CWE-94
7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,056)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Dell 2Emc Data Protection Advisor Emc Integrated Data Protection Appliance FirmwareJun 17, 2026 Mar 18, 2020 N/A· v4 7.2 HIGH· v3 9.0 HIGH· v2 Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated...Show more |
Codiad Web IDE through 2.8.4 allows PHP Code injection. |
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype. |
admin/save-settings.php in Chadha PHPKB Standard Multi-Language 9 allows remote attackers to achieve Code Execution by injecting PHP code into any POST parameter when saving global settings. |
1Fatfreeframework 1Fat Free Framework Jun 17, 2026 Mar 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method. |
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, s...Show more |
3Debian LinuxfoundationOracle10Communications Application Session Controller Communications Policy ManagementCommunications Pricing Design Center+7 moreJun 17, 2026 Mar 10, 2020 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes,...Show more |
1Themerex 63Addons Aldo Gutenberg Wordpress Blog ThemeAmuli+60 moreJun 17, 2026 Mar 10, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ThemeREX Addons plugin before 2020-03-09 for WordPress lacks access control on the /trx_addons/v2/get/sc_layout REST API endpoint, allowing for PHP functions to be executed by any users, because includes/plugin.rest-...Show more |
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of opening other components. Attackers need to induce users to open speci...Show more |
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise...Show more |
1Pdf Image Project 1Pdf Image Jun 17, 2026 Feb 28, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input. |
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service. |
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges. |
3Debian FedoraprojectHorde3Debian Linux FedoraGroupwareJun 17, 2026 Feb 17, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution. |
1Script Manager Project 1Script Manager Jun 17, 2026 Feb 14, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code. |
A Code Execution Vulnerability exists in OpenX Ad Server 2.8.10 due to a backdoor in flowplayer-3.1.1.min.js library, which could let a remote malicious user execute arbitrary PHP code |
1Restful Web Services Project 1Restful Web Services Nov 21, 2024 Feb 11, 2020 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The RESTful Web Services (restws) module 7.x-1.x before 7.x-1.4 and 7.x-2.x before 7.x-2.1 for Drupal does not properly restrict access to entity write operations, which makes it easier for remote authenticated users wit...Show more |
4Apache CanonicalDebian+1 more4Camel Debian LinuxHtmlunit+1 moreJun 17, 2026 Feb 11, 2020 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded...Show more |
1Omniauth Weibo Oauth2 Project 1Omniauth Weibo Oauth2 Jun 17, 2026 Feb 7, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected. |
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string. |