CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,137 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 111 of 143
- CVE-2025-61774CRITICALCVSS 9.3EG 9.32025-10-06
PyVista provides 3D plotting and mesh analysis through an interface for the Visualization Toolkit (VTK). Version 0.46.3 of the PyVista Project is vulnerable to remote code execution via dependency confusion. Two pieces of code use`--extra-…
- CVE-2025-61927HIGHCVSS 7.2EG 7.22025-10-10
Happy DOM is a JavaScript implementation of a web browser without its graphical user interface. Happy DOM v19 and lower contains a security vulnerability that puts the owner system at the risk of RCE (Remote Code Execution) attacks. A Node…
- CVE-2025-61929CRITICALCVSS 9.6EG 9.62025-10-10
Cherry Studio is a desktop client that supports for multiple LLM providers. Cherry Studio registers a custom protocol called `cherrystudio://`. When handling the MCP installation URL, it parses the base64-encoded configuration data and dir…
- CVE-2025-61937CRITICALCVSS 10.0EG 10.02026-01-16
The vulnerability, if exploited, could allow an unauthenticated miscreant to achieve remote code execution under OS system privileges of “taoimr” service, potentially resulting in complete compromise of the model application server.
- CVE-2025-61982HIGHCVSS 7.8EG 7.82026-02-18
An arbitrary code execution vulnerability exists in the Code Stream directive functionality of OpenCFD OpenFOAM 2506. A specially crafted OpenFOAM simulation file can lead to arbitrary code execution. An attacker can provide a malicious fi…
- CVE-2025-62023CRITICALCVSS 9.0EG 9.82025-10-22
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member.This issue affects s2Member: from n/a through <= 250905.
- CVE-2025-6204CRITICALCVSS 8.0EG 9.0⚠ KEV2025-08-04
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
- CVE-2025-6213HIGHCVSS 7.2EG 7.22025-07-22
The Nginx Cache Purge Preload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.1.1 via the 'nppp_preload_cache_on_update' function. This is due to insufficient sanitization of the $_SERVER…
- CVE-2025-62348HIGHCVSS 7.8EG 7.82026-01-30
Salt's junos execution module contained an unsafe YAML decode/load usage. A specially crafted YAML payload processed by the junos module could lead to unintended code execution under the context of the Salt process.
- CVE-2025-62369HIGHCVSS 7.2EG 7.22025-11-04
Xibo is an open source digital signage platform with a web content management system (CMS). Versions 4.3.0 and below contain a Remote Code Execution vulnerability in the CMS Developer menu's Module Templating functionality, allowing authen…
- CVE-2025-62416MEDIUMCVSS 6.8EG 6.82025-10-16
Bagisto is an open source laravel eCommerce platform. Bagisto v2.3.7 is vulnerable to Server-Side Template Injection (SSTI) due to unsanitized user input being processed by the server-side templating engine when rendering product descripti…
- CVE-2025-62429HIGHCVSS 7.2EG 7.22025-10-20
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.2 #147, ClipBucket v5 is vulnerable to arbitrary PHP code execution. In /upload/admin_area/actions/update_launch.php, the "type" parameter from a POST request is …
- CVE-2025-62521CRITICALCVSS 10.0EG 10.02025-12-17
ChurchCRM is an open-source church management system. Prior to version 5.21.0, a pre-authentication remote code execution vulnerability in ChurchCRM's setup wizard allows unauthenticated attackers to inject arbitrary PHP code during the in…
- CVE-2025-62593CRITICALCVSS 8.8EG 9.0⚠ KEV2025-11-26
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guar…
- CVE-2025-6268MEDIUMCVSS 4.3EG 4.32025-06-19
A vulnerability classified as problematic has been found in Luna Imaging up to 7.5.5.6. Affected is an unknown function of the file /luna/servlet/view/search. The manipulation of the argument q leads to cross site scripting. It is possible…
- CVE-2025-6285MEDIUMCVSS 6.1EG 6.12025-06-19
A vulnerability was found in PHPGurukul COVID19 Testing Management System 2021. It has been rated as problematic. This issue affects some unknown processing of the file /search-report-result.php. The manipulation of the argument q leads to…
- CVE-2025-6287MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability classified as problematic was found in PHPGurukul COVID19 Testing Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /test-details.php of the component Take Action. The manipulatio…
- CVE-2025-6288MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability, which was classified as problematic, has been found in PHPGurukul Bus Pass Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/admin-profile.php of the component Profile Page. The…
- CVE-2025-62959CRITICALCVSS 9.1EG 9.12025-10-27
Improper Control of Generation of Code ('Code Injection') vulnerability in videowhisper Paid Videochat Turnkey Site ppv-live-webcams allows Remote Code Inclusion.This issue affects Paid Videochat Turnkey Site: from n/a through <= 7.3.23.
- CVE-2025-6301MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability, which was classified as problematic, has been found in PHPGurukul Notice Board System 1.0. This issue affects some unknown processing of the file /admin/manage-notices.php of the component Add Notice. The manipulation of t…
- CVE-2025-6340MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability classified as problematic has been found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /branch.php. The manipulation of the argument Branch/Address/Detail leads to cross site scri…
- CVE-2025-63421HIGHCVSS 7.8EG 7.82026-02-12
An issue in filosoft Comerc.32 Commercial Invoicing v.16.0.0.3 allows a local attacker to execute arbitrary code via the comeinst.exe file
- CVE-2025-6345MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability was found in SourceCodester My Food Recipe 1.0 and classified as problematic. Affected by this issue is the function addRecipeModal of the file /endpoint/add-recipe.php of the component Add Recipe Page. The manipulation of …
- CVE-2025-6347MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability was found in code-projects Responsive Blog 1.0/1.12.4/3.3.4. It has been declared as problematic. This vulnerability affects unknown code of the file /responsive/resblog/blogadmin/admin/pageViewMembers.php. The manipulation…
- CVE-2025-6353MEDIUMCVSS 5.4EG 5.42025-06-20
A vulnerability classified as problematic was found in code-projects Responsive Blog 1.0. Affected by this vulnerability is an unknown functionality of the file /search.php. The manipulation of the argument keyword leads to cross site scri…
- CVE-2025-63665CRITICALCVSS 9.8EG 9.82025-12-19
An issue in GT Edge AI Community Edition Versions before v2.0.12 allows attackers to execute arbitrary code via injecting a crafted JSON payload into the Prompt window.
- CVE-2025-63693MEDIUMCVSS 5.4EG 5.42025-11-18
The comment editing template (dzz/comment/template/edit_form.htm) in DzzOffice 2.3.x lacks adequate security escaping for user-controllable data in multiple contexts, including HTML and JavaScript strings. This allows low-privilege attacke…
- CVE-2025-63706CRITICALCVSS 9.8EG 9.82026-05-07
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
- CVE-2025-6389CRITICALCVSS 9.8EG 9.82025-11-25
The Sneeit Framework plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 8.3 via the sneeit_articles_pagination_callback() function. This is due to the function accepting user input and then pa…
- CVE-2025-64050HIGHCVSS 7.2EG 7.22025-11-25
A Remote Code Execution (RCE) vulnerability in the template management component in REDAXO CMS 5.20.0 allows remote authenticated administrators to execute arbitrary operating system commands by injecting PHP code into an active template. …
- CVE-2025-64108HIGHCVSS 8.8EG 8.82025-11-04
Cursor is a code editor built for programming with AI. In versions 1.7.44 and below, various NTFS path quirks allow a prompt injection attacker to circumvent sensitive file protections and overwrite files which Cursor requires human approv…
- CVE-2025-64318MEDIUMCVSS 5.3EG 6.52025-11-04
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Mulesoft Anypoint Code Builder allows Manipulating Writeable Configuration Files.This issue affects Mulesoft Anypoint Code Builder: before 1.12.1.
- CVE-2025-64320MEDIUMCVSS 6.5EG 6.52025-11-04
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Code Injection.This issue affects Agentforce Vibes Extension: before 3.2.0.
- CVE-2025-64321MEDIUMCVSS 5.3EG 5.32025-11-04
Improper Neutralization of Input Used for LLM Prompting vulnerability in Salesforce Agentforce Vibes Extension allows Manipulating Writeable Configuration Files.This issue affects Agentforce Vibes Extension: before 3.3.0.
- CVE-2025-6452MEDIUMCVSS 4.8EG 4.82025-06-22
A vulnerability was found in CodeAstro Patient Record Management System 1.0. It has been rated as problematic. This issue affects some unknown processing of the component Generate New Report Page. The manipulation of the argument Patient N…
- CVE-2025-64676HIGHCVSS 7.2EG 7.22025-12-18
'.../...//' in Microsoft Purview allows an authorized attacker to execute code over a network.
- CVE-2025-64691HIGHCVSS 8.8EG 8.82026-01-16
The vulnerability, if exploited, could allow an authenticated miscreant (OS standard user) to tamper with TCL Macro scripts and escalate privileges to OS system, potentially resulting in complete compromise of the model application serv…
- CVE-2025-6473MEDIUMCVSS 6.1EG 6.12025-06-22
A vulnerability, which was classified as problematic, was found in code-projects School Fees Payment System 1.0. This affects an unknown part of the file /fees.php. The manipulation of the argument transcation_remark leads to cross site sc…
- CVE-2025-6475MEDIUMCVSS 4.8EG 4.82025-06-22
A vulnerability was found in SourceCodester Student Result Management System 1.0 and classified as problematic. This issue affects some unknown processing of the file /script/admin/manage_students of the component Manage Students Module. T…
- CVE-2025-6477MEDIUMCVSS 4.8EG 4.82025-06-22
A vulnerability was found in SourceCodester Student Result Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /script/admin/system of the component System Sett…
- CVE-2025-65026CRITICALCVSS 9.6EG 9.62025-11-19
esm.sh is a nobuild content delivery network(CDN) for modern web development. Prior to version 136, The esm.sh CDN service contains a Template Literal Injection vulnerability (CWE-94) in its CSS-to-JavaScript module conversion feature. Whe…
- CVE-2025-65037CRITICALCVSS 10.0EG 10.02025-12-18
Improper control of generation of code ('code injection') in Azure Container Apps allows an unauthorized attacker to execute code over a network.
- CVE-2025-6509LOWCVSS 3.5EG 3.52025-06-23
A vulnerability was found in seaswalker spring-analysis up to 4379cce848af96997a9d7ef91d594aa129be8d71. It has been declared as problematic. Affected by this vulnerability is the function echo of the file /src/main/java/controller/SimpleCo…
- CVE-2025-65099CRITICALCVSS 9.8EG 9.82025-11-19
Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the star…
- CVE-2025-65108CRITICALCVSS 10.0EG 10.02025-11-21
md-to-pdf is a CLI tool for converting Markdown files to PDF using Node.js and headless Chrome. Prior to version 5.2.5, a Markdown front-matter block that contains JavaScript delimiter causes the JS engine in gray-matter library to execute…
- CVE-2025-6512CRITICALCVSS 10.0EG 10.02025-06-23
On a client with a non-admin user, a script can be integrated into a report. The reports could later be executed on the BRAIN2 server with administrator rights.
- CVE-2025-65271HIGHCVSS 8.8EG 8.82025-12-08
Client-side template injection (CSTI) in Azuriom CMS admin dashboard allows a low-privilege user to execute arbitrary template code in the context of an administrator's session. This can occur via plugins or dashboard components that rende…
- CVE-2025-65294CRITICALCVSS 9.8EG 9.82025-12-10
Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.
- CVE-2025-6551MEDIUMCVSS 5.4EG 5.42025-06-24
A vulnerability was found in java-aodeng Hope-Boot 1.0.0 and classified as problematic. This issue affects the function Login of the file /src/main/java/com/hope/controller/WebController.java. The manipulation of the argument errorMsg lead…
- CVE-2025-65602CRITICALCVSS 9.8EG 9.82025-12-10
A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →