← Back
CWE-94

7,072 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,072)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Dedecms
1Dedecms
Jun 17, 2026
May 27, 2023
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the...Show more
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can be launched remotely. The exploit has been disclosed to the public and may be used. The associated identifier of this vulnerability is VDB-230083.Show less
1Faculty Evaluation System Project
1Faculty Evaluation System
Jun 17, 2026
May 26, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Sourcecodester Faculty Evaluation System v1.0 is vulnerable to arbitrary code execution via /eval/ajax.php?action=save_user.
1Tuzitio
1Camaleon Cms
Jun 17, 2026
May 26, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
1Apache
1Rocketmq
Jun 17, 2026
May 24, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and...Show more
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution.  Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission verification, an attacker can exploit this vulnerability by using the update configuration function to execute commands as the system users that RocketMQ is running as. Additionally, an attacker can achieve the same effect by forging the RocketMQ protocol content.  To prevent these attacks, users are recommended to upgrade to version 5.1.1 or above for using RocketMQ 5.x or 4.9.6 or above for using RocketMQ 4.x .Show less
1Teampass
1Teampass
Jun 17, 2026
May 24, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
1Sqlite Jdbc Project
1Sqlite Jdbc
Jun 17, 2026
May 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has...Show more
SQLite JDBC is a library for accessing and creating SQLite database files in Java. Sqlite-jdbc addresses a remote code execution vulnerability via JDBC URL. This issue impacting versions 3.6.14.1 through 3.41.2.1 and has been fixed in version 3.41.2.2. Show less
1Worksmobile
1Drive Explorer
Jun 17, 2026
May 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the pro...Show more
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is required to execute LINE WORKS Drive Explorer, the attacker may be able to read and/or write to arbitrary files without the access privileges.Show less
1Flir
1Dvtel Camera Firmware
Jun 17, 2026
May 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
1Agasio Camera Project
1Agasio Camera Firmware
Jun 17, 2026
May 15, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
1Jedox
2Jedox
Jedox Cloud
Jul 9, 2026
May 12, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that...Show more
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version 22.5 or earlier. The issue was resolved with version 23.2 and later versions are not affected.Show less
1Craftcms
1Craft Cms
Jun 17, 2026
May 12, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
1Golang
1Go
Jun 17, 2026
May 11, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of...Show more
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attributes into tags.Show less
1Golang
1Go
Jun 17, 2026
May 11, 2023
N/A· v4
7.3 HIGH· v3
N/A· v2
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allow...Show more
Angle brackets (<>) are not considered dangerous characters when inserted into CSS contexts. Templates containing multiple actions separated by a '/' character can result in unexpectedly closing the CSS context and allowing for injection of unexpected HTML, if executed with untrusted input.Show less
1Phpok
1Phpok
Jun 17, 2026
May 11, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
1Microsoft
2Sharepoint Enterprise Server
Sharepoint Server
Jun 17, 2026
May 9, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
Microsoft SharePoint Server Remote Code Execution Vulnerability
1Jsreport
1Jsreport
Jun 17, 2026
May 8, 2023
N/A· v4
10.0 CRITICAL· v3
N/A· v2
Code Injection in GitHub repository jsreport/jsreport prior to 3.11.3.
1S Cms
1S Cms
Jun 17, 2026
May 5, 2023
N/A· v4
7.2 HIGH· v3
N/A· v2
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
1Elastic
1Kibana
Jun 17, 2026
May 4, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the a...Show more
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.Show less
1Elastic
1Kibana
Jun 17, 2026
May 4, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. T...Show more
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to the attacker executing arbitrary commands on the host system with permissions of the Kibana process.Show less
1Gitlab
1Gitlab
Jun 17, 2026
May 3, 2023
N/A· v4
5.7 MEDIUM· v3
N/A· v2
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromi...Show more
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled from a tag or from a release containing a ref to another commit.Show less