CWE-94
7,058 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,058)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges. |
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file. |
1Cisco 1Firepower Device Manager On Box Jun 17, 2026 Jul 22, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. Th...Show more |
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string...Show more |
2Fail2ban Fedoraproject2Fail2ban FedoraJun 17, 2026 Jul 16, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code exec...Show more |
1Sap 1Netweaver Application Server Abap Jun 17, 2026 Jul 14, 2021 N/A· v4 6.5 MEDIUM· v3 7.5 HIGH· v2 A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code...Show more |
The package total4 before 0.0.43 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
The package total.js before 3.4.9 are vulnerable to Arbitrary Code Execution via the U.set() and U.get() functions. |
1Cisco 1Adaptive Security Device Manager Jun 17, 2026 Jul 8, 2021 N/A· v4 8.1 HIGH· v3 9.3 HIGH· v2 A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of...Show more |
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module. |
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel. |
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php. |
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php. |
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area. |
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable. |
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory. |
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data. |
1Microsoft 3365 Apps OfficeOutlookJun 17, 2026 Jun 8, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Microsoft Outlook Remote Code Execution Vulnerability |
1Reg Keygen Git Hash Project 1Reg Keygen Git Hash Jun 17, 2026 Jun 8, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary...Show more |
There is an Improper Control of Generation of Code vulnerability in Huawei Smartphone. Successful exploitation of this vulnerability may cause denial of security services on a rooted device. |