CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,136 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 105 of 143
- CVE-2025-37157MEDIUMCVSS 6.7EG 6.72025-11-18
A command injection vulnerability exists in the AOS-CX Operating System. Successful exploitation could allow an authenticated remote attacker to conduct a Remote Code Execution (RCE) on the affected system.
- CVE-2025-37164CRITICALCVSS 10.0EG 10.0⚠ KEV2025-12-16
A remote code execution issue exists in HPE OneView.
- CVE-2025-3753HIGHCVSS 7.8EG 7.82025-07-17
A code execution vulnerability has been identified in the Robot Operating System (ROS) 'rosbag' tool, affecting ROS distributions Noetic Ninjemys and earlier. The vulnerability arises from the use of the eval() function to process unsaniti…
- CVE-2025-3776HIGHCVSS 8.3EG 8.32025-04-24
The Verification SMS with TargetSMS plugin for WordPress is vulnerable to limited Remote Code Execution in all versions up to, and including, 1.5 via the 'targetvr_ajax_handler' function. This is due to a lack of validation on the type of …
- CVE-2025-3788LOWCVSS 3.5EG 3.52025-04-18
A vulnerability was found in baseweb JSite 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /a/sys/user/save. The manipulation of the argument Name leads to cross site scripti…
- CVE-2025-3789LOWCVSS 3.5EG 3.52025-04-18
A vulnerability was found in baseweb JSite 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /a/sys/area/save. The manipulation of the argument Name leads to cross site scripting. The a…
- CVE-2025-3795LOWCVSS 2.4EG 2.42025-04-18
A vulnerability was found in DaiCuo 1.3.13. It has been rated as problematic. Affected by this issue is some unknown functionality of the component SEO Optimization Settings Section. The manipulation leads to cross site scripting. The atta…
- CVE-2025-3801LOWCVSS 2.4EG 2.42025-04-19
A vulnerability was found in songquanpeng one-api up to 0.6.10. It has been classified as problematic. This affects an unknown part of the component System Setting Handler. The manipulation of the argument Homepage Content/About System/Foo…
- CVE-2025-3806LOWCVSS 2.4EG 2.42025-04-19
A vulnerability, which was classified as problematic, has been found in dazhouda lecms up to 3.0.3. Affected by this issue is some unknown functionality of the file /admin of the component Edit Profile Handler. The manipulation leads to cr…
- CVE-2025-3821LOWCVSS 2.4EG 2.42025-04-20
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file add-admin.php. The manipulation of the argument txtpassw…
- CVE-2025-3822LOWCVSS 2.4EG 2.42025-04-20
A vulnerability was found in SourceCodester Web-based Pharmacy Product Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the file changepassword.php. The manipulation of the argument txt…
- CVE-2025-3823LOWCVSS 2.4EG 2.42025-04-20
A vulnerability classified as problematic has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected is an unknown function of the file add-stock.php. The manipulation of the argument txttotalcost/txtproduc…
- CVE-2025-3824LOWCVSS 2.4EG 2.42025-04-20
A vulnerability classified as problematic was found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this vulnerability is an unknown functionality of the file add-product.php. The manipulation of the argumen…
- CVE-2025-3825LOWCVSS 2.4EG 2.42025-04-20
A vulnerability, which was classified as problematic, has been found in SourceCodester Web-based Pharmacy Product Management System 1.0. Affected by this issue is some unknown functionality of the file add-category.php. The manipulation of…
- CVE-2025-3826LOWCVSS 2.4EG 2.42025-04-20
A vulnerability, which was classified as problematic, was found in SourceCodester Web-based Pharmacy Product Management System 1.0. This affects an unknown part of the file add-supplier.php. The manipulation of the argument txtsupplier_nam…
- CVE-2025-3841LOWCVSS 3.3EG 3.32025-04-21
A vulnerability, which was classified as problematic, was found in wix-incubator jam up to e87a6fd85cf8fb5ff37b62b2d68f917219d07ae9. This affects an unknown part of the file jam.py of the component Jinja2 Template Handler. The manipulation…
- CVE-2025-3842MEDIUMCVSS 6.3EG 6.32025-04-21
A vulnerability was found in panhainan DS-Java 1.0 and classified as critical. This issue affects the function uploadUserPic.action of the file src/com/phn/action/FileUpload.java. The manipulation of the argument fileUpload leads to code i…
- CVE-2025-39483MEDIUMCVSS 6.5EG 6.52025-08-14
Improper Control of Generation of Code ('Code Injection') vulnerability in imithemes Eventer eventer allows Code Injection.This issue affects Eventer: from n/a through < 3.9.9.1.
- CVE-2025-3958LOWCVSS 3.5EG 3.52025-04-27
A vulnerability was found in withstars Books-Management-System 1.0. It has been classified as problematic. Affected is an unknown function of the file /book_edit_do.html of the component Book Edit Page. The manipulation of the argument Nam…
- CVE-2025-3961LOWCVSS 3.5EG 3.52025-04-27
A vulnerability classified as problematic has been found in withstars Books-Management-System 1.0. This affects an unknown part of the file /admin/article/add/do. The manipulation of the argument Title leads to cross site scripting. It is …
- CVE-2025-3962LOWCVSS 3.5EG 3.52025-04-27
A vulnerability classified as problematic was found in withstars Books-Management-System 1.0. This vulnerability affects unknown code of the file /api/comment/add of the component Comment Handler. The manipulation of the argument content l…
- CVE-2025-3965LOWCVSS 3.5EG 3.52025-04-27
A vulnerability has been found in itwanger paicoding 1.0.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /article/app/post. The manipulation of the argument content leads to cross sit…
- CVE-2025-3970LOWCVSS 3.5EG 3.52025-04-27
A vulnerability classified as problematic has been found in baseweb JSite up to 1.0. Affected is an unknown function of the file /sys/office/save. The manipulation of the argument Remarks leads to cross site scripting. It is possible to la…
- CVE-2025-3982MEDIUMCVSS 4.3EG 4.32025-04-27
A vulnerability, which was classified as problematic, was found in nortikin Sverchok 1.3.0. Affected is the function SvSetPropNodeMK2 of the file sverchok/nodes/object_nodes/getsetprop_mk2.py of the component Set Property Mk2 Node. The man…
- CVE-2025-3984MEDIUMCVSS 5.0EG 5.02025-04-27
A vulnerability was found in Apereo CAS 5.2.6 and classified as critical. Affected by this issue is the function saveService of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\Reg…
- CVE-2025-3994LOWCVSS 2.4EG 2.42025-04-28
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been classified as problematic. Affected is an unknown function of the file /home.htm of the component IP Port Filtering. The manipulation of the argument Comment leads t…
- CVE-2025-3995LOWCVSS 2.4EG 2.42025-04-28
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /boafrm/fromStaticDHCP of the component LAN Settings Page. The manipu…
- CVE-2025-3996LOWCVSS 2.4EG 2.42025-04-28
A vulnerability was found in TOTOLINK N150RT 3.4.0-B20190525. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /home.htm of the component MAC Filtering Page. The manipulation of the argumen…
- CVE-2025-3999LOWCVSS 3.5EG 3.52025-04-28
A vulnerability, which was classified as problematic, has been found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. This issue affects some unknown processing of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\common\js\a…
- CVE-2025-4000LOWCVSS 3.5EG 3.52025-04-28
A vulnerability, which was classified as problematic, was found in Seeyon Zhiyuan OA Web Application System 8.1 SP2. Affected is an unknown function of the file seeyon\opt\Seeyon\A8\ApacheJetspeed\webapps\seeyon\ssoproxy\jsp\ssoproxy.jsp. …
- CVE-2025-4011LOWCVSS 3.5EG 3.52025-04-28
A vulnerability has been found in Redmine 6.0.0/6.0.1/6.0.2/6.0.3 and classified as problematic. This vulnerability affects unknown code of the component Custom Query Handler. The manipulation of the argument Name leads to cross site scrip…
- CVE-2025-4022MEDIUMCVSS 6.3EG 6.32025-04-28
A vulnerability was found in web-arena-x webarena up to 0.2.0. It has been declared as critical. This vulnerability affects the function HTMLContentEvaluator of the file webarena/evaluation_harness/evaluators.py. The manipulation of the ar…
- CVE-2025-4056HIGHCVSS 7.5EG 7.52025-07-28
A flaw was found in GLib. A denial of service on Windows platforms may occur if an application attempts to spawn a program using long command lines.
- CVE-2025-4075MEDIUMCVSS 4.3EG 4.32025-04-29
A vulnerability was found in VMSMan up to 20250416. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /login.php. The manipulation of the argument Email with the input "><script>alert(1)</sc…
- CVE-2025-41243CRITICALCVSS 10.0EG 10.02025-09-16
Spring Cloud Gateway Server Webflux may be vulnerable to Spring Environment property modification. An application should be considered vulnerable when all the following are true: * The application is using Spring Cloud Gateway Server …
- CVE-2025-41362MEDIUMCVSS 5.3EG 5.32025-06-06
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authent…
- CVE-2025-41365MEDIUMCVSS 5.1EG 5.12025-06-06
Code injection vulnerability in IDF v0.10.0-0C03-03 and ZLF v0.10.0-0C03-04. This vulnerability allows an attacker to store malicious payload in software that will run in the victim's browser. Exploiting this vulnerability requires authent…
- CVE-2025-41699HIGHCVSS 8.8EG 8.82025-10-14
An low privileged remote attacker with an account for the Web-based management can change the system configuration to perform a command injection as root, resulting in a total loss of confidentiality, availability and integrity due to impr…
- CVE-2025-41717HIGHCVSS 8.8EG 8.82026-01-13
An unauthenticated remote attacker can trick a high privileged user into uploading a malicious payload via the config-upload endpoint, leading to code injection as root. This results in a total loss of confidentiality, availability and int…
- CVE-2025-4208MEDIUMCVSS 6.3EG 6.32025-05-08
The NEX-Forms – Ultimate Form Builder – Contact forms and much more plugin for WordPress is vulnerable to Limited Code Execution in all versions up to, and including, 8.9.1 via the get_table_records function. This is due to the unsanit…
- CVE-2025-4218MEDIUMCVSS 5.3EG 5.32025-05-02
A vulnerability was found in handrew browserpilot up to 0.2.51. It has been declared as critical. Affected by this vulnerability is the function GPTSeleniumAgent of the file browserpilot/browserpilot/agents/gpt_selenium_agent.py. The manip…
- CVE-2025-4256LOWCVSS 3.5EG 3.52025-05-05
A vulnerability classified as problematic was found in SeaCMS 13.2. This vulnerability affects unknown code of the file /admin_paylog.php. The manipulation of the argument cstatus leads to cross site scripting. The attack can be initiated …
- CVE-2025-4257LOWCVSS 3.5EG 3.52025-05-05
A vulnerability, which was classified as problematic, has been found in SeaCMS 13.2. This issue affects some unknown processing of the file /admin_pay.php. The manipulation of the argument cstatus leads to cross site scripting. The attack …
- CVE-2025-4261MEDIUMCVSS 5.3EG 5.32025-05-05
A vulnerability was found in GAIR-NLP factool up to 3f3914bc090b644be044b7e0005113c135d8b20f. It has been classified as critical. This affects the function run_single of the file factool/factool/math/tool.py. The manipulation leads to code…
- CVE-2025-42880CRITICALCVSS 9.9EG 9.92025-12-09
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to…
- CVE-2025-42887CRITICALCVSS 9.9EG 9.92025-11-11
Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to…
- CVE-2025-42895MEDIUMCVSS 6.9EG 6.92025-11-11
Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confi…
- CVE-2025-42901MEDIUMCVSS 5.4EG 5.42025-10-14
SAP Application Server for ABAP allows an authenticated attacker to store malicious JavaScript payloads which could be executed in victim user's browser when accessing the affected functionality of BAPI explorer. This has low impact on con…
- CVE-2025-4292LOWCVSS 2.4EG 2.42025-05-05
A vulnerability has been found in MRCMS 3.1.3 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/user/edit.do of the component Edit User Page. The manipulation of the argument Usern…
- CVE-2025-42922CRITICALCVSS 9.9EG 9.92025-09-09
SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and …
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →