CWE-94
6,471 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (6,471)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyNov 21, 2024 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {bloc...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shel...Show more |
1Weintek 16Cmt Ctrl01 Firmware Cmt Fhd FirmwareCmt G01 Firmware+13 moreNov 21, 2024 May 16, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system. |
Code Injection in GitHub repository publify/publify prior to 9.2.8. |
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. |
1Pentest Collaboration Framework Project 1Pentest Collaboration Framework Nov 21, 2024 May 11, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/. |
1Ejointech 3Acom508 Firmware Acom516 FirmwareAcom532 FirmwareNov 21, 2024 May 9, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field. |
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows...Show more |
1Fluxcd 3Flux2 Helm ControllerKustomize ControllerNov 21, 2024 May 6, 2022 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Inj...Show more |
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app. |
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible |
4Fedoraproject NetappOracle+1 more5Communications Operations Monitor FedoraManagement Services For Element Software+2 moreNov 21, 2024 Apr 27, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execu...Show more |
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine...Show more |
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFu...Show more |
1Ad Injection Project 1Ad Injection Nov 21, 2024 Apr 18, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unf...Show more |
1Geosolutionsgroup 1Jai Ext Oct 24, 2025 Apr 13, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is c...Show more |