CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 110 of 143
- CVE-2025-58372HIGHCVSS 8.1EG 8.12025-09-05
Roo Code is an AI-powered autonomous coding agent that lives in users' editors. Versions 3.25.23 and below contain a vulnerability where certain VS Code workspace configuration files (.code-workspace) are not protected in the same way as t…
- CVE-2025-58673MEDIUMCVSS 5.4EG 5.42025-09-22
Improper Control of Generation of Code ('Code Injection') vulnerability in weDevs WP User Frontend wp-user-frontend allows Code Injection.This issue affects WP User Frontend: from n/a through <= 4.1.12.
- CVE-2025-58745CRITICALCVSS 9.9EG 9.92025-09-08
WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at endpoint `/html/socio/sistema/controller…
- CVE-2025-58764CRITICALCVSS 9.8EG 9.82025-09-10
Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this …
- CVE-2025-58766CRITICALCVSS 9.0EG 9.02025-09-17
Dyad is a local AI app builder. A critical security vulnerability has been discovered that affected Dyad v0.19.0 and earlier versions that allows attackers to execute arbitrary code on users' systems. The vulnerability affects the applicat…
- CVE-2025-58768CRITICALCVSS 9.6EG 9.62025-09-09
DeepChat is a smart assistant uses artificial intelligence. Prior to version 0.3.5, in the Mermaid chart rendering component, there is a risky operation of directly using `innerHTML` to set user content. Therefore, any malicious content re…
- CVE-2025-5879MEDIUMCVSS 5.4EG 5.42025-06-09
A vulnerability, which was classified as problematic, was found in WuKongOpenSource WukongCRM 9.0. This affects an unknown part of the file AdminSysConfigController.java of the component File Upload. The manipulation of the argument File l…
- CVE-2025-58827LOWCVSS 3.8EG 3.82025-09-05
Improper Control of Generation of Code ('Code Injection') vulnerability in PickPlugins Job Board Manager job-board-manager allows Code Injection.This issue affects Job Board Manager: from n/a through <= 2.1.61.
- CVE-2025-5884MEDIUMCVSS 5.4EG 5.42025-06-09
A vulnerability, which was classified as problematic, was found in Konica Minolta bizhub up to 20250202. This affects an unknown part of the component Display MFP Information List. The manipulation of the argument Model Name leads to cross…
- CVE-2025-5886MEDIUMCVSS 4.1EG 4.12025-06-09
A vulnerability was found in Emlog up to 2.5.7 and classified as problematic. This issue affects some unknown processing of the file /admin/article.php. The manipulation of the argument active_post leads to cross site scripting. The attack…
- CVE-2025-5887MEDIUMCVSS 5.4EG 5.42025-06-09
A vulnerability was found in jsnjfz WebStack-Guns 1.0. It has been classified as problematic. Affected is an unknown function of the file UserMgrController.java of the component File Upload. The manipulation of the argument File leads to c…
- CVE-2025-59041CRITICALCVSS 9.8EG 9.82025-09-10
Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execu…
- CVE-2025-59042HIGHCVSS 7.0EG 7.02025-09-09
PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script …
- CVE-2025-59053CRITICALCVSS 9.6EG 9.62025-09-11
AIRI is a self-hosted, artificial intelligence based Grok Companion. In v0.7.2-beta.2 in the `packages/stage-ui/src/components/MarkdownRenderer.vue` path, the Markdown content is processed using the useMarkdown composable, and the processe…
- CVE-2025-59059CRITICALCVSS 9.8EG 9.82026-03-03
Remote Code Execution Vulnerability in NashornScriptEngineCreator is reported in Apache Ranger versions <= 2.7.0. Users are recommended to upgrade to version 2.8.0, which fixes this issue.
- CVE-2025-59251HIGHCVSS 7.6EG 7.62025-09-24
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2025-59302MEDIUMCVSS 4.7EG 4.72025-11-27
In Apache CloudStack improper control of generation of code ('Code Injection') vulnerability is found in the following APIs which are accessible only to admins. * quotaTariffCreate * quotaTariffUpdate * createSecondaryStorageSel…
- CVE-2025-59528CRITICALCVSS 10.0EG 10.02025-09-22
Flowise is a drag & drop user interface to build a customized large language model flow. In version 3.0.5, Flowise is vulnerable to remote code execution. The CustomMCP node allows users to input configuration settings for connecting to an…
- CVE-2025-59536HIGHCVSS 8.8EG 8.82025-10-03
Claude Code is an agentic coding tool. Versions before 1.0.111 were vulnerable to Code Injection due to a bug in the startup trust dialog implementation. Claude Code could be tricked to execute code contained in a project before the user a…
- CVE-2025-5970LOWCVSS 2.4EG 2.42025-06-10
A vulnerability was found in PHPGurukul Restaurant Table Booking System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /admin/add-subadmin.php. The manipulation of the argument fullname …
- CVE-2025-5972LOWCVSS 2.4EG 2.42025-06-10
A vulnerability classified as problematic has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected is an unknown function of the file /admin/manage-subadmins.php. The manipulation of the argument fullname leads to cross s…
- CVE-2025-5973LOWCVSS 2.4EG 2.42025-06-10
A vulnerability classified as problematic was found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add-table.php. The manipulation of the argument tableno le…
- CVE-2025-5974LOWCVSS 3.5EG 3.52025-06-10
A vulnerability, which was classified as problematic, has been found in PHPGurukul Restaurant Table Booking System 1.0. Affected by this issue is some unknown functionality of the file /check-status.php. The manipulation of the argument se…
- CVE-2025-5975MEDIUMCVSS 4.3EG 4.32025-06-10
A vulnerability, which was classified as problematic, was found in PHPGurukul Rail Pass Management System 1.0. This affects an unknown part of the file /rpms/download-pass.php. The manipulation of the argument searchdata leads to cross sit…
- CVE-2025-5976LOWCVSS 3.5EG 3.52025-06-10
A vulnerability has been found in PHPGurukul Rail Pass Management System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/add-pass.php. The manipulation of the argument fullname leads to cross s…
- CVE-2025-59823CRITICALCVSS 9.9EG 9.92025-09-25
Project Gardener implements the automated management and operation of Kubernetes clusters as a service. Code injection may be possible in Gardener Extensions for AWS providers prior to version 1.64.0, Azure providers prior to version 1.55.…
- CVE-2025-5984LOWCVSS 3.5EG 3.52025-06-10
A vulnerability has been found in SourceCodester Online Student Clearance System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Admin/add-fee.php. The manipulation of the argument…
- CVE-2025-59952HIGHCVSS 8.7EG 8.72025-09-30
MinIO Java SDK is a Simple Storage Service (aka S3) client to perform bucket and object operations to any Amazon S3 compatible object storage service. In minio-java versions prior to 8.6.0, XML tag values containing references to system pr…
- CVE-2025-59954CRITICALCVSS 9.8EG 9.82025-09-30
Knowage is an open source analytics and business intelligence suite. Versions 8.1.26 and below are vulnerable to Remote Code Exection through using an unsafe org.apache.commons.jxpath.JXPathContext in MetaService.java service. This issue i…
- CVE-2025-6000CRITICALCVSS 9.1EG 9.12025-08-01
A privileged Vault operator within the root namespace with write permission to {{sys/audit}} may obtain code execution on the underlying host if a plugin directory is set in Vault’s configuration. Fixed in Vault Community Edition 1.20.1 …
- CVE-2025-60068MEDIUMCVSS 6.5EG 6.52025-12-18
Improper Control of Generation of Code ('Code Injection') vulnerability in javothemes Javo Core javo-core allows Code Injection.This issue affects Javo Core: from n/a through <= 3.0.0.266.
- CVE-2025-60070MEDIUMCVSS 6.5EG 6.52025-12-18
Improper Control of Generation of Code ('Code Injection') vulnerability in The4 Molla molla allows Code Injection.This issue affects Molla: from n/a through <= 1.5.13.
- CVE-2025-60114MEDIUMCVSS 6.6EG 6.62025-09-26
Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1.
- CVE-2025-60206CRITICALCVSS 10.0EG 10.02025-10-22
Improper Control of Generation of Code ('Code Injection') vulnerability in Beplusthemes Alone alone allows Code Injection.This issue affects Alone: from n/a through <= 7.8.3.
- CVE-2025-60785HIGHCVSS 8.8EG 8.82025-11-03
A remote code execution (RCE) vulnerability in the Postgres Drivers component of iceScrum v7.54 Pro On-prem allows attackers to execute arbitrary code via a crafted HTML page.
- CVE-2025-6092MEDIUMCVSS 4.3EG 4.32025-06-15
A vulnerability was found in comfyanonymous comfyui up to 0.3.39. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /upload/image of the component Incomplete Fix CVE-2024-10099. The…
- CVE-2025-6101MEDIUMCVSS 5.5EG 5.52025-06-16
A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to impr…
- CVE-2025-61136HIGHCVSS 7.1EG 7.12025-10-23
A Host Header Injection vulnerability in the password reset component in axewater sharewarez v2.4.3 allows remote attackers to conduct password reset poisoning and account takeover via manipulation of the Host header when Flask's url_for(_…
- CVE-2025-61196HIGHCVSS 8.8EG 8.82025-10-30
An issue in BusinessNext CRMnext v.10.8.3.0 allows a remote attacker to execute arbitrary code via the comments input parameter.
- CVE-2025-6125MEDIUMCVSS 5.4EG 5.42025-06-16
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/aboutus.php. The manipulation of the argument pagedes leads to cross site sc…
- CVE-2025-6126MEDIUMCVSS 5.4EG 5.42025-06-16
A vulnerability was found in PHPGurukul Rail Pass Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /contact.php. The manipulation of the argument Name leads …
- CVE-2025-61260CRITICALCVSS 9.8EG 9.82026-04-14
A vulnerability was identified in OpenAI Codex CLI v0.23.0 and before that enables code execution through malicious MCP (Model Context Protocol) configuration files. The attack is triggered when a user runs the codex command inside a malic…
- CVE-2025-6127MEDIUMCVSS 5.4EG 5.42025-06-16
A vulnerability was found in PHPGurukul Nipah Virus Testing Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /search-report.php. The manipulation of the argument sera…
- CVE-2025-6131MEDIUMCVSS 4.8EG 4.82025-06-16
A vulnerability, which was classified as problematic, was found in CodeAstro Food Ordering System 1.0. Affected is an unknown function of the file /admin/store/edit/ of the component POST Request Parameter Handler. The manipulation of the …
- CVE-2025-61488HIGHCVSS 7.6EG 7.62025-10-20
An issue in Senayan Library Management System (SLiMS) 9 Bulian v.9.6.1 allows a remote attacker to execute arbitrary code via the scrap_image.php component and the imageURL parameter
- CVE-2025-61588CRITICALCVSS 9.3EG 9.32025-10-02
RISC Zero is a zero-knowledge verifiable general computing platform based on zk-STARKs and the RISC-V microarchitecture. In versions 2.0.2 and below of risc0-zkvm-platform, when the zkVM guest calls sys_read, the host is able to use a craf…
- CVE-2025-61590HIGHCVSS 7.5EG 7.52025-10-03
Cursor is a code editor built for programming with AI. Versions 1.6 and below are vulnerable to Remote Code Execution (RCE) attacks through Visual Studio Code Workspaces. Workspaces allow users to open more than a single folder and save sp…
- CVE-2025-61593HIGHCVSS 8.8EG 8.82025-10-03
Cursor is a code editor built for programming with AI. In versions 1.7 and below, a vulnerability in the way Cursor CLI Agent protects its sensitive files (i.e. */.cursor/cli.json) allows attackers to modify the content of the files throug…
- CVE-2025-61732HIGHCVSS 8.6EG 8.62026-02-05
A discrepancy between how Go and C/C++ comments were parsed allowed for code smuggling into the resulting cgo binary.
- CVE-2025-61773HIGHCVSS 8.1EG 8.12025-10-09
pyLoad is a free and open-source download manager written in Python. In versions prior to 0.5.0b3.dev91, pyLoad web interface contained insufficient input validation in both the Captcha script endpoint and the Click'N'Load (CNL) Blueprint.…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →