← Back
CWE-94

7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,056)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Fudforum
1Fudforum
Nov 21, 2024
Jan 27, 2020
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
1Hot Formula Parser Project
1Hot Formula Parser
Jun 17, 2026
Jan 11, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eva...Show more
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value of the formula is taken from user-controlled input, it may allow attackers to run arbitrary commands on the server.Show less
1Mojohaus
1Exec Maven
Jun 17, 2026
Jan 6, 2020
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can...Show more
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbitrary command-line arguments in an arguments element).Show less
1Determine
1Contract Lifecycle Management
Jun 17, 2026
Jan 5, 2020
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code...Show more
An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the underlying server.Show less
1Mongo Express Project
1Mongo Express
Jun 17, 2026
Dec 24, 2019
N/A· v4
9.9 CRITICAL· v3
9.0 HIGH· v2
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
1Sfu
1Open Journal System
Jun 17, 2026
Dec 19, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Man...Show more
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a crafted URL, because unserialize is used.Show less
1Sonicwall
1Sma 100 Firmware
Jun 17, 2026
Dec 19, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
1Tree Kill Project
1Tree Kill
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
1Treekill Project
1Treekill
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
1Node Df Project
1Node Df
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
1Ibm
1Planning Analytics
Jun 17, 2026
Dec 18, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 17...Show more
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.Show less
1Phpfastcache
1Phpfastcache
Jun 17, 2026
Dec 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
1Safer Eval Project
1Safer Eval
Jun 17, 2026
Dec 6, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError.
1Okay Cms
1Okaycms
Jun 17, 2026
Dec 3, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the...Show more
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter, and second in api/Comparison.php via the cookie comparison.Show less
1Mcafee
1Webadvisor
Jun 17, 2026
Dec 3, 2019
N/A· v4
6.5 MEDIUM· v3
4.3 MEDIUM· v2
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked...Show more
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully crafted web site.Show less
1Maleck
1Image Uploader And Browser For Ckeditor
Jun 17, 2026
Dec 2, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
2Fedoraproject
Freeipa
2Fedora
Freeipa
Jun 17, 2026
Nov 27, 2019
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, w...Show more
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerberos key data. An unauthenticated attacker who could trigger parsing of the krb principal key could cause the IPA server to crash or in some conditions, cause arbitrary code to be executed on the server hosting the IPA server.Show less
4Debian
OpensuseOracle+1 more
4Debian Linux
GraalvmLeap+1 more
Jun 17, 2026
Nov 26, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can explo...Show more
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.Show less
2Google
Opensuse
2Backports Sle
Chrome
Jun 17, 2026
Nov 25, 2019
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL.
1Zte
1Zxcdn Iamweb Firmware
Jun 17, 2026
Nov 22, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ inform...Show more
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.Show less