← Back
CWE-94

7,068 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,068)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Oracle
1Vm Virtualbox
Jun 17, 2026
Oct 18, 2022
N/A· v4
8.1 HIGH· v3
N/A· v2
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker w...Show more
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM VirtualBox. Successful attacks of this vulnerability can result in takeover of Oracle VM VirtualBox. CVSS 3.1 Base Score 8.1 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H).Show less
1Get Simple
1Getsimple Cms
Jun 17, 2026
Oct 18, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
GetSimple CMS v3.3.16 was discovered to contain a remote code execution (RCE) vulnerability via the edited_file parameter in admin/theme-edit.php.
1Huawei
2Emui
Harmonyos
Jun 17, 2026
Oct 14, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.
1Octobercms
1October
Jun 17, 2026
Oct 13, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing pub...Show more
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the admin panel. Assuming an attacker has access to the admin panel and permission to open the "Editor" section, they can bypass the Safe Mode (`cms.safe_mode`) restriction to introduce new PHP code in a CMS template using a specially crafted request. The issue has been patched in versions 2.2.34 and 3.0.66.Show less
1Online Diagnostic Lab Management System Project
1Online Diagnostic Lab Management System
Jun 17, 2026
Oct 13, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code v...Show more
Online Diagnostic Lab Management System v1.0 was discovered to contain an arbitrary file upload vulnerability via the component /php_action/createOrder.php. This vulnerability allows attackers to execute arbitrary code via a crafted PHP file.Show less
3Apache
JuniperNetapp
3Bluexp
Commons TextSecurity Threat Response Manager
Jun 17, 2026
Oct 13, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance o...Show more
Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with version 1.5 and continuing through 1.9, the set of default Lookup instances included interpolators that could result in arbitrary code execution or contact with remote servers. These lookups are: - "script" - execute expressions using the JVM script execution engine (javax.script) - "dns" - resolve dns records - "url" - load values from urls, including from remote servers Applications using the interpolation defaults in the affected versions may be vulnerable to remote code execution or unintentional contact with remote servers if untrusted configuration values are used. Users are recommended to upgrade to Apache Commons Text 1.10.0, which disables the problematic interpolators by default.Show less
2Debian
Linaro
2Debian Linux
Lava
Jun 17, 2026
Oct 13, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn ser...Show more
In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Oct 12, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database an...Show more
Dolibarr ERP & CRM <=15.0.3 is vulnerable to Eval injection. By default, any administrator can be added to the installation page of dolibarr, and if successfully added, malicious code can be inserted into the database and then execute it by eval.Show less
1Ikuai8
1Ikuaios
Jun 17, 2026
Oct 12, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.
1Gridea
1Gridea
Jun 17, 2026
Sep 30, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegra...Show more
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.Show less
1Tp Link
1Archer Ax10 V1 Firmware
Jun 17, 2026
Sep 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.
1Wazuh
1Wazuh
Jun 17, 2026
Sep 28, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
Wazuh v3.6.1 - v3.13.5, v4.0.0 - v4.2.7, and v4.3.0 - v4.3.7 were discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Response endpoint.
3Debian
FedoraprojectJoblib Project
3Debian Linux
FedoraJoblib
Jun 17, 2026
Sep 26, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
1Tacitine
2En6200 Prime Quad 100 Firmware
En6200 Prime Quad 35 Firmware
Jun 17, 2026
Sep 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall we...Show more
This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted device. Successful exploitation of this vulnerability could allow an unauthenticated remote attacker to execute arbitrary commands on the targeted device.Show less
1Sophos
1Firewall
Jun 17, 2026
Sep 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
1Apache
1Pinot
Jun 17, 2026
Sep 23, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the gro...Show more
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0. See https://docs.pinot.apache.org/basics/releases/0.11.0Show less
1Soflyy
1Wp All Import
Jun 17, 2026
Sep 21, 2022
N/A· v4
7.2 HIGH· v3
N/A· v2
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
1Hpe
1Integrated Lights Out 5 Firmware
Jun 17, 2026
Sep 20, 2022
N/A· v4
8.8 HIGH· v3
N/A· v2
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2....Show more
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated firmware for HPE Integrated Lights-Out 5 (iLO 5) that addresses this security vulnerability.Show less
1Zutty Project
1Zutty
Jun 17, 2026
Sep 20, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Zutty before 0.13, DECRQSS in text written to the terminal can achieve arbitrary code execution.
1Microweber
1Microweber
Jun 17, 2026
Sep 20, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validatio...Show more
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.Show less