← Back
CWE-94

7,089 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,089)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Comfast
1Cf Xr11 Firmware
Jun 17, 2026
Sep 11, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
COMFAST CF-XR11 V2.7.2 has a command injection vulnerability in function sub_424CB4. Attackers can send POST request messages to /usr/bin/webmgnt and inject commands into parameter iface.
1Microsoft
1Azure Cyclecloud
Aug 10, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Azure CycleCloud Remote Code Execution Vulnerability
1Logitech
1Logi Options+
Jun 17, 2026
Sep 10, 2024
2.0 LOW· v4
7.8 HIGH· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection') in Electron Fuses in Logitech Options Plus version 1.60.496306 on macOS allows attackers to execute arbitrary code via insecure Electron Fuses configuration.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP FW_RULESETS.IN_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
30Fl Mguard Centerport Vpn 1000 Firmware
Fl Mguard Core Tx FirmwareFl Mguard Core Tx Vpn Firmware+27 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment vari...Show more
A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.Show less
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.
1Phoenixcontact
36Fl Mguard 2102 Firmware
Fl Mguard 2105 FirmwareFl Mguard 4102 Pci Firmware+33 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
1Endress
6Echo Curve Viewer
Field Xpert Smt50 FirmwareField Xpert Smt70 Firmware+3 more
Jun 17, 2026
Sep 10, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
1Ifeelweb
1Affiliate Super Assistent
Jun 17, 2026
Sep 10, 2024
N/A· v4
7.3 HIGH· v3
N/A· v2
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes...Show more
The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes.Show less
1Buffercode
1Frontend Dashboard
Jun 17, 2026
Sep 10, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2...Show more
The Frontend Dashboard plugin for WordPress is vulnerable to unauthorized code execution due to insufficient filtering on callable methods/functions via the ajax_request() function in all versions up to, and including, 2.2.4. This makes it possible for authenticated attackers, with subscriber-level access and above, to call arbitrary functions that can be leverage for privilege escalation by changing user's passwords.Show less
1Dlink
1Di 8300 Firmware
Jun 17, 2026
Sep 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
1Dlink
1Di 8300 Firmware
Jun 17, 2026
Sep 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
1Autocms Project
1Autocms
Jun 17, 2026
Sep 9, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted va...Show more
AutoCMS v5.4 was discovered to contain a PHP code injection vulnerability via the txtsite_url parameter at /admin/site_add.php. This vulnerability allows attackers to execute arbitrary PHP code via injecting a crafted value.Show less
-
-
Jun 17, 2026
Sep 7, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.
-
-
Jun 17, 2026
Sep 7, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
-
-
Jun 17, 2026
Sep 7, 2024
N/A· v4
8.5 HIGH· v3
N/A· v2
A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.
-
-
Jun 17, 2026
Sep 7, 2024
N/A· v4
5.3 MEDIUM· v3
N/A· v2
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, simila...Show more
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebAssembly module was a JavaScript module. This vulnerability affects users of any active release line of Node.js. The vulnerable feature is only available if Node.js is started with the `--experimental-wasm-modules` command line option.Show less
1Lmxcms
1Lmxcms
Jun 17, 2026
Sep 7, 2024
5.1 MEDIUM· v4
7.2 HIGH· v3
5.8 MEDIUM· v2
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. T...Show more
A vulnerability was found in lmxcms up to 1.4 and classified as critical. Affected by this issue is the function formatData of the file /admin.php?m=Acquisi&a=testcj&lid=1 of the component SQL Command Execution Module. The manipulation of the argument data leads to code injection. The attack may be launched remotely. The exploit has been disclosed to the public and may be used. The vendor was contacted early about this disclosure but did not respond in any way.Show less