CWE-94
6,471 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (6,471)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Lexmark 2336500e Firmware B2236 FirmwareB2338 Firmware+230 moreNov 21, 2024 Jan 20, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. |
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Adva...Show more |
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using t...Show more |
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the...Show more |
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authenticatio...Show more |
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code. |
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary s...Show more |
A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent. |
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent. |
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information. |
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity. |
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. |
1Unisharp 1Laravel Filemanager Jun 17, 2025 Dec 17, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps...Show more |
1Vault Cli Project 1Vault Cli Nov 21, 2024 Dec 16, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerNov 21, 2024 Dec 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Server Remote Code Execution Vulnerability |
1Sap 2Abap Platform Netweaver Application Server AbapNov 21, 2024 Dec 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, w...Show more |
1Ivanti 1Endpoint Manager Cloud Services Appliance Nov 3, 2025 Dec 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). |
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart. |
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission. |