← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Crowd
Nov 21, 2024
Mar 29, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
The administration SMTP configuration resource in Atlassian Crowd before version 2.10.2 allows remote attackers with administration rights to execute arbitrary code via a JNDI injection.
1Microfocus
1Solutions Business Manager
Nov 21, 2024
Mar 27, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Unauthenticated remote code execution issue in Micro Focus Solutions Business Manager (SBM) (formerly Serena Business Manager (SBM)) versions prior to 11.5.
1Hospira
1Mednet
Nov 3, 2025
Mar 26, 2019
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira ha...Show more
Hospira MedNet software version 5.8 and prior uses vulnerable versions of the JBoss Enterprise Application Platform software that may allow unauthenticated users to execute arbitrary code on the target system. Hospira has developed a new version of the MedNet software, MedNet 6.1. Existing versions of MedNet can be upgraded to MedNet 6.1.Show less
1Elastic
1Kibana
Jun 17, 2026
Mar 25, 2019
N/A· v4
9.0 CRITICAL· v3
9.3 HIGH· v2
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that wil...Show more
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.Show less
2Elastic
Redhat
2Kibana
Openshift Container Platform
Jun 17, 2026
Mar 25, 2019
N/A· v4
10.0 CRITICAL· v3
10.0 HIGH· v2
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascrip...Show more
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could possibly lead to an attacker executing arbitrary commands with permissions of the Kibana process on the host system.Show less
1Baigo
1Baigo Sso
Jun 17, 2026
Mar 24, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
baigoStudio baigoSSO v3.0.1 allows remote attackers to execute arbitrary PHP code via the first form field of a configuration screen, because this code is written to the BG_SITE_NAME field in the opt_base.inc.php file.
1Morgan Project
1Morgan
Jun 17, 2026
Mar 21, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
1Sdcms
1Sdcms
Jun 17, 2026
Mar 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. This occurs because some dangerous PHP fu...Show more
An issue was discovered in SDCMS V1.7. In the \app\admin\controller\themecontroller.php file, the check_bad() function's filtering is not strict, resulting in PHP code execution. This occurs because some dangerous PHP functions (such as "eval") are blocked but others (such as "system") are not, and because ".php" is blocked but ".PHP" is not blocked.Show less
1Simplemachines
1Simple Machines Forum
Nov 21, 2024
Mar 7, 2019
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
Simple Machines Forum (SMF) 2.0.4 allows PHP Code Injection via the index.php?action=admin;area=languages;sa=editlang dictionary parameter.
1Baigo
1Baigo Cms
Jun 17, 2026
Feb 28, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in baigo CMS 2.1.1. There is a vulnerability that allows remote attackers to execute arbitrary code. A BG_SITE_NAME parameter with malicious code can be written into the opt_base.inc.php file.
1Irisnet
1Irisnet Crypto
Jun 17, 2026
Feb 25, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In irisnet-crypto before 1.1.7 for IRISnet, the util/utils.js file allows code execution because of unsafe eval usage.
3Opensourcebms
ThinkphpZzzcms
3Open Source Background Management System
ThinkphpZzzphp
Jun 17, 2026
Feb 24, 2019
N/A· v4
8.8 HIGH· v3
9.3 HIGH· v2
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed...Show more
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.Show less
1Intel
1Usb 3.0 Extensible Host Controller Driver
Nov 21, 2024
Feb 18, 2019
N/A· v4
6.7 MEDIUM· v3
4.6 MEDIUM· v2
Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v2 may allow a user to potentially enable escalation of privilege via lo...Show more
Code injection vulnerability in the installer for Intel(R) USB 3.0 eXtensible Host Controller Driver for Microsoft Windows 7 before version 5.0.4.43v2 may allow a user to potentially enable escalation of privilege via local access.Show less
2Opensuse
Pocoo
2Jinja2
Leap
Jun 17, 2026
Feb 15, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker...Show more
An issue was discovered in Jinja2 2.10. The from_string function is prone to Server Side Template Injection (SSTI) where it takes the "source" parameter as a template object, renders it, and then returns it. The attacker can exploit it with {{INJECTION COMMANDS}} in a URI. NOTE: The maintainer and multiple third parties believe that this vulnerability isn't valid because users shouldn't use untrusted templates without sandboxingShow less
1Taogogo
1Taocms
Jun 17, 2026
Feb 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
1Nibbleblog
1Nibbleblog
Jun 17, 2026
Feb 11, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
1Frog Cms Project
1Frog Cms
Nov 21, 2024
Feb 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
admin/?/plugin/file_manager in Frog CMS 0.9.5 allows PHP code execution by creating a new .php file containing PHP code, and then visiting this file under the public/ URI.
1Frog Cms Project
1Frog Cms
Nov 21, 2024
Feb 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Frog CMS 0.9.5 allows PHP code execution by visiting admin/?/page/edit/1 and inserting additional <?php lines.
1Frog Cms Project
1Frog Cms
Nov 21, 2024
Feb 11, 2019
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
Frog CMS 0.9.5 allows PHP code execution via <?php to the admin/?/layout/edit/1 URI.
1Xerox
29Workcentre 3655 Firmware
Workcentre 3655i FirmwareWorkcentre 5845 Firmware+26 more
Nov 21, 2024
Feb 10, 2019
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute...Show more
An issue was discovered on Xerox WorkCentre 3655, 3655i, 58XX, 58XXi, 59XX, 59XXi, 6655, 6655i, 72XX, 72XXi, 78XX, 78XXi, 7970, 7970i, EC7836, and EC7856 devices before R18-05 073.xxx.0487.15000. An attacker can execute PHP code by leveraging a writable file.Show less