CWE-94
7,058 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,058)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Vault Cli Project 1Vault Cli Jun 17, 2026 Dec 16, 2021 N/A· v4 9.1 CRITICAL· v3 9.0 HIGH· v2 vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts...Show more |
1Microsoft 3Sharepoint Enterprise Server Sharepoint FoundationSharepoint ServerJun 17, 2026 Dec 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Microsoft SharePoint Server Remote Code Execution Vulnerability |
1Sap 2Abap Platform Netweaver Application Server AbapJun 17, 2026 Dec 14, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, w...Show more |
1Ivanti 1Endpoint Manager Cloud Services Appliance Aug 4, 2026 Dec 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody). |
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart. |
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission. |
IBM MQ Appliance 9.2 CD and 9.2 LTS could allow a local privileged user to inject and execute malicious code. IBM X-Force ID: 212441. |
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If...Show more |
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability |
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. |
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format. |
Applications using both `spring-cloud-netflix-hystrix-dashboard` and `spring-boot-starter-thymeleaf` expose a way to execute code submitted within the request URI path during the resolution of view templates. When a requ...Show more |
1Cron Utils Project 1Cron Utils Jun 17, 2026 Nov 15, 2021 N/A· v4 9.8 CRITICAL· v3 6.8 MEDIUM· v2 cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inj...Show more |
1Tp Link 1Tl Wr840n Firmware Jul 9, 2026 Nov 13, 2021 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 The PING function on the TP-Link TL-WR840N EU v5 router with firmware through TL-WR840N(EU)_V5_171211 is vulnerable to remote code execution via a crafted payload in an IP address input field. |
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked. |
3D Viewer Remote Code Execution Vulnerability |
1Microsoft 1Malware Protection Engine Aug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Microsoft Defender Remote Code Execution Vulnerability |
1Microsoft 3365 Apps OfficeOffice Long Term Servicing ChannelAug 19, 2026 Nov 10, 2021 N/A· v4 7.8 HIGH· v3 6.9 MEDIUM· v2 Microsoft Word Remote Code Execution Vulnerability |
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. |