CWE-94
7,057 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,057)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Pug is an npm package which is a high-performance template engine. In pug before version 3.0.1, if a remote attacker was able to control the `pretty` option of the pug compiler, e.g. if you spread a user provided object...Show more |
3Debian FedoraprojectSaltstack3Debian Linux FedoraSaltJun 17, 2026 Feb 27, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks. |
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system. |
2Debian Smarty2Debian Linux SmartyJun 17, 2026 Feb 22, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring. |
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and cont...Show more |
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel...Show more |
4Lodash NetappOracle+1 more23Active Iq Unified Manager Banking Corporate Lending Process ManagementBanking Credit Facilities Process Management+20 moreJun 17, 2026 Feb 15, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function. |
1Trendmicro 8Antivirus+ Security 2020 Antivirus+ Security 2021Internet Security 2020+5 moreJun 17, 2026 Feb 10, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An...Show more |
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php. |
SAP Commerce Cloud, versions - 1808,1811,1905,2005,2011, enables certain users with required privileges to edit drools rules, an authenticated attacker with this privilege will be able to inject malicious code in the dro...Show more |
1Smartfoxserver 1Smartfoxserver Jun 17, 2026 Feb 9, 2021 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/adm...Show more |
1Carrierwave Project 1Carrierwave Jun 17, 2026 Feb 8, 2021 N/A· v4 8.8 HIGH· v3 7.5 HIGH· v2 CarrierWave is an open-source RubyGem which provides a simple and flexible way to upload files from Ruby applications. In CarrierWave before versions 1.3.2 and 2.1.1, there is a code injection vulnerability. The "#manipu...Show more |
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution. |
angular-expressions is "angular's nicest part extracted as a standalone module for the browser and node". In angular-expressions before version 1.1.2 there is a vulnerability which allows Remote Code Execution if you cal...Show more |
1Opensolution 2Quick.cart Quick.cmsJun 17, 2026 Jan 28, 2021 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. |
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication. |
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, there is a critical vulnerability involving the build endpoint parameters. InputSpec is used to define parameters of a Build spec. It does so by us...Show more |
OneDev is an all-in-one devops platform. In OneDev before version 4.0.3, There is a vulnerability that enabled pre-auth server side template injection via Bean validation message tampering. Full details in the reference...Show more |
1Sap 2Business Warehouse Bw/4hanaJun 17, 2026 Jan 12, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 SAP Business Warehouse, versions 700, 701, 702, 711, 730, 731, 740, 750, 782 and SAP BW/4HANA, versions 100, 200, allow a low privileged attacker to inject code using a remote enabled function module over the network. Vi...Show more |
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check...Show more |