← Back
CWE-94

7,055 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,055)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Netapp
1Ontap Select Deploy Administration Utility
Jun 17, 2026
Nov 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and u...Show more
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged user account.Show less
2Fedoraproject
Limnoria Project
2Fedora
Limnoria
Jun 17, 2026
Nov 16, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and i...Show more
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.Show less
1Coolpad
1Mega 5 Firmware
Jun 17, 2026
Nov 14, 2019
N/A· v4
8.1 HIGH· v3
9.3 HIGH· v2
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer...Show more
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an exported service named com.lovelyfont.manager.FontCoverService that allows any app co-located on the device to supply arbitrary commands to be executed as the system user. This app cannot be disabled by the user and the attack can be performed by a zero-permission app. In addition to the local attack surface, its accompanying app with a package name of com.ekesoo.lovelyhifonts makes network requests using HTTP and an attacker can perform a Man-in-the-Middle (MITM) attack on the connection to inject a command in a network response that will be executed as the system user by the com.lovelyfont.defcontainer app. Executing commands as the system user can allow a third-party app to video record the user's screen, factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the Graphical User Interface (GUI), and obtains the user's text messages, and more. Executing commands as the system user can allow a third-party app to factory reset the device, obtain the user's notifications, read the logcat logs, inject events in the GUI, change the default Input Method Editor (IME) (e.g., keyboard) with one contained within the attacking app that contains keylogging functionality, and obtains the user's text messages, and more.Show less
1Foswiki
1Foswiki
Nov 21, 2024
Nov 1, 2019
N/A· v4
9.8 CRITICAL· v3
6.8 MEDIUM· v2
Foswiki before 1.1.8 contains a code injection vulnerability in the MAKETEXT macro.
1Getcujo
1Smart Firewall
Nov 21, 2024
Oct 31, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from...Show more
An exploitable vulnerability exists in the safe browsing function of the CUJO Smart Firewall, version 7003. The flaw lies in the way the safe browsing function parses HTTP requests. The server hostname is extracted from captured HTTP/HTTPS requests and inserted as part of a Lua statement without prior sanitization, which results in arbitrary Lua script execution in the kernel. An attacker could send an HTTP request to exploit this vulnerability.Show less
1Postgresql
1Postgresql
Jun 17, 2026
Oct 29, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Postgresql Windows installer before versions 11.5, 10.10, 9.6.15, 9.5.19, 9.4.24 is vulnerable via bundled OpenSSL executing code from unprotected directory.
1Sagemath
1Sagemathcell
Jun 17, 2026
Oct 18, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underl...Show more
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating system, as demonstrated by an __import__('os').popen('whoami').read() line. NOTE: the vendor's position is that the product is "vulnerable by design" and the current behavior will be retainedShow less
1Qibosoft
1Qibosoft
Jun 17, 2026
Oct 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/...Show more
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadmin&action=addjf via CSRF, as demonstrated by a payload in the content parameter.Show less
1Zzzcms
1Zzzphp
Jun 17, 2026
Oct 14, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
1Mcafee
1Endpoint Security
Jun 17, 2026
Oct 9, 2019
N/A· v4
5.3 MEDIUM· v3
4.6 MEDIUM· v2
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSet...Show more
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attacker with access to the installer.Show less
1Centreon
1Centreon Web
Nov 21, 2024
Oct 8, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
getStats.php in Centreon Web before 2.8.28 allows authenticated attackers to execute arbitrary code via the ns_id parameter.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
1Sugarcrm
1Sugarcrm
Jun 17, 2026
Oct 7, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.