← Back
CWE-94

7,080 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,080)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Microsoft
1Azure Uamqp
Jun 17, 2026
Feb 12, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication...Show more
The UAMQP is a general purpose C library for AMQP 1.0. During a call to open_get_offered_capabilities, a memory allocation may fail causing a use-after-free issue and if a client called it during connection communication it may cause a remote code execution. Users are advised to update the submodule with commit `30865c9c`. There are no known workarounds for this vulnerability.Show less
1Yealink
1Yealink Meeting Server
Jun 17, 2026
Feb 8, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
1Westermo
1L206 F2g Firmware
Jun 17, 2026
Feb 6, 2024
N/A· v4
8.0 HIGH· v3
N/A· v2
A potential attacker with access to the Westermo Lynx device may be able to execute malicious code that could affect the correct functioning of the device.
1Ispyconnect
1Agent Dvr
Jun 17, 2026
Feb 6, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
1Vegacorp
1Display Custom Fields In The Frontend Post And User Profile Fields
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to...Show more
The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access to that shortcode. This makes it possible for authenticated attackers with contributor-level and above permissions to call arbitrary functions and execute code.Show less
1Filemanagerpro
1File Manager
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated...Show more
The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute code on the server. Version 8.3.5 introduces a capability check that prevents users lower than admin from executing this function.Show less
1Stimulsoft
1Dashboard.js
Jul 9, 2026
Feb 5, 2024
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
1Flusity
1Flusity
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
1Axis
3Axis Os
Axis Os 2020Axis Os 2022
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited...Show more
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. Axis has released patched AXIS OS versions for the highlighted flaw. Please refer to the Axis security advisory for more information and solution.Show less
1Axis
11M3024 Lve Firmware
M3025 Ve FirmwareM7014 Firmware+8 more
Jun 17, 2026
Feb 5, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be...Show more
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticating with an operator- or administrator-privileged service account. The impact of exploiting this vulnerability is lower with operator-privileges compared to administrator-privileges service accounts. Please refer to the Axis security advisory for more information and solution.Show less
1Malwarebytes
1Binisoft Windows Firewall Control
Jun 17, 2026
Feb 4, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.
1Blurams
1Lumi Security Camera A31c Firmware
Jun 17, 2026
Feb 2, 2024
N/A· v4
6.8 MEDIUM· v3
N/A· v2
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.
1Blurams
1Lumi Security Camera A31c Firmware
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.
1Br Automation
1Automation Studio
Jun 17, 2026
Feb 2, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Improper Control of Generation of Code ('Code Injection') vulnerability in B&R Industrial Automation Automation Studio allows Local Execution of Code.This issue affects Automation Studio: from 4.0 through 4.12.
1Xiandafu
1Beetl
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Beca...Show more
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be bypassed, leading to arbitrary code execution.Show less
1Miro
1Miro
Jun 17, 2026
Feb 2, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.ap...Show more
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back to app.app/Contents).Show less
1Vinchin
1Vinchin Backup And Recovery
Jul 9, 2026
Feb 2, 2024
N/A· v4
8.8 HIGH· v3
N/A· v2
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
1Perforce
1Helix Sync
Jun 17, 2026
Feb 1, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
In Helix Sync versions prior to 2024.1, a local command injection was identified. Reported by Bryan Riggins.  
1Connectwise
2Automate
Screenconnect
Jun 17, 2026
Feb 1, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.
1Openbi
1Openbi
Jun 17, 2026
Jan 31, 2024
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /application/index/controller/Screen.php. The manipulation of the argume...Show more
A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /application/index/controller/Screen.php. The manipulation of the argument fileurl leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-252475.Show less