CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 108 of 143
- CVE-2025-51427HIGHCVSS 7.3EG 7.32026-05-19
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
- CVE-2025-51482HIGHCVSS 8.8EG 8.82025-07-22
Remote Code Execution in letta.server.rest_api.routers.v1.tools.run_tool_from_source in letta-ai Letta 0.7.12 allows remote attackers to execute arbitrary Python code and system commands via crafted payloads to the /v1/tools/run endpoint, …
- CVE-2025-5150HIGHCVSS 8.8EG 8.82025-05-25
A vulnerability was found in docarray up to 0.40.1. It has been rated as critical. Affected by this issue is the function __getitem__ of the file /docarray/data/torch_dataset.py of the component Web API. The manipulation leads to improperl…
- CVE-2025-5151HIGHCVSS 7.8EG 7.82025-05-25
A vulnerability classified as critical has been found in defog-ai introspect up to 0.1.4. This affects the function execute_analysis_code_safely of the file introspect/backend/tools/analysis_tools.py. The manipulation of the argument code …
- CVE-2025-5153MEDIUMCVSS 4.8EG 4.82025-05-25
A vulnerability, which was classified as problematic, has been found in CMS Made Simple 2.2.21. This issue affects some unknown processing of the component Design Manager Module. The manipulation of the argument Description leads to cross …
- CVE-2025-5177MEDIUMCVSS 4.7EG 4.72025-05-26
A vulnerability was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. It has been rated as problematic. This issue affects some unknown processing of the file /adm/index.php of the component Admin Login Page. The manipulation o…
- CVE-2025-5179LOWCVSS 3.4EG 3.42025-05-26
A vulnerability classified as problematic was found in Realce Tecnologia Queue Ticket Kiosk up to 20250517. Affected by this vulnerability is an unknown functionality of the file /adm/index.php of the component Cadastro de Administrador Pa…
- CVE-2025-5181MEDIUMCVSS 4.1EG 4.12025-05-26
A vulnerability, which was classified as problematic, was found in Summer Pearl Group Vacation Rental Management Platform up to 1.0.1. This affects an unknown part of the file /spgpm/updateListing. The manipulation of the argument spgLsTit…
- CVE-2025-51991HIGHCVSS 8.8EG 8.82025-08-20
XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrato…
- CVE-2025-52122CRITICALCVSS 9.8EG 9.82025-08-27
Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).
- CVE-2025-52218HIGHCVSS 7.5EG 7.52025-08-26
SelectZero Data Observability Platform before 2025.5.2 is vulnerable to Content Spoofing / Text Injection. Improper sanitization of unspecified parameters allows attackers to inject arbitrary text or limited HTML into the login page.
- CVE-2025-52385CRITICALCVSS 9.8EG 9.82025-08-13
An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module
- CVE-2025-52718HIGHCVSS 7.2EG 7.22025-07-04
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Remote Code Inclusion.This issue affects Alone: from n/a through <= 7.8.2.
- CVE-2025-52744HIGHCVSS 7.7EG 7.72026-02-20
Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Inpersttion For Theme err-our-team allows Code Injection.This issue affects Inpersttion For Theme: from n/a through <= 1.0.
- CVE-2025-52756HIGHCVSS 7.4EG 7.42025-10-22
Improper Control of Generation of Code ('Code Injection') vulnerability in Sayan Datta WP Last Modified Info wp-last-modified-info allows Remote Code Inclusion.This issue affects WP Last Modified Info: from n/a through <= 1.9.4.
- CVE-2025-53002HIGHCVSS 8.3EG 8.32025-06-26
LLaMA-Factory is a tuning library for large language models. A remote code execution vulnerability was discovered in LLaMA-Factory versions up to and including 0.9.3 during the LLaMA-Factory training process. This vulnerability arises beca…
- CVE-2025-5309CRITICALCVSS 9.8EG 9.82025-06-16
The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.
- CVE-2025-5321CRITICALCVSS 9.9EG 9.92025-05-29
A vulnerability classified as critical was found in aimhubio aim up to 3.29.1. This vulnerability affects the function RestrictedPythonQuery of the file /aim/storage/query.py of the component run_view Object Handler. The manipulation of th…
- CVE-2025-5333CRITICALCVSS 9.5EG 9.52025-07-06
Remote attackers can execute arbitrary code in the context of the vulnerable service process.
- CVE-2025-53419HIGHCVSS 7.8EG 7.82025-08-26
Delta Electronics COMMGR has Code Injection vulnerability.
- CVE-2025-53547HIGHCVSS 8.5EG 8.52025-07-08
Helm is a package manager for Charts for Kubernetes. Prior to 3.18.4, a specially crafted Chart.yaml file along with a specially linked Chart.lock file can lead to local code execution when dependencies are updated. Fields in a Chart.yaml …
- CVE-2025-53577CRITICALCVSS 10.0EG 10.02025-08-20
Improper Control of Generation of Code ('Code Injection') vulnerability in thehp Global DNS global-dns allows Remote Code Inclusion.This issue affects Global DNS: from n/a through <= 3.1.0.
- CVE-2025-53626MEDIUMCVSS 6.1EG 6.12025-07-10
pdfme is a TypeScript-based PDF generator and React-based UI. The expression evaluation feature in pdfme 5.2.0 to 5.4.0 contains critical vulnerabilities allowing sandbox escape leading to XSS and prototype pollution attacks. This vulnerab…
- CVE-2025-5377MEDIUMCVSS 6.1EG 6.12025-05-31
A vulnerability was found in Astun Technology iShare Maps 5.4.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file historic1.asp. The manipulation of the argument Zoom leads to cross site sc…
- CVE-2025-5378MEDIUMCVSS 6.1EG 6.12025-05-31
A vulnerability classified as problematic has been found in Astun Technology iShare Maps 5.4.0. This affects an unknown part of the file mycouncil2.aspx. The manipulation of the argument atTxtStreet leads to cross site scripting. It is pos…
- CVE-2025-5383MEDIUMCVSS 4.8EG 4.82025-05-31
A vulnerability was found in Yifang CMS up to 2.0.2 and classified as problematic. Affected by this issue is some unknown functionality of the component Article Management Module. The manipulation of the argument Default Value leads to cro…
- CVE-2025-53836CRITICALCVSS 9.9EG 9.92025-07-15
XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, t…
- CVE-2025-53867CRITICALCVSS 9.8EG 9.82025-07-17
Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.
- CVE-2025-53890CRITICALCVSS 9.8EG 9.82025-07-15
pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser a…
- CVE-2025-5392CRITICALCVSS 9.8EG 9.82025-07-11
The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. This is due to the function accepting user input and then passing that through …
- CVE-2025-53927MEDIUMCVSS 4.6EG 4.62025-07-17
MaxKB is an open-source AI assistant for enterprise. Prior to version 2.0.0, the sandbox design rules can be bypassed because MaxKB only restricts the execution permissions of files in a specific directory. Therefore, an attacker can use t…
- CVE-2025-53928MEDIUMCVSS 4.6EG 4.62025-07-17
MaxKB is an open-source AI assistant for enterprise. Prior to versions 1.10.9-lts and 2.0.0, a Remote Command Execution vulnerability exists in the MCP call. Versions 1.10.9-lts and 2.0.0 fix the issue.
- CVE-2025-5396CRITICALCVSS 9.8EG 9.82025-07-17
The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input p…
- CVE-2025-54019MEDIUMCVSS 6.5EG 6.52025-08-20
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through < 7.8.5.
- CVE-2025-5405MEDIUMCVSS 5.4EG 5.42025-06-01
A vulnerability, which was classified as problematic, has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513. This issue affects some unknown processing of the file /post.php. The manipulation of the argume…
- CVE-2025-54063HIGHCVSS 8.0EG 8.02025-08-11
Cherry Studio is a desktop client that supports for multiple LLM providers. From versions 1.4.8 to 1.5.0, there is a one-click remote code execution vulnerability through the custom URL handling. An attacker can exploit this by hosting a m…
- CVE-2025-54068CRITICALCVSS 9.8EG 9.8⚠ KEV2025-07-17
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain compone…
- CVE-2025-5407MEDIUMCVSS 5.4EG 5.42025-06-01
A vulnerability has been found in chaitak-gorai Blogbook up to 92f5cf90f8a7e6566b576fe0952e14e1c6736513 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /register_script.php. The manipul…
- CVE-2025-5411MEDIUMCVSS 5.4EG 5.42025-06-01
A vulnerability was found in Mist Community Edition up to 4.7.1. It has been rated as problematic. This issue affects the function tag_resources of the file src/mist/api/tag/views.py. The manipulation of the argument tag leads to cross sit…
- CVE-2025-5412MEDIUMCVSS 5.4EG 5.42025-06-02
A vulnerability classified as problematic has been found in Mist Community Edition up to 4.7.1. Affected is the function Login of the file src/mist/api/views.py of the component Authentication Endpoint. The manipulation of the argument ret…
- CVE-2025-5420MEDIUMCVSS 5.4EG 5.42025-06-02
A vulnerability classified as problematic was found in juzaweb CMS up to 3.4.2. Affected by this vulnerability is an unknown functionality of the file /admin-cp/file-manager/upload of the component Profile Page. The manipulation of the arg…
- CVE-2025-54322CRITICALCVSS 10.0EG 10.02025-12-27
Xspeeder SXZOS through 2025-12-26 allows root remote code execution via base64-encoded Python code in the chkid parameter to vLogin.py. The title and oIP parameters are also used.
- CVE-2025-54374HIGHCVSS 8.8EG 8.82025-10-03
Eidos is an extensible framework for Personal Data Management. Versions 0.21.0 and below contain a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted eidos: URL on any…
- CVE-2025-54417HIGHCVSS 8.8EG 8.82025-08-09
Craft is a platform for creating digital experiences. Versions 4.13.8 through 4.16.2 and 5.5.8 through 5.8.3 contain a vulnerability that can bypass CVE-2025-23209: "Craft CMS has a potential RCE with a compromised security key". To exploi…
- CVE-2025-54451CRITICALCVSS 9.8EG 9.82025-07-23
Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.
- CVE-2025-54466CRITICALCVSS 9.8EG 9.82025-08-15
Improper Control of Generation of Code ('Code Injection') vulnerability leading to a possible RCE in Apache OFBiz scrum plugin. This issue affects Apache OFBiz: before 24.09.02 only when the scrum plugin is used. Even unauthenticated a…
- CVE-2025-54550HIGHCVSS 8.1EG 8.12026-04-15
The example example_xcom that was included in airflow documentation implemented unsafe pattern of reading value from xcom in the way that could be exploited to allow UI user who had access to modify XComs to perform arbitrary execution of…
- CVE-2025-54593HIGHCVSS 7.2EG 7.22025-08-01
FreshRSS is a free, self-hostable RSS aggregator. In versions 1.26.1 and below, an authenticated administrator user can execute arbitrary code on the FreshRSS server by modifying the update URL to one they control, and gain code execution …
- CVE-2025-54594CRITICALCVSS 9.1EG 9.12025-08-06
react-native-bottom-tabs is a library of Native Bottom Tabs for React Native. In versions 0.9.2 and below, the github/workflows/release-canary.yml GitHub Actions repository workflow improperly used the pull_request_target event trigger, wh…
- CVE-2025-54731HIGHCVSS 8.1EG 8.12025-08-28
Improper Control of Generation of Code ('Code Injection') vulnerability in emarket-design YouTube Showcase youtube-showcase allows Object Injection.This issue affects YouTube Showcase: from n/a through <= 3.5.1.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →