← Back
CWE-94

7,055 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,055)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Yikesinc
1Easy Forms For Mailchimp
Jun 17, 2026
Aug 22, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
1Rest Client Project
1Rest Client
Jun 17, 2026
Aug 19, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
1Microsoft
1Internet Explorer
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.5 HIGH· v3
7.6 HIGH· v2
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitr...Show more
A remote code execution vulnerability exists in the way that the scripting engine handles objects in memory in Internet Explorer. The vulnerability could corrupt memory in such a way that an attacker could execute arbitrary code in the context of the current user. An attacker who successfully exploited the vulnerability could gain the same user rights as the current user. If the current user is logged on with administrative user rights, an attacker who successfully exploited the vulnerability could take control of an affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability through Internet Explorer and then convince a user to view the website. An attacker could also embed an ActiveX control marked &quot;safe for initialization&quot; in an application or Microsoft Office document that hosts the IE rendering engine. The attacker could also take advantage of compromised websites and websites that accept or host user-provided content or advertisements. These websites could contain specially crafted content that could exploit the vulnerability. The security update addresses the vulnerability by modifying how the scripting engine handles objects in memory.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim s...Show more
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by enticing a victim to open a specially crafted file. The update addresses the vulnerability by correcting the way the Windows Jet Database Engine handles objects in memory.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected...Show more
A remote code execution vulnerability exists when the Windows font library improperly handles specially crafted embedded fonts. An attacker who successfully exploited the vulnerability could take control of the affected system. An attacker could then install programs; view, change, or delete data; or create new accounts with full user rights. Users whose accounts are configured to have fewer user rights on the system could be less impacted than users who operate with administrative user rights. There are multiple ways an attacker could exploit the vulnerability: In a web-based attack scenario, an attacker could host a specially crafted website that is designed to exploit the vulnerability and then convince users to view the website. An attacker would have no way to force users to view the attacker-controlled content. Instead, an attacker would have to convince users to take action, typically by getting them to click a link in an email or instant message that takes users to the attacker's website, or by opening an attachment sent through email. In a file-sharing attack scenario, an attacker could provide a specially crafted document file designed to exploit the vulnerability and then convince users to open the document file. The security update addresses the vulnerability by correcting how the Windows font library handles embedded fonts.Show less
1Microsoft
8Windows 10
Windows 7Windows 8.1+5 more
Jun 17, 2026
Aug 14, 2019
N/A· v4
7.5 HIGH· v3
9.3 HIGH· v2
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take cont...Show more
A remote code execution vulnerability exists when the Microsoft XML Core Services MSXML parser processes user input. An attacker who successfully exploited the vulnerability could run malicious code remotely to take control of the user’s system. To exploit the vulnerability, an attacker could host a specially crafted website designed to invoke MSXML through a web browser. However, an attacker would have no way to force a user to visit such a website. Instead, an attacker would typically have to convince a user to either click a link in an email message or instant message that would then take the user to the website. When Internet Explorer parses the XML content, an attacker could run malicious code remotely to take control of the user’s system. The update addresses the vulnerability by correcting how the MSXML parser processes user input.Show less
1Sap
1Commerce Cloud
Jun 17, 2026
Aug 14, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection...Show more
SAP Commerce Cloud (Mediaconversion Extension), versions 6.4, 6.5, 6.6, 6.7, 1808, 1811, 1905, allows an authenticated Backoffice/HMC user to inject code that can be executed by the application, leading to Code Injection. An attacker could thereby control the behavior of the application.Show less
1Pixelite
1Events Manager
Nov 21, 2024
Aug 13, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The events-manager plugin before 5.6 for WordPress has code injection.
1Frappe
1Frappe
Jun 17, 2026
Aug 12, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
1Kuaifan
1Kuaifancms
Jun 17, 2026
Aug 7, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
1Cpanel
1Cpanel
Nov 21, 2024
Aug 5, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 62.0.17 allows demo accounts to execute code via the Htaccess::setphppreference API (SEC-232).
1Magento
1Magento
Jun 17, 2026
Aug 2, 2019
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code. An authenticated user can bypass security protections th...Show more
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code. An authenticated user can bypass security protections that prevent arbitrary PHP script upload via form data injection.Show less
1Happypointcard
1Happypoint
Jun 17, 2026
Aug 1, 2019
N/A· v4
8.1 HIGH· v3
5.8 MEDIUM· v2
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An...Show more
When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an unsuspecting user to open a specific malicious URL.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
6.3 MEDIUM· v3
6.5 MEDIUM· v2
cPanel before 70.0.23 allows demo accounts to execute code via the Landing Page (SEC-405).
2Apache
Debian
2Debian Linux
Solr
Jun 17, 2026
Aug 1, 2019
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter....Show more
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of the DIH admin screen uses this to allow convenient debugging / development of a DIH config. Since a DIH config can contain scripts, this parameter is a security risk. Starting with version 8.2.0 of Solr, use of this parameter requires setting the Java System property "enable.dih.dataConfigParam" to true.Show less
1Cpanel
1Cpanel
Nov 21, 2024
Aug 1, 2019
N/A· v4
3.9 LOW· v3
3.3 LOW· v2
cPanel before 71.9980.37 allows code injection in the WHM cPAddons interface (SEC-394).
2Icedtea Web Project
Redhat
6Enterprise Linux Desktop
Enterprise Linux ServerEnterprise Linux Server Aus+3 more
Jun 17, 2026
Jul 31, 2019
N/A· v4
6.5 MEDIUM· v3
5.8 MEDIUM· v2
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to...Show more
It was found that icedtea-web though 1.7.2 and 1.8.2 did not properly sanitize paths from <jar/> elements in JNLP files. An attacker could trick a victim into running a specially crafted application and use this flaw to upload arbitrary files to arbitrary locations in the context of the user.Show less
1Dolibarr
1Dolibarr Erp/crm
Jun 17, 2026
Jul 29, 2019
N/A· v4
8.0 HIGH· v3
8.5 HIGH· v2
Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code...Show more
Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a setting on the same page, which specifies the inclusion of dynamic content. Thus, a lower privileged user of the application can execute code under the context and permissions of the underlying web server.Show less
1Simple Captcha2 Project
1Simple Captcha2
Jun 17, 2026
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
1Datagrid Project
1Datagrid
Jun 17, 2026
Jul 26, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.