← Back
CWE-94

7,058 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,058)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Trezor
1Bridge
Jun 17, 2026
Jul 26, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
1Bludit
1Bludit
Jun 17, 2026
Jul 23, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
1Cisco
1Firepower Device Manager On Box
Jun 17, 2026
Jul 22, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. Th...Show more
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is due to insufficient sanitization of user input on specific REST API commands. An attacker could exploit this vulnerability by sending a crafted HTTP request to the API subsystem of an affected device. A successful exploit could allow the attacker to execute arbitrary code on the underlying operating system. To exploit this vulnerability, an attacker would need valid low-privileged user credentials.Show less
1Manageiq
1Manageiq
Jun 17, 2026
Jul 21, 2021
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string...Show more
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string which would be evaluated. Successful exploitation will allow an attacker to execute arbitrary code with root privileges on the host system. There are patches for this issue in releases named jansa-4, kasparov-2, and lasker-1. If possible, restrict users, via RBAC, to only the part of the application that they need access to. While MiqExpression is widely used throughout the product, restricting users can limit the surface of the attack.Show less
2Fail2ban
Fedoraproject
2Fail2ban
Fedora
Jun 17, 2026
Jul 16, 2021
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code exec...Show more
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailing action mail-whois. Command `mail` from mailutils package used in mail actions like `mail-whois` can execute command if unescaped sequences (`\n~`) are available in "foreign" input (for instance in whois output). To exploit the vulnerability, an attacker would need to insert malicious characters into the response sent by the whois server, either via a MITM attack or by taking over a whois server. The issue is patched in versions 0.10.7 and 0.11.3. As a workaround, one may avoid the usage of action `mail-whois` or patch the vulnerability manually.Show less
1Sap
1Netweaver Application Server Abap
Jun 17, 2026
Jul 14, 2021
N/A· v4
6.5 MEDIUM· v3
7.5 HIGH· v2
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code...Show more
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be executed by the application. An attacker could thereby delete some critical information and could make the SAP system completely unavailable.Show less
1Totaljs
1Total4
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
1Totaljs
1Total.js
Jun 17, 2026
Jul 12, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions.
1Cisco
1Adaptive Security Device Manager
Jun 17, 2026
Jul 8, 2021
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of...Show more
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature verification for specific code exchanged between the ASDM and the Launcher. An attacker could exploit this vulnerability by leveraging a man-in-the-middle position on the network to intercept the traffic between the Launcher and the ASDM and then inject arbitrary code. A successful exploit could allow the attacker to execute arbitrary code on the user's operating system with the level of privileges assigned to the ASDM Launcher. A successful exploit may require the attacker to perform a social engineering attack to persuade the user to initiate communication from the Launcher to the ASDM.Show less
1Monstra
1Monstra Cms
Jun 17, 2026
Jul 1, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.
1Narou Project
1Narou
Jun 17, 2026
Jun 28, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
1Phpwcms
1Phpwcms
Jun 17, 2026
Jun 24, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
1Phpcms
1Phpcms
Jun 17, 2026
Jun 16, 2021
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
6.5 MEDIUM· v3
2.1 LOW· v2
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
4.4 MEDIUM· v3
2.1 LOW· v2
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
1Google
1Android
Jun 17, 2026
Jun 11, 2021
N/A· v4
5.5 MEDIUM· v3
2.1 LOW· v2
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
1Microsoft
3365 Apps
OfficeOutlook
Jun 17, 2026
Jun 8, 2021
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Microsoft Outlook Remote Code Execution Vulnerability
1Reg Keygen Git Hash Project
1Reg Keygen Git Hash
Jun 17, 2026
Jun 8, 2021
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary...Show more
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade to version 0.10.16 or later to resolve this issue.Show less
1Huawei
2Emui
Magic Ui
Jun 17, 2026
Jun 3, 2021
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial of security services on a rooted device.