← Back
CWE-94

7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,056)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Logkitty Project
1Logkitty
Jun 17, 2026
May 15, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.
1Xwiki
1Xwiki
Jun 17, 2026
May 12, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0...Show more
In XWiki Platform 7.2 through 11.10.2, registered users without scripting/programming permissions are able to execute python/groovy scripts while editing personal dashboards. This has been fixed 11.3.7 , 11.10.3 and 12.0.Show less
1Sap
1Application Server
Jun 17, 2026
May 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An...Show more
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application and the whole ABAP system leading to Code Injection.Show less
1Sap
1Adaptive Server Enterprise Backup Server
Jun 17, 2026
May 12, 2020
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Inje...Show more
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.Show less
1Sap
1Adaptive Server Enterprise
Jun 17, 2026
May 12, 2020
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure...Show more
Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attacker to read, modify, delete restricted data on connected servers, leading to Code Injection.Show less
1Barrelstrengthdesign
1Sprout Forms
Jun 17, 2026
May 7, 2020
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0...Show more
In Sprout Forms before 3.9.0, there is a potential Server-Side Template Injection vulnerability when using custom fields in Notification Emails which could lead to the execution of Twig code. This has been fixed in 3.9.0.Show less
1Assaabloy
1Yale Wipc 301w Firmware
Jun 17, 2026
May 7, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
ASSA ABLOY Yale WIPC-301W 2.x.2.29 through 2.x.2.43_p1 devices allow Eval Injection of commands.
1Node Rules Project
1Node Rules
Jun 17, 2026
Apr 27, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
1Grandstream
6Gxp1610 Firmware
Gxp1615 FirmwareGxp1620 Firmware+3 more
Jun 17, 2026
Apr 14, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field i...Show more
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface. When the VPN's connection is established, the user defined script is executed with root privileges.Show less
1Hitachienergy
1Esoms
Jun 17, 2026
Apr 2, 2020
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared....Show more
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack scenario would be unauthorized code execution via text interpreted as JavaScript.Show less
1Alienform2 Project
1Alienform2
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exp...Show more
Jon Hedley AlienForm2 (typically installed as af.cgi or alienform.cgi) 2.0.2 is vulnerable to Remote Command Execution via eval injection, a different issue than CVE-2002-0934. An unauthenticated, remote attacker can exploit this via a series of crafted requests.Show less
1Marchnetworks
1Command Client
Jun 17, 2026
Apr 1, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The connection initiation process in March Networks Command Client before 2.7.2 allows remote attackers to execute arbitrary code via crafted XAML objects.
1Cutephp
1Cutenews
Jun 17, 2026
Mar 25, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
1Mailform
1Mailform
Jun 17, 2026
Mar 25, 2020
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
3Debian
FedoraprojectRedhat
5Ansible
Ansible TowerDebian Linux+2 more
Jun 17, 2026
Mar 24, 2020
N/A· v4
7.1 HIGH· v3
3.6 LOW· v2
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled,...Show more
A flaw was found in Ansible Engine, all versions 2.7.x, 2.8.x and 2.9.x prior to 2.7.17, 2.8.9 and 2.9.6 respectively, when using ansible_facts as a subkey of itself and promoting it to a variable when inject is enabled, overwriting the ansible_facts after the clean. An attacker could take advantage of this by altering the ansible_facts, such as ansible_hosts, users and any other key data which would lead into privilege escalation or code injection.Show less
1Schneider Electric
11Andover Continuum 5720 Firmware
Andover Continuum 5740 FirmwareAndover Continuum 9200 Firmware+8 more
Jun 17, 2026
Mar 23, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker i...Show more
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an application's processing of XML data.Show less
1Eaton
1Ups Companion
Jun 17, 2026
Mar 23, 2020
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” i...Show more
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results in arbitrary code execution on the machine where software is installed.Show less
1Nextcloud
1Desktop
Jun 17, 2026
Mar 20, 2020
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
1Blamer Project
1Blamer
Jun 17, 2026
Mar 20, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
1Phpbb
1Phpbb
Jun 17, 2026
Mar 20, 2020
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.