CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,135 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 99 of 143
- CVE-2025-1585LOWCVSS 2.4EG 2.42025-02-23
A vulnerability, which was classified as problematic, has been found in otale tale up to 2.0.5. This issue affects the function OptionsService of the file src/main/resources/templates/themes/default/partial/header.html. The manipulation of…
- CVE-2025-1586LOWCVSS 3.5EG 3.52025-02-23
A vulnerability was found in code-projects Blood Bank System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /Blood/A-.php. The manipulation of the argument Bloodname leads to cross site script…
- CVE-2025-1589MEDIUMCVSS 4.3EG 4.32025-02-23
A vulnerability was found in SourceCodester E-Learning System 1.0 and classified as problematic. This issue affects some unknown processing of the file /register.php of the component User Registration Handler. The manipulation leads to cro…
- CVE-2025-1591LOWCVSS 2.4EG 2.42025-02-23
A vulnerability was found in SourceCodester Employee Management System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /department.php of the component Department Page. The m…
- CVE-2025-1592LOWCVSS 2.4EG 2.42025-02-23
A vulnerability was found in SourceCodester Best Employee Management System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/Operations/Role.php of the component Add Role Page. …
- CVE-2025-1597LOWCVSS 3.5EG 3.52025-02-23
A vulnerability was found in SourceCodester Best Church Management Software 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/redirect.php. The manipulation of the argument a leads to cross site…
- CVE-2025-1612LOWCVSS 3.5EG 3.52025-02-24
A vulnerability was found in Edimax BR-6288ACL 1.30. It has been declared as problematic. This vulnerability affects unknown code of the file wireless5g_basic.asp. The manipulation of the argument SSID leads to cross site scripting. The at…
- CVE-2025-1613LOWCVSS 2.4EG 2.42025-02-24
A vulnerability was found in FiberHome AN5506-01A ONU GPON RP2511. It has been rated as problematic. This issue affects some unknown processing of the file /goform/URL_filterCfg of the component URL Filtering Submenu. The manipulation of t…
- CVE-2025-1614LOWCVSS 2.4EG 2.42025-02-24
A vulnerability classified as problematic has been found in FiberHome AN5506-01A ONU GPON RP2511. Affected is an unknown function of the file /goform/portForwardingCfg of the component Port Forwarding Submenu. The manipulation of the argum…
- CVE-2025-1615LOWCVSS 2.4EG 2.42025-02-24
A vulnerability classified as problematic was found in FiberHome AN5506-01A ONU GPON RP2511. Affected by this vulnerability is an unknown functionality of the component NAT Submenu. The manipulation of the argument Description leads to cro…
- CVE-2025-1617LOWCVSS 2.4EG 2.42025-02-24
A vulnerability, which was classified as problematic, was found in Netis WF2780 2.1.41925. This affects an unknown part of the component Wireless 2.4G Menu. The manipulation of the argument SSID leads to cross site scripting. It is possibl…
- CVE-2025-1618MEDIUMCVSS 4.3EG 4.32025-02-24
A vulnerability has been found in vTiger CRM 6.4.0/6.5.0 and classified as problematic. This vulnerability affects unknown code of the file /modules/Mobile/index.php. The manipulation of the argument _operation leads to cross site scriptin…
- CVE-2025-1742MEDIUMCVSS 4.3EG 4.32025-02-27
A vulnerability, which was classified as problematic, has been found in pihome-shc PiHome 2.0. Affected by this issue is some unknown functionality of the file /home.php. The manipulation of the argument page_name leads to cross site scrip…
- CVE-2025-1782CRITICALCVSS 9.9EG 9.92025-04-14
In HylaFAX Enterprise Web Interface and AvantFAX, the language form element is not properly sanitized before being used and can be misused to include an arbitrary file in the PHP code allowing an attacker to do anything as the web server…
- CVE-2025-1810MEDIUMCVSS 4.3EG 4.32025-03-02
A vulnerability was found in Pixsoft Vivaz 6.0.11. It has been classified as problematic. Affected is an unknown function of the file /servlet?act=login&submit=1&evento=0&pixrnd=0125021817031859360231 of the component Login Endpoint. The m…
- CVE-2025-1817LOWCVSS 2.4EG 2.42025-03-02
A vulnerability classified as problematic was found in Mini-Tmall up to 20250211. This vulnerability affects unknown code of the file /admin of the component Admin Name Handler. The manipulation leads to cross site scripting. The attack ca…
- CVE-2025-1830LOWCVSS 2.4EG 2.42025-03-02
A vulnerability was found in zj1983 zz up to 2024-8. It has been rated as problematic. This issue affects some unknown processing of the component Customer Information Handler. The manipulation of the argument Customer Name leads to cross …
- CVE-2025-1842MEDIUMCVSS 4.3EG 4.32025-03-03
A vulnerability classified as problematic was found in FITSTATS Technologies AthleteMonitoring up to 20250302. This vulnerability affects unknown code of the file /login.php. The manipulation of the argument username leads to cross site sc…
- CVE-2025-1892LOWCVSS 2.4EG 2.42025-03-04
A vulnerability was found in shishuocms 1.1. It has been classified as problematic. Affected is an unknown function of the file /manage/folder/add.json of the component Directory Deletion Page. The manipulation of the argument folderName l…
- CVE-2025-1904LOWCVSS 3.5EG 3.52025-03-04
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank System 1.0. Affected by this issue is some unknown functionality of the file /Blood/A+.php. The manipulation of the argument Availibility lead…
- CVE-2025-1905LOWCVSS 3.5EG 3.52025-03-04
A vulnerability, which was classified as problematic, was found in SourceCodester Employee Management System 1.0. This affects an unknown part of the file employee.php. The manipulation of the argument Full Name leads to cross site scripti…
- CVE-2025-1949MEDIUMCVSS 4.3EG 4.32025-03-04
A vulnerability, which was classified as problematic, has been found in ZZCMS 2025. This issue affects some unknown processing of the file /3/ucenter_api/code/register_nodb.php of the component URL Handler. The manipulation of the argument…
- CVE-2025-1955LOWCVSS 3.5EG 3.52025-03-04
A vulnerability was found in code-projects Online Class and Exam Scheduling System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /Scheduling/scheduling/pages/profile.php. The manipu…
- CVE-2025-1957LOWCVSS 3.5EG 3.52025-03-04
A vulnerability classified as problematic was found in code-projects Blood Bank System 1.0. This vulnerability affects unknown code of the file /BBfile/Blood/o+.php. The manipulation of the argument Bloodname leads to cross site scripting.…
- CVE-2025-1967LOWCVSS 3.5EG 3.52025-03-05
A vulnerability, which was classified as problematic, has been found in code-projects Blood Bank Management System 1.0. Affected by this issue is some unknown functionality of the file /user_dashboard/donor.php. The manipulation of the arg…
- CVE-2025-1976CRITICALCVSS 6.7EG 9.0⚠ KEV2025-04-24
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
- CVE-2025-1978HIGHCVSS 8.3EG 8.32026-05-07
Remote Code Execution Vulnerability in Hitachi Storage Navigator and the maintenance console in Hitachi Virtual Storage Platform G130, G150, G350, G370, G700, G900, F350, F370, F700, F900, Hitachi Virtual Storage Platform E390, E590, E790,…
- CVE-2025-2047LOWCVSS 3.5EG 3.52025-03-06
A vulnerability was found in PHPGurukul Art Gallery Management System 1.0. It has been classified as problematic. This affects an unknown part of the file /search.php. The manipulation of the argument search leads to cross site scripting. …
- CVE-2025-2049LOWCVSS 3.5EG 3.52025-03-06
A vulnerability classified as problematic has been found in code-projects Blood Bank System 1.0. Affected is an unknown function of the file AB+.php. The manipulation of the argument Bloodname leads to cross site scripting. It is possible …
- CVE-2025-2061MEDIUMCVSS 4.3EG 4.32025-03-07
A vulnerability was found in code-projects Online Ticket Reservation System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /passenger.php. The manipulation of the argument name leads to cross …
- CVE-2025-2084LOWCVSS 3.5EG 3.52025-03-07
A vulnerability was found in PHPGurukul Human Metapneumovirus Testing Management System 1.0. It has been classified as problematic. Affected is an unknown function of the file /search-report.php of the component Search Report Page. The man…
- CVE-2025-2085LOWCVSS 3.5EG 3.52025-03-07
A vulnerability classified as problematic has been found in StarSea99 starsea-mall 1.0. This affects an unknown part of the file /admin/carousels/save. The manipulation of the argument redirectUrl leads to cross site scripting. It is possi…
- CVE-2025-2086LOWCVSS 3.5EG 3.52025-03-07
A vulnerability classified as problematic was found in StarSea99 starsea-mall 1.0. This vulnerability affects unknown code of the file /admin/indexConfigs/update. The manipulation of the argument redirectUrl leads to cross site scripting. …
- CVE-2025-2087LOWCVSS 3.5EG 3.52025-03-07
A vulnerability, which was classified as problematic, has been found in StarSea99 starsea-mall 1.0. This issue affects some unknown processing of the file /admin/goods/update. The manipulation of the argument goodsName leads to cross site …
- CVE-2025-21187HIGHCVSS 7.8EG 7.82025-01-14
Microsoft Power Automate Remote Code Execution Vulnerability
- CVE-2025-2123LOWCVSS 3.5EG 3.52025-03-09
A vulnerability, which was classified as problematic, has been found in GeSHi up to 1.0.9.1. Affected by this issue is the function get_var of the file /contrib/cssgen.php of the component CSS Handler. The manipulation of the argument defa…
- CVE-2025-2124LOWCVSS 3.5EG 3.52025-03-09
A vulnerability, which was classified as problematic, was found in Control iD RH iD 25.2.25.0. This affects an unknown part of the file /v2/customerdb/person.svc/change_password of the component API Handler. The manipulation of the argumen…
- CVE-2025-2127MEDIUMCVSS 4.3EG 4.32025-03-09
A vulnerability was found in JoomlaUX JUX Real Estate 3.4.0 on Joomla. It has been classified as problematic. Affected is an unknown function of the file /extensions/realestate/index.php/properties/list/list-with-sidebar/realties. The mani…
- CVE-2025-21292HIGHCVSS 8.8EG 8.82025-01-14
Windows Search Service Elevation of Privilege Vulnerability
- CVE-2025-2130LOWCVSS 3.5EG 3.52025-03-09
A vulnerability was found in OpenXE up to 1.12. It has been declared as problematic. This vulnerability affects unknown code of the component Ticket Bearbeiten Page. The manipulation of the argument Notizen leads to cross site scripting. T…
- CVE-2025-2131LOWCVSS 2.4EG 2.42025-03-09
A vulnerability was found in dayrui XunRuiCMS up to 4.6.3. It has been rated as problematic. This issue affects some unknown processing of the component Friendly Links Handler. The manipulation of the argument Website Address leads to cros…
- CVE-2025-2133LOWCVSS 2.4EG 2.42025-03-10
A vulnerability classified as problematic was found in ftcms 2.1. Affected by this vulnerability is an unknown functionality of the file /admin/index.php/news/edit. The manipulation of the argument title leads to cross site scripting. The …
- CVE-2025-2169HIGHCVSS 7.3EG 7.32025-03-11
The The WPCS – WordPress Currency Switcher Professional plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.0.4. This is due to the software allowing users to execute an action th…
- CVE-2025-2191LOWCVSS 2.4EG 2.42025-03-11
A vulnerability, which was classified as problematic, has been found in Claro A7600-A1 RNR4-A72T-2x16_v2110403_CLA_32_160817. Affected by this issue is some unknown functionality of the file /form2pingv6.cgi of the component Ping6 Diagnós…
- CVE-2025-2194LOWCVSS 3.5EG 3.52025-03-11
A vulnerability was found in MRCMS 3.1.2 and classified as problematic. This issue affects the function list of the file /admin/file/list.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argument p…
- CVE-2025-2195LOWCVSS 3.5EG 3.52025-03-11
A vulnerability was found in MRCMS 3.1.2. It has been classified as problematic. Affected is the function rename of the file /admin/file/rename.do of the component org.marker.mushroom.controller.FileController. The manipulation of the argu…
- CVE-2025-2196LOWCVSS 3.5EG 3.52025-03-11
A vulnerability was found in MRCMS 3.1.2. It has been declared as problematic. Affected by this vulnerability is the function upload of the file /admin/file/upload.do of the component org.marker.mushroom.controller.FileController. The mani…
- CVE-2025-2206LOWCVSS 2.4EG 2.42025-03-11
A vulnerability classified as problematic has been found in aitangbao springboot-manager 3.0. This affects an unknown part of the file /sys/permission. The manipulation of the argument name leads to cross site scripting. It is possible to …
- CVE-2025-2207LOWCVSS 2.4EG 2.42025-03-11
A vulnerability classified as problematic was found in aitangbao springboot-manager 3.0. This vulnerability affects unknown code of the file /sys/dept. The manipulation of the argument name leads to cross site scripting. The attack can be …
- CVE-2025-2208LOWCVSS 2.4EG 2.42025-03-11
A vulnerability, which was classified as problematic, has been found in aitangbao springboot-manager 3.0. This issue affects some unknown processing of the file /sysFiles/upload of the component Filename Handler. The manipulation of the ar…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →