CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 109 of 143
- CVE-2025-54815HIGHCVSS 8.8EG 8.82025-09-19
Server-side template injection (SSTI) vulnerability in PPress 0.0.9 allows attackers to execute arbitrary code via crafted themes.
- CVE-2025-54940LOWCVSS 3.4EG 3.42025-08-08
An HTML injection vulnerability exists in WordPress plugin "Advanced Custom Fields" prior to 6.4.3. If this vulnerability is exploited, crafted HTML code may be rendered and page display may be tampered.
- CVE-2025-54997CRITICALCVSS 9.1EG 9.12025-08-09
OpenBao exists to provide a software solution to manage, store, and distribute sensitive data including secrets, certificates, and keys. In versions 2.3.1 and below, some OpenBao deployments intentionally limit privileged API operators fro…
- CVE-2025-5505LOWCVSS 2.4EG 2.42025-06-03
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011 and classified as problematic. This issue affects some unknown processing of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argum…
- CVE-2025-5506MEDIUMCVSS 5.4EG 5.42025-06-03
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been classified as problematic. Affected is an unknown function of the component NAT Mapping Page. The manipulation of the argument Comment leads to cross site scri…
- CVE-2025-5507MEDIUMCVSS 5.4EG 5.42025-06-03
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component MAC Filtering Page. The manipulation of the argument Comme…
- CVE-2025-5508LOWCVSS 3.4EG 3.42025-06-03
A vulnerability was found in TOTOLINK A3002RU 2.1.1-B20230720.1011. It has been rated as problematic. Affected by this issue is some unknown functionality of the component IP Port Filtering Page. The manipulation of the argument Comment le…
- CVE-2025-5513MEDIUMCVSS 5.4EG 5.42025-06-03
A vulnerability has been found in quequnlong shiyi-blog up to 1.2.1 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /dev-api/api/comment/add. The manipulation of the argument content le…
- CVE-2025-5516MEDIUMCVSS 4.8EG 4.82025-06-03
A vulnerability, which was classified as problematic, was found in TOTOLINK X2000R 1.0.0-B20230726.1108. This affects an unknown part of the file /boafrm/formFilter of the component URL Filtering Page. The manipulation of the argument URL …
- CVE-2025-55192HIGHCVSS 8.6EG 8.62025-08-14
HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect user…
- CVE-2025-55204CRITICALCVSS 9.6EG 9.62026-01-05
muffon is a cross-platform music streaming client for desktop. Versions prior to 2.3.0 have a one-click Remote Code Execution (RCE) vulnerability in. An attacker can exploit this issue by embedding a specially crafted `muffon://` link on a…
- CVE-2025-5523MEDIUMCVSS 6.1EG 6.12025-06-03
A vulnerability classified as problematic has been found in enilu web-flash 1.0. This affects the function fileService.upload of the file src/main/java/cn/enilu/flash/api/controller/FileController/upload of the component File Upload. The m…
- CVE-2025-55305MEDIUMCVSS 6.1EG 6.12025-09-04
Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. In versions below 35.7.5, 36.0.0-alpha.1 through 36.8.0, 37.0.0-alpha.1 through 37.3.1 and 38.0.0-alpha.1 through 38.0.0-beta.6, ASAR I…
- CVE-2025-55313HIGHCVSS 7.8EG 7.82025-12-11
An issue was discovered in Foxit PDF and Editor for Windows and macOS before 13.2 and 2025 before 2025.2. They allow potential arbitrary code execution when processing crafted PDF files. The vulnerability stems from insufficient handling o…
- CVE-2025-55346CRITICALCVSS 9.8EG 9.82025-08-14
User-controlled input flows to an unsafe implementation of a dynamic Function constructor, allowing network attackers to run arbitrary unsandboxed JS code in the context of the host, by sending a simple POST request.
- CVE-2025-5542MEDIUMCVSS 4.8EG 4.82025-06-03
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been classified as problematic. Affected is an unknown function of the file /boafrm/formPortFw of the component Virtual Server Page. The manipulation of the argument…
- CVE-2025-55423CRITICALCVSS 9.8EG 9.82026-01-20
A command injection vulnerability exists in the upnp_relay() function in multiple ipTIME router models because the controlURL value used to pass port-forwarding information to an upper router is passed to system() without proper validation…
- CVE-2025-5543MEDIUMCVSS 4.8EG 4.82025-06-03
A vulnerability was found in TOTOLINK X2000R 1.0.0-B20230726.1108. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Parent Controls Page. The manipulation of the argument Devi…
- CVE-2025-55727CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the width parameter in the column macro allows remote code…
- CVE-2025-55728CRITICALCVSS 10.0EG 10.02025-09-09
XWiki Remote Macros provides XWiki rendering macros that are useful when migrating content from Confluence. Starting in version 1.0 and prior to version 1.26.5, missing escaping of the classes parameter in the panel macro allows remote cod…
- CVE-2025-55733CRITICALCVSS 9.6EG 9.62025-08-19
DeepChat is a smart assistant that connects powerful AI to your personal world. DeepChat before 0.3.1 has a one-click remote code execution vulnerability. An attacker can exploit this vulnerability by embedding a specially crafted deepcha…
- CVE-2025-5584MEDIUMCVSS 5.4EG 5.42025-06-04
A vulnerability was found in PHPGurukul Hospital Management System 4.0. It has been classified as problematic. Affected is an unknown function of the file /doctor/edit-patient.php?editid=2 of the component POST Parameter Handler. The manip…
- CVE-2025-5628MEDIUMCVSS 5.4EG 5.42025-06-05
A vulnerability, which was classified as problematic, has been found in SourceCodester Food Menu Manager 1.0. Affected by this issue is some unknown functionality of the file /index.php of the component Add Menu Handler. The manipulation o…
- CVE-2025-56399HIGHCVSS 8.8EG 8.82025-10-28
alexusmai laravel-file-manager 3.3.1 and before allows an authenticated attacker to achieve Remote Code Execution (RCE) through a crafted file upload. A file with a '.png` extension containing PHP code can be uploaded via the file manager …
- CVE-2025-5651MEDIUMCVSS 5.4EG 5.42025-06-05
A vulnerability, which was classified as problematic, has been found in code-projects Traffic Offense Reporting System 1.0. This issue affects some unknown processing of the file saveuser.php. The manipulation of the argument user_id/usern…
- CVE-2025-56588HIGHCVSS 8.8EG 8.82025-10-01
Dolibarr ERP & CRM v21.0.1 were discovered to contain a remote code execution (RCE) vulnerability in the User module configuration via the computed field parameter.
- CVE-2025-5661MEDIUMCVSS 5.4EG 5.42025-06-05
A vulnerability, which was classified as problematic, was found in code-projects Traffic Offense Reporting System 1.0. This affects an unknown part of the file /save-settings.php of the component Setting Handler. The manipulation of the ar…
- CVE-2025-5713MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in SoluçõesCoop iSoluçõesWEB up to 20250519 and classified as problematic. Affected by this issue is some unknown functionality of the file /fluxos-dashboard of the component Flow Handler. The manipulation of …
- CVE-2025-57141CRITICALCVSS 9.8EG 9.82025-09-08
rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.
- CVE-2025-5717MEDIUMCVSS 6.8EG 6.82025-09-23
An authenticated remote code execution (RCE) vulnerability exists in multiple WSO2 products due to improper input validation in the event processor admin service. A user with administrative access to the SOAP admin services can exploit thi…
- CVE-2025-5721MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability, which was classified as problematic, was found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/core/update_profile of the component Profile Setting Page. Th…
- CVE-2025-5722MEDIUMCVSS 4.8EG 4.82025-06-06
A vulnerability has been found in SourceCodester Student Result Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /script/academic/terms of the component Add Academic Term. The manipul…
- CVE-2025-5723MEDIUMCVSS 4.8EG 4.82025-06-06
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/academic/classes of the component Classes Page. The manipulation…
- CVE-2025-5724MEDIUMCVSS 4.8EG 4.82025-06-06
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /script/academic/subjects of the component Subjects Page. The manipulation…
- CVE-2025-5725MEDIUMCVSS 4.8EG 4.82025-06-06
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/academic/grading-system of the component …
- CVE-2025-5726MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /script/academic/division-system of the component Division…
- CVE-2025-5727MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability classified as problematic has been found in SourceCodester Student Result Management System 1.0. This affects an unknown part of the file /script/academic/announcement of the component Announcement Page. The manipulation of…
- CVE-2025-57283HIGHCVSS 7.8EG 7.82026-01-28
The Node.js package browserstack-local 1.5.8 contains a command injection vulnerability. This occurs because the logfile variable is not properly sanitized in lib/Local.js.
- CVE-2025-57439HIGHCVSS 8.8EG 8.82025-09-22
Creacast Creabox Manager 4.4.4 contains a critical Remote Code Execution vulnerability accessible via the edit.php endpoint. An authenticated attacker can inject arbitrary Lua code into the configuration, which is then executed on the serv…
- CVE-2025-57567CRITICALCVSS 9.1EG 9.12025-10-17
A remote code execution (RCE) vulnerability exists in the PluXml CMS theme editor, specifically in the minify.php file located under the default theme directory (/themes/defaut/css/minify.php). An authenticated administrator user can overw…
- CVE-2025-5757MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in code-projects Traffic Offense Reporting System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /save-reported.php. The manipulation of the argument offenc…
- CVE-2025-5764MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /data/insert_laundry.php. The manipulation of the argument Customer leads to cros…
- CVE-2025-57644CRITICALCVSS 9.1EG 9.12025-09-19
Accela Automation Platform 22.2.3.0.230103 contains multiple vulnerabilities in the Test Script feature. An authenticated administrative user can execute arbitrary Java code on the server, resulting in remote code execution. In addition, i…
- CVE-2025-5765MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in code-projects Laundry System 1.0. It has been classified as problematic. This affects an unknown part of the file /data/edit_laundry.php. The manipulation of the argument Customer leads to cross site scripting.…
- CVE-2025-57772CRITICALCVSS 9.8EG 9.82025-08-25
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, there is a H2 JDBC RCE bypass in DataEase. If the JDBC URL meets criteria, the getJdbcUrl method is returned, which acts as the getter …
- CVE-2025-57773CRITICALCVSS 9.8EG 9.82025-08-25
DataEase is an open source business intelligence and data visualization tool. Prior to version 2.10.12, because DB2 parameters are not filtered, a JNDI injection attack can be directly launched. JNDI triggers an AspectJWeaver deserializati…
- CVE-2025-5796MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability has been found in code-projects Laundry System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /data/edit_type.php. The manipulation of the argument Type leads to cross site scripting.…
- CVE-2025-5797MEDIUMCVSS 5.4EG 5.42025-06-06
A vulnerability was found in code-projects Laundry System 1.0 and classified as problematic. This issue affects some unknown processing of the file /data/insert_type.php. The manipulation of the argument Type leads to cross site scripting.…
- CVE-2025-58159CRITICALCVSS 9.9EG 9.92025-08-29
WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validation of uploaded files. The application allows an attacker to upload files with arb…
- CVE-2025-58176HIGHCVSS 8.8EG 8.82025-09-03
Dive is an open-source MCP Host Desktop Application that enables integration with function-calling LLMs. In versions 0.9.0 through 0.9.3, there is a one-click Remote Code Execution vulnerability triggered through a custom url value, `trans…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →