CWE-94
7,057 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,057)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution. |
3Debian Exiftool ProjectFedoraproject3Debian Linux ExiftoolFedoraJun 17, 2026 Apr 23, 2021 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image |
Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is able to overwrite any file on the system with the command results. This...Show more |
Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to 0.0.3 could be exploited to read internal files from the system and wr...Show more |
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can...Show more |
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the applic...Show more |
1Eaton 1Intelligent Power Manager Jun 17, 2026 Apr 13, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated remote code execution vulnerability. IPM software does not sanitize the date provided via coverterCheckList action in meta_driver_srv.j...Show more |
1Eaton 3Intelligent Power Manager Intelligent Power Manager Virtual ApplianceIntelligent Power ProtectorJun 17, 2026 Apr 13, 2021 N/A· v4 10.0 CRITICAL· v3 7.5 HIGH· v2 Eaton Intelligent Power Manager (IPM) prior to 1.69 is vulnerable to unauthenticated eval injection vulnerability. The software does not neutralize code syntax from users before using in the dynamic evaluation call in lo...Show more |
Discord Recon Server is a bot that allows you to do your reconnaissance process from your Discord. Remote code execution in version 0.0.1 would allow remote users to execute commands on the server resulting in serious is...Show more |
1Cisco 4Prime License Manager Unified Communications ManagerUnified Communications Manager Im & Presence Service+1 moreJun 17, 2026 Apr 8, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Uni...Show more |
The WP Super Cache WordPress plugin before 1.7.2 was affected by an authenticated (admin+) RCE in the settings page due to input validation failure and weak $cache_path check in the WP Super Cache Settings -> Cache Locat...Show more |
4Debian FedoraprojectTenable+1 more4Debian Linux FedoraTenable.sc+1 moreJun 17, 2026 Mar 29, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The package underscore from 1.13.0-0 and before 1.13.0-2, from 1.3.2 and before 1.12.1 are vulnerable to Arbitrary Code Injection via the template function, particularly when a variable property is passed as an argument...Show more |
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1). |
6Apache DebianFedoraproject+3 more16Activemq Banking Enterprise Default ManagementBanking Platform+13 moreJun 17, 2026 Mar 23, 2021 N/A· v4 9.9 CRITICAL· v3 6.5 MEDIUM· v2 XStream is a Java library to serialize objects to XML and back again. In XStream before version 1.4.16, there is a vulnerability which may allow a remote attacker who has sufficient rights to execute commands of the host...Show more |
4Debian GaleraclusterMariadb+1 more4Debian Linux MariadbPercona Server+1 moreJun 17, 2026 Mar 19, 2021 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for...Show more |
1Expressionengine 1Expressionengine Jun 17, 2026 Mar 15, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory. |
2Linux Redhat2Enterprise Linux Linux KernelJun 17, 2026 Mar 9, 2021 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confide...Show more |
1Sap 1Manufacturing Integration And Intelligence Jun 17, 2026 Mar 9, 2021 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 SAP MII allows users to create dashboards and save them as JSP through the SSCE (Self Service Composition Environment). An attacker can intercept a request to the server, inject malicious JSP code in the request and forw...Show more |
1Xmlhttprequest Project 1Xmlhttprequest Jun 17, 2026 Mar 5, 2021 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could resul...Show more |
The package total.js before 3.4.8 are vulnerable to Remote Code Execution (RCE) via set. |