CWE-94
6,471 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (6,471)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pip...Show more |
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS comman...Show more |
1Oracle 1Communications Converged Application Server Nov 21, 2024 Jan 18, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability all...Show more |
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Difficult to exploit vulnerability allows unaut...Show more |
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`,...Show more |
3Debian FedoraprojectRuby Git Project3Debian Linux FedoraRuby GitApr 4, 2025 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
2Debian Ruby Git Project2Debian Linux Ruby GitApr 4, 2025 Jan 17, 2023 N/A· v4 8.0 HIGH· v3 N/A· v2 ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability...Show more |
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31. |
Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval. |
1Nvidia 6Nvidia Isaac Sim Omniverse Audio2faceOmniverse Code+3 moreNov 21, 2024 Jan 13, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Descriptio...Show more |
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation. |
1Sap 1Businessobjects Business Intelligence Platform Nov 21, 2024 Jan 10, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attac...Show more |
1Window Control Project 1Window Control Apr 10, 2025 Jan 4, 2023 N/A· v4 7.8 HIGH· v3 N/A· v2 Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
|
Code Injection in GitHub repository lirantal/daloradius prior to master-branch. |
A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/controllers/code_caller_controller.php. The manipulation of the argument q wi...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdApr 15, 2025 Dec 22, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious cod...Show more |
1Mozilla 3Firefox Firefox EsrThunderbirdApr 16, 2025 Dec 22, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 If a user was convinced to drag and drop an image to their desktop or other folder, the resulting object could have been changed into an executable script which would have run arbitrary code after the user clicked on it....Show more |
AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code. |
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks. |
1Buffalo 13Wcr 1166ds Firmware Wex 1800ax4 FirmwareWex 1800ax4ea Firmware+10 moreApr 17, 2025 Dec 19, 2022 N/A· v4 6.8 MEDIUM· v3 N/A· v2 Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command on the affected devic...Show more |