CWE-94
7,058 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,058)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible |
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible |
4Fedoraproject NetappOracle+1 more5Communications Operations Monitor FedoraManagement Services For Element Software+2 moreJun 17, 2026 Apr 27, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Redis is an in-memory database that persists on disk. By exploiting weaknesses in the Lua script execution environment, an attacker with access to Redis prior to version 7.0.0 or 6.2.7 can inject Lua code that will execu...Show more |
Ballcat Codegen provides the function of online editing code to generate templates. In versions prior to 1.0.0.beta.2, attackers can implement remote code execution through malicious code injection of the template engine...Show more |
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFu...Show more |
1Ad Injection Project 1Ad Injection Jun 17, 2026 Apr 18, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unf...Show more |
1Geosolutionsgroup 1Jai Ext Jun 17, 2026 Apr 13, 2022 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is c...Show more |
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege. |
1Vmware 5Cloud Foundation Identity ManagerVrealize Automation+2 moreJun 17, 2026 Apr 11, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection tha...Show more |
Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. |
Combodo iTop is a web based IT Service Management tool. In versions prior to 2.7.6 and 3.0.0, users of the iTop user portal can send TWIG code to the server by forging specific http queries, and execute arbitrary code on...Show more |
1Simplemachines 1Simple Machines Forum Jun 17, 2026 Apr 5, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's pos...Show more |
1Atlassian 2Confluence Data Center Confluence ServerJun 17, 2026 Apr 5, 2022 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL...Show more |
5Cisco OracleSiemens+2 more38Access Appliance Commerce PlatformCommunications Cloud Native Core Automated Test Suite+35 moreJun 17, 2026 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the a...Show more |
2Oracle Vmware28Banking Branch Banking Cash ManagementBanking Corporate Lending Process Management+25 moreJun 17, 2026 Apr 1, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in rem...Show more |
1Rockwellautomation 5Compact Guardlogix 5380 Firmware Compactlogix 5380 FirmwareCompactlogix 5480 Firmware+2 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectabl...Show more |
In all versions of GitLab CE/EE starting from 0.8.0 before 14.2.6, all versions starting from 14.3 before 14.3.4, and all versions starting from 14.4 before 14.4.1 certain Unicode characters can be abused to commit malic...Show more |
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code. |
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM pri...Show more |
Chamilo LMS v1.11.14 was discovered to contain a zero click code injection vulnerability which allows attackers to execute arbitrary code via a crafted plugin. This vulnerability is triggered through user interaction wit...Show more |