← Back
CWE-94

7,081 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,081)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Apple
5Ipados
Iphone OsMacos+2 more
Jun 17, 2026
Mar 8, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break o...Show more
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.Show less
1Paddlepaddle
1Paddlepaddle
Jun 17, 2026
Mar 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
remote code execution in paddlepaddle/paddle 2.6.0
1Code Projects
1Student Enrollment
Jun 17, 2026
Mar 7, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
1Teamwire
1Teamwire
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.5 HIGH· v3
N/A· v2
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
-
-
Jun 17, 2026
Mar 5, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A reflected cross-site scripting (XSS) vulnerability exists in SuperCali version 1.1.0, allowing remote attackers to execute arbitrary JavaScript code via the email parameter in the bad_password.php page.
1Cmsmadesimple
1Cms Made Simple
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the '...Show more
A remote code execution vulnerability has been identified in the User Defined Tags module of CMS Made Simple version 2.2.19 / 2.2.21. This vulnerability arises from inadequate sanitization of user-supplied input in the 'Code' section of the module. As a result, authenticated users with administrative privileges can inject and execute arbitrary PHP code.Show less
1Typo3
1Typo3
Jun 17, 2026
Mar 5, 2024
N/A· v4
7.2 HIGH· v3
N/A· v2
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields...Show more
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool. The fixed versions are 8.7.57 ELTS, 9.5.46 ELTS, 10.4.43 ELTS, 11.5.35 LTS, 12.4.11 LTS, and 13.0.1.Show less
1Mjml
1Mjml App
Jun 17, 2026
Mar 1, 2024
N/A· v4
9.3 CRITICAL· v3
N/A· v2
mjml-app versions 3.0.4 and 3.1.0-beta were discovered to contain a remote code execution (RCE) via the href attribute.
1Pdfmake Project
1Pdfmake
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf...Show more
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test framework (that lives outside of the pdfmake applicaton). Anyone installing this is responsible for ensuring that it is only available to authorized testers.Show less
1Deskfiler
1Deskfiler
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
1Epoint
1Epointwebbuilder
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.
1Oretnom23
1Simple Student Attendance System
Jun 17, 2026
Feb 29, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
2Fedoraproject
Ibireme
2Fedora
Yyjson
Jun 17, 2026
Feb 29, 2024
N/A· v4
8.6 HIGH· v3
N/A· v2
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_r...Show more
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)Show less
1Phpgurukul
1Zoo Management System
Jun 17, 2026
Feb 28, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
1Phpgurukul
1User Registration & Login And User Management System
Jun 17, 2026
Feb 28, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Phpgurukul User Registration & Login and User Management System 1.0 allows attackers to run arbitrary code via the search bar.
1Apache
1Ambari
Jun 17, 2026
Feb 27, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code in...Show more
Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.Show less
1Lg
1Webos Signage
Jun 17, 2026
Feb 26, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
1Zkteco
1Zkbio Wdms
Jun 17, 2026
Feb 23, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.
1Br Automation
2Automation Studio
Technology Guarding
Jun 17, 2026
Feb 22, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to exec...Show more
B&R Automation Studio Upgrade Service and B&R Technology Guarding use insufficient cryptography for communication to the upgrade and the licensing servers. A network-based attacker could exploit the vulnerability to execute arbitrary code on the products or sniff sensitive data.Show less
1Getkirby
1Kirby
Jun 17, 2026
Feb 22, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.