CWE-94
7,062 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,062)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Simple Ads Manager Project 1Simple Ads Manager Nov 21, 2024 Jun 24, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability classified as critical was found in Simple Ads Manager Plugin. This vulnerability affects unknown code. The manipulation leads to code injection. The attack can be initiated remotely. |
A vulnerability, which was classified as critical, was found in VaultPress Plugin 1.8.4. This affects an unknown part. The manipulation leads to code injection. It is possible to initiate the attack remotely. |
A vulnerability was found in Elefant CMS 1.3.12-RC. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /designer/add/layout. The manipulation leads to code injection....Show more |
flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code. |
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments...Show more |
Code Injection in GitHub repository nuitka/nuitka prior to 0.9. |
In the SEOmatic plugin up to 3.4.11 for Craft CMS 3, it is possible for unauthenticated attackers to perform a Server-Side Template Injection, allowing for remote code execution. |
1Convert Svg Core Project 1Convert Svg Core Jun 17, 2026 Jun 10, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 The package convert-svg-core before 0.6.3 are vulnerable to Arbitrary Code Injection when using a specially crafted SVG file. An attacker can read arbitrary files from the file system and then show the file content as a...Show more |
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2. |
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScrip...Show more |
2Debian Rubyonrails2Active Storage Debian LinuxJun 17, 2026 May 26, 2022 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments. |
3Debian FedoraprojectSmarty3Debian Linux FedoraSmartyJun 17, 2026 May 24, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {bloc...Show more |
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shel...Show more |
1Weintek 16Cmt Ctrl01 Firmware Cmt Fhd FirmwareCmt G01 Firmware+13 moreJun 17, 2026 May 16, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system. |
Code Injection in GitHub repository publify/publify prior to 9.2.8. |
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php. |
1Pentest Collaboration Framework Project 1Pentest Collaboration Framework Jun 17, 2026 May 11, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/. |
1Ejointech 3Acom508 Firmware Acom516 FirmwareAcom532 FirmwareJun 17, 2026 May 9, 2022 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Command injection vulnerability in Manual Ping Form (Web UI) in Shenzhen Ejoin Information Technology Co., Ltd. ACOM508/ACOM516/ACOM532 609-915-041-100-020 allows a remote attacker to inject arbitrary code via the field. |
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows...Show more |
1Fluxcd 3Flux2 Helm ControllerKustomize ControllerJun 17, 2026 May 6, 2022 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 Flux2 is an open and extensible continuous delivery solution for Kubernetes. Flux2 versions between 0.1.0 and 0.29.0, helm-controller 0.1.0 to v0.19.0, and kustomize-controller 0.1.0 to v0.23.0 are vulnerable to Code Inj...Show more |