CWE-94
7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,056)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1. |
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0...Show more |
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An...Show more |
1Sap 1Adaptive Server Enterprise Backup Server Jun 17, 2026 May 12, 2020 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Inje...Show more |
1Sap 1Adaptive Server Enterprise Jun 17, 2026 May 12, 2020 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure...Show more |
1Barrelstrengthdesign 1Sprout Forms Jun 17, 2026 May 7, 2020 N/A· v4 6.3 MEDIUM· v3 6.5 MEDIUM· v2 In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0...Show more |
1Assaabloy 1Yale Wipc 301w Firmware Jun 17, 2026 May 7, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands. |
1Node Rules Project 1Node Rules Jun 17, 2026 Apr 27, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization. |
1Grandstream 6Gxp1610 Firmware Gxp1615 FirmwareGxp1620 Firmware+3 moreJun 17, 2026 Apr 14, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field i...Show more |
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared....Show more |
1Alienform2 Project 1Alienform2 Jun 17, 2026 Apr 1, 2020 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exp...Show more |
1Marchnetworks 1Command Client Jun 17, 2026 Apr 1, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects. |
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors. |
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors. |
3Debian FedoraprojectRedhat5Ansible Ansible TowerDebian Linux+2 moreJun 17, 2026 Mar 24, 2020 N/A· v4 7.1 HIGH· v3 3.6 LOW· v2 A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled,...Show more |
1Schneider Electric 11Andover Continuum 5720 Firmware Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 moreJun 17, 2026 Mar 23, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker i...Show more |
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” i...Show more |
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment. |
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker. |
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode. |