← Back
CWE-94

7,058 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,058)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Jpress
1Jpress
Jul 9, 2026
Jan 26, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
1Jpress
1Jpress
Jul 9, 2026
Jan 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some...Show more
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.Show less
1Jpress
1Jpress
Jul 9, 2026
Jan 26, 2022
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious...Show more
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.Show less
1F5
1Nginx Controller Api Management
Jun 17, 2026
Jan 25, 2022
N/A· v4
5.4 MEDIUM· v3
5.5 MEDIUM· v2
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript cod...Show more
On NGINX Controller API Management versions 3.18.0-3.19.0, an authenticated attacker with access to the "user" or "admin" role can use undisclosed API endpoints on NGINX Controller API Management to inject JavaScript code that is executed on managed NGINX data plane instances. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.Show less
1Apache
1Shenyu
Jun 17, 2026
Jan 25, 2022
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
1Mustache Project
1Mustache
Jun 17, 2026
Jan 21, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
1Trendmicro
1Deep Security Agent
Jun 17, 2026
Jan 20, 2022
N/A· v4
7.8 HIGH· v3
6.9 MEDIUM· v2
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of r...Show more
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to the target agent in an un-activated and unconfigured state in order to exploit this vulnerability.Show less
1Lexmark
2336500e Firmware
B2236 FirmwareB2338 Firmware+230 more
Jun 17, 2026
Jan 20, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
1Code42
1Code42
Jun 17, 2026
Jan 20, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Adva...Show more
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for Small Business. (Incydr Professional and Enterprise are unaffected.)Show less
1Octobercms
1October
Jun 17, 2026
Jan 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using t...Show more
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using the theme import feature. This will bypass the safe mode feature that prevents PHP execution in the CMS templates.The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.Show less
1Octobercms
1October
Jun 17, 2026
Jan 14, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the...Show more
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to execute PHP code by running specially crafted Twig code in the template markup. The issue has been patched in Build 473 (v1.0.473) and v1.1.6. Those unable to upgrade may apply the patch to their installation manually as a workaround.Show less
1Commvault
1Commcell
Jun 17, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authenticatio...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the DataProvider class. The issue results from the lack of proper validation of a user-supplied string before executing it as JavaScript code. An attacker can leverage this vulnerability to escape the JavaScript sandbox and execute Java code in the context of NETWORK SERVICE. Was ZDI-CAN-13755.Show less
1Jpress
1Jpress
Jul 9, 2026
Jan 13, 2022
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
1Mirantis
1Lens
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary s...Show more
In Lens prior to 5.3.4, custom helm chart configuration creates helm commands from string concatenation of provided arguments which are then executed in the user's shell. Arguments can be provided which cause arbitrary shell commands to run on the system.Show less
1Samsung
1Bixby Routines
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.
1Samsung
1Reminder
Jun 17, 2026
Jan 10, 2022
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.
1Google
1Android
Jun 17, 2026
Jan 10, 2022
N/A· v4
3.3 LOW· v3
4.3 MEDIUM· v2
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
1Huawei
1Harmonyos
Jun 17, 2026
Jan 3, 2022
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.
1Thinkcmf
1Thinkcmf
Jun 17, 2026
Dec 22, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
1Unisharp
1Laravel Filemanager
Jun 17, 2026
Dec 17, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps...Show more
This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2. Navigate to the Upload window 3. Upload an image file, then capture the request 4. Edit the request contents with a malicious file (webshell) 5. Enter the path of file uploaded on URL - Remote Code Execution **Note:** Prevention for bad extensions can be done by using a whitelist in the config file(lfm.php). Corresponding document can be found in [here](https://unisharp.github.io/laravel-filemanager/configfolder-categories).Show less