← Back
CWE-94

7,081 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Instawp
1Instawp Connect
Jun 17, 2026
Apr 3, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
1Beescms
1Beescms
Jun 17, 2026
Apr 3, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.
1Axiosys
1Bento4
Jun 17, 2026
Apr 2, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment
1Axiosys
1Bento4
Jun 17, 2026
Apr 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
1Axiosys
1Bento4
Jun 17, 2026
Apr 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.
-
-
Jun 17, 2026
Apr 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.
1Netentsec
1Ns Asg Firmware
Jun 17, 2026
Apr 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.
1Netentsec
1Ns Asg Firmware
Jun 17, 2026
Apr 1, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.
1Ivanti
1Standalone Sentry
Jun 17, 2026
Mar 31, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical...Show more
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network. Show less
-
-
Jun 17, 2026
Mar 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.
1Fit2cloud
1Jumpserver
Jun 17, 2026
Mar 29, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within t...Show more
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This vulnerability is fixed in v3.10.7.Show less
1Fit2cloud
1Jumpserver
Jun 17, 2026
Mar 29, 2024
N/A· v4
9.9 CRITICAL· v3
N/A· v2
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery co...Show more
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the Celery container runs with root privileges and has database access, attackers could steal sensitive information from all hosts or manipulate the database. This vulnerability is fixed in v3.10.7.Show less
-
-
Jun 17, 2026
Mar 28, 2024
N/A· v4
8.4 HIGH· v3
N/A· v2
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.Web...Show more
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.Show less
1Nec
59Aterm Cr2500p Firmware
Aterm Mr01ln FirmwareAterm Mr02ln Firmware+56 more
Jun 17, 2026
Mar 28, 2024
N/A· v4
4.7 MEDIUM· v3
N/A· v2
Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP...Show more
Aterm WG1800HP4, WG1200HS3, WG1900HP2, WG1200HP3, WG1800HP3, WG1200HS2, WG1900HP, WG1200HP2, W1200EX(-MS), WG1200HS, WG1200HP, WF300HP2, W300P, WF800HP, WR8165N, WG2200HP, WF1200HP2, WG1800HP2, WF1200HP, WG600HP, WG300HP, WF300HP, WG1800HP, WG1400HP, WR8175N, WR9300N, WR8750N, WR8160N, WR9500N, WR8600N, WR8370N, WR8170N, WR8700N, WR8300N, WR8150N, WR4100N, WR4500N, WR8100N, WR8500N, CR2500P, WR8400N, WR8200N, WR1200H, WR7870S, WR6670S, WR7850S, WR6650S, WR6600H, WR7800H, WM3400RN, WM3450RN, WM3500R, WM3600R, WM3800R, WR8166N, MR01LN MR02LN, WG1810HP(JE) and WG1810HP(MF) all versions allows a attacker who has obtained high privileges can execute arbitrary scripts.Show less
-
-
Jun 17, 2026
Mar 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewer...Show more
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.Show less
-
-
Jun 17, 2026
Mar 27, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted c...Show more
SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE) on the SCM Server remotely. Malicious clients can execute any command by using this RCE vulnerability.Show less
1Hp
2826k67a Firmware
26k67b Firmware26k68a Firmware+25 more
Jun 17, 2026
Mar 27, 2024
N/A· v4
6.3 MEDIUM· v3
N/A· v2
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default down...Show more
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution.Show less
-
-
Jun 17, 2026
Mar 26, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to...Show more
The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain circumstances. The action the attacker wishes to execute needs to have a nonce check, and the nonce needs to be known to the attacker. Furthermore, the absence of a capability check is a requirement.Show less
1Gnu
2Emacs
Org Mode
Jun 17, 2026
Mar 25, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
1Home Made
1Fastmag Sync
Jul 9, 2026
Mar 25, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.