← Back
CWE-94

6,465 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (6,465)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Wordpress
1Wordpress
May 6, 2026
Oct 27, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in wp-links/links.all.php in WordPress 0.70 allows remote attackers to execute arbitrary PHP code via a URL in the $abspath variable.
1Egroupware
1Egroupware
May 6, 2026
Oct 27, 2014
N/A· v4
N/A· v3
8.5 HIGH· v2
EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via cra...Show more
EGroupware Enterprise Line (EPL) before 1.1.20140505, EGroupware Community Edition before 1.8.007.20140506, and EGroupware before 14.1 beta allows remote authenticated administrators to execute arbitrary PHP code via crafted callback values to the call_user_func PHP function, as demonstrated using the newsettings[system] parameter. NOTE: this can be exploited by remote attackers by leveraging CVE-2014-2987.Show less
1Ghostscript
1Ghostscript
May 6, 2026
Oct 27, 2014
N/A· v4
N/A· v3
4.4 MEDIUM· v2
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vul...Show more
Untrusted search path vulnerability in Ghostscript 8.62 allows local users to execute arbitrary PostScript code via a Trojan horse Postscript library file in Encoding/ under the current working directory, a different vulnerability than CVE-2010-2055.Show less
1Samsung
2Findmymobile
Mobile
May 6, 2026
Oct 24, 2014
N/A· v4
N/A· v3
7.8 HIGH· v2
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with a...Show more
The Remote Controls feature on Samsung mobile devices does not validate the source of lock-code data received over a network, which makes it easier for remote attackers to cause a denial of service (screen locking with an arbitrary code) by triggering unexpected Find My Mobile network traffic.Show less
1Merethis
2Centreon
Centreon Enterprise Server
May 6, 2026
Oct 23, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) temp...Show more
displayServiceStatus.php in Centreon 2.5.1 and Centreon Enterprise Server 2.2 (fixed in Centreon web 2.5.3) allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) session_id or (2) template_id parameter, related to the command_line variable.Show less
1Sap
1Hana
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Eval injection in ide/core/base/server/net.xsjs in the Developer Workbench in SAP HANA allows remote attackers to execute arbitrary XSJX code via unspecified vectors.
2Jenkins
Redhat
2Jenkins
Openshift
May 6, 2026
Oct 16, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Jenkins before 1.583 and LTS before 1.565.3 allows remote attackers to execute arbitrary code via a crafted packet to the CLI channel.
1Scientificlinux
1Luci
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
6.0 MEDIUM· v2
Eval injection vulnerability in luci 0.26.0 allows remote authenticated users with certain permissions to execute arbitrary Python code via a crafted cluster configuration.
1Microsoft
9Windows 7
Windows 8Windows 8.1+6 more
Apr 22, 2026
Oct 15, 2014
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Go...Show more
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to execute arbitrary code via a crafted TrueType font, as exploited in the wild in October 2014, aka "TrueType Font Parsing Remote Code Execution Vulnerability."Show less
1Adobe
3Adobe Air
Adobe Air SdkFlash Player
May 6, 2026
Oct 15, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler be...Show more
Adobe Flash Player before 13.0.0.250 and 14.x and 15.x before 15.0.0.189 on Windows and OS X and before 11.2.202.411 on Linux, Adobe AIR before 15.0.0.293, Adobe AIR SDK before 15.0.0.302, and Adobe AIR SDK & Compiler before 15.0.0.302 allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE-2014-0564.Show less
1Rejetto
1Http File Server
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executab...Show more
The file comment feature in Rejetto HTTP File Server (hfs) 2.3c and earlier allows remote attackers to execute arbitrary code by uploading a file with certain invalid UTF-8 byte sequences that are interpreted as executable macro symbols.Show less
1X2engine
1X2engine
May 6, 2026
Oct 10, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafte...Show more
The actionSendErrorReport method in protected/controllers/SiteController.php in X2Engine 2.8 through 4.1.7 allows remote attackers to conduct PHP object injection and Server-Side Request Forgery (SSRF) attacks via crafted serialized data in the report parameter.Show less
1Eng
1Spagobi
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
6.8 MEDIUM· v2
The default configuration in the accessibility engine in SpagoBI 5.0.0 does not set FEATURE_SECURE_PROCESSING, which allows remote authenticated users to execute arbitrary Java code via a crafted XSL document.
1Bassmaster Project
1Bassmaster
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code vi...Show more
Eval injection vulnerability in the internals.batch function in lib/batch.js in the bassmaster plugin before 1.5.2 for the hapi server framework for Node.js allows remote attackers to execute arbitrary Javascript code via unspecified vectors.Show less
2Google
Redhat
6Chrome
Chrome OsEnterprise Linux Desktop Supplementary+3 more
May 6, 2026
Oct 8, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data,...Show more
Google Chrome before 38.0.2125.101 and Chrome OS before 38.0.2125.101 do not properly handle the interaction of IPC and Google V8, which allows remote attackers to execute arbitrary code via vectors involving JSON data, related to improper parsing of an escaped index by ParseJsonObject in json-parser.h.Show less
2Freepbx
Sangoma
2Freepbx
Freepbx
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth...Show more
htdocs_ari/includes/login.php in the ARI Framework module/Asterisk Recording Interface (ARI) in FreePBX before 2.9.0.9, 2.10.x, and 2.11 before 2.11.1.5 allows remote attackers to execute arbitrary code via the ari_auth cookie, related to the PHP unserialize function, as exploited in the wild in September 2014.Show less
1Gopro
2Gopro Hero
Gopro Hero Firmware
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
gpExec in GoPro HERO 3+ allows remote attackers to execute arbitrary files via a the (1) a1 or (2) a2 parameter in a start action.
1Rejetto
1Http File Server
Apr 22, 2026
Oct 7, 2014
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
1Cisco
1Adaptive Security Appliance Software
May 6, 2026
Oct 7, 2014
N/A· v4
N/A· v3
5.5 MEDIUM· v2
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated...Show more
The SSL VPN implementation in Cisco Adaptive Security Appliance (ASA) Software 9.2(.2.4) and earlier does not properly manage session information during creation of a SharePoint handler, which allows remote authenticated users to overwrite arbitrary RAMFS cache files or inject Lua programs, and consequently cause a denial of service (portal outage or system reload), via crafted HTTP requests, aka Bug ID CSCup54208.Show less
1Phpcompta
1Phpcompta/noalyss
May 6, 2026
Oct 6, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
backup.php in PHPCompta/NOALYSS before 6.7.2 allows remote attackers to execute arbitrary commands via shell metacharacters in the d parameter.