← Back
CWE-94

7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,056)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Djv Project
1Djv
Jun 17, 2026
Jan 4, 2021
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
1Zzzcms
1Zzzphp
Jun 17, 2026
Dec 18, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
1Golang
1Go
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.
3Fedoraproject
GolangNetapp
4Cloud Insights Telegraf Agent
FedoraGo+1 more
Jun 17, 2026
Nov 18, 2020
N/A· v4
7.5 HIGH· v3
5.1 MEDIUM· v2
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
1Microfocus
1Arcsight Logger
Jun 17, 2026
Nov 17, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Arbitrary code execution vulnerability on Micro Focus ArcSight Logger product, affecting all version prior to 7.1.1. The vulnerability could be remotely exploited resulting in the execution of arbitrary code.
1Cmsuno Project
1Cmsuno
Jun 17, 2026
Nov 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of thi...Show more
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, authenticated user can run command on the server.Show less
1Cmsuno Project
1Cmsuno
Jun 17, 2026
Nov 13, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Nov 12, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code exe...Show more
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a configured SugarCRM instance via crafted HTTP requests. (This is exploitable even after installation is completed.).Show less
1Microsoft
1Teams
Jun 17, 2026
Nov 11, 2020
N/A· v4
7.8 HIGH· v3
4.4 MEDIUM· v2
Microsoft Teams Remote Code Execution Vulnerability
1Vbulletin
1Vbulletin
Jun 17, 2026
Oct 30, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-1675...Show more
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2020-7373 is a duplicate of CVE-2020-17496. CVE-2020-17496 is the preferred CVE ID to track this vulnerability.Show less
1Mintegral
1Mintegraladsdk
Jun 17, 2026
Oct 19, 2020
N/A· v4
7.1 HIGH· v3
10.0 HIGH· v2
This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitra...Show more
This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user device.Show less
1Xwiki
1Xwiki
Jun 17, 2026
Oct 16, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java obj...Show more
In XWiki before version 12.5 and 11.10.6, any user with SCRIPT right (EDIT right before XWiki 7.4) can gain access to the application server Servlet context which contains tools allowing to instantiate arbitrary Java objects and invoke methods that may lead to arbitrary code execution. This is patched in XWiki 12.5 and XWiki 11.10.6.Show less
1Lenovo
1Cloud Networking Operating System
Jun 17, 2026
Oct 14, 2020
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default...Show more
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerable unless enabled. When enabled, it is only vulnerable where attached to a VRF and as allowed by defined ACLs. Lenovo strongly recommends upgrading to a non-vulnerable CNOS release. Where not possible, Lenovo recommends disabling the REST API management interface or restricting access to the management VRF and further limiting access to authorized management stations via ACL.Show less
1Oauth2 Server Project
1Oauth2 Server
Nov 21, 2024
Oct 4, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extens...Show more
oauth2-server (aka node-oauth2-server) through 3.1.1 implements OAuth 2.0 without PKCE. It does not prevent authorization code injection. This is similar to CVE-2020-7692. NOTE: the vendor states 'As RFC7636 is an extension, I think the claim in the Readme of "RFC 6749 compliant" is valid and not misleading and I also therefore wouldn't describe this as a "vulnerability" with the library per se.Show less
1Hpe
1Kvm Ip Console Switch G2 Firmware
Jun 17, 2026
Oct 2, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
1Pluxml
1Pluxml
Jun 17, 2026
Oct 2, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
1Openmediavault
1Openmediavault
Jun 17, 2026
Oct 2, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Success...Show more
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation allows arbitrary command execution on the underlying operating system as root.Show less
2Debian
Nette
2Application
Debian Linux
Jun 17, 2026
Oct 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC F...Show more
Nette versions before 2.0.19, 2.1.13, 2.2.10, 2.3.14, 2.4.16, 3.0.6 are vulnerable to an code injection attack by passing specially formed parameters to URL that may possibly leading to RCE. Nette is a PHP/Composer MVC Framework.Show less
1Ivanti
2Connect Secure
Policy Secure
Jun 17, 2026
Sep 30, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
1Handlebarsjs
1Handlebars
Jun 17, 2026
Sep 30, 2020
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. Th...Show more
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to run arbitrary code on a server processing Handlebars templates or in a victim's browser (effectively serving as XSS).Show less