS 6.8EG 6.82025-12-11
In U-Boot of append_uint32_le(), there is a possible fault injection due to a logic error in the code. This could lead to physical escalation of privilege with no additional execution privileges needed. User interaction is not needed for e…
- CVE-2025-37099CRITICALCVSS 9.8EG 9.82025-07-01
A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.
- CVE-2025-37105HIGHCVSS 7.5EG 7.52025-07-16
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.18.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →