CWE-94
7,056 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,056)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. |
1Hot Formula Parser Project 1Hot Formula Parser Jun 17, 2026 Jan 11, 2020 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eva...Show more |
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can...Show more |
1Determine 1Contract Lifecycle Management Jun 17, 2026 Jan 5, 2020 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code...Show more |
1Mongo Express Project 1Mongo Express Jun 17, 2026 Dec 24, 2019 N/A· v4 9.9 CRITICAL· v3 9.0 HIGH· v2 mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment. |
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Man...Show more |
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier. |
1Tree Kill Project 1Tree Kill Jun 17, 2026 Dec 18, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command. |
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command. |
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input. |
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 17...Show more |
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver. |
1Safer Eval Project 1Safer Eval Jun 17, 2026 Dec 6, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 safer-eval is a npm package to sandbox the he evaluation of code used within the eval function. Affected versions of this package are vulnerable to Arbitrary Code Execution via generating a RangeError. |
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the...Show more |
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked...Show more |
1Maleck 1Image Uploader And Browser For Ckeditor Jun 17, 2026 Dec 2, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code. |
2Fedoraproject Freeipa2Fedora FreeipaJun 17, 2026 Nov 27, 2019 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, w...Show more |
4Debian OpensuseOracle+1 more4Debian Linux GraalvmLeap+1 moreJun 17, 2026 Nov 26, 2019 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can explo...Show more |
2Google Opensuse2Backports Sle ChromeJun 17, 2026 Nov 25, 2019 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Insufficient validation of untrusted input in Color Enhancer extension in Google Chrome prior to 78.0.3904.70 allowed a remote attacker to inject CSS into an HTML page via a crafted URL. |
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ inform...Show more |