CWE-94
7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,044)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Twig before 2.4.4 allows Server-Side Template Injection (SSTI) via the search search_key parameter. NOTE: the vendor points out that Twig itself is not a web application and states that it is the responsibility of web ap...Show more |
1Trendmicro 6Antivirus + Security Internet SecurityMaximum Security+3 moreNov 21, 2024 Jul 6, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 A vulnerability in Trend Micro Maximum Security's (Consumer) 2018 (versions 12.0.1191 and below) User-Mode Hooking (UMH) driver could allow an attacker to create a specially crafted packet that could alter a vulnerable s...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 6, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the secu...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 6, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the secu...Show more |
1Ibm 2Rational Collaborative Lifecycle Management Rational Quality ManagerNov 21, 2024 Jul 6, 2018 N/A· v4 5.4 MEDIUM· v3 3.5 LOW· v2 IBM Quality Manager (RQM) 5.0.x and 6.0 through 6.0.5 are vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the secu...Show more |
2Canonical Debian2Devscripts Ubuntu LinuxNov 21, 2024 Jul 1, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 scripts/grep-excuses.pl in Debian devscripts through 2.18.3 allows code execution through unsafe YAML loading because YAML::Syck is used without a configuration that prevents unintended blessing. |
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the Upload screen. |
onefilecms.php in OneFileCMS through 2012-04-14 might allow attackers to execute arbitrary PHP code via a .php filename on the New File screen. |
1Redhat 1Jboss Enterprise Application Platform Nov 21, 2024 Jun 27, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 It was found that the JAXP implementation used in JBoss EAP 7.0 for XSLT processing is vulnerable to code injection. An attacker could use this flaw to cause remote code execution if they are able to provide XSLT content...Show more |
1Centreon 2Centreon Centreon WebNov 21, 2024 Jun 25, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 There is Remote Code Execution in Centreon 3.4.6 including Centreon Web 2.8.23 via the RPN value in the Virtual Metric form in centreonGraph.class.php. |
An issue was discovered in MetInfo 6.0.0. install\index.php allows remote attackers to write arbitrary PHP code into config_db.php, a different vulnerability than CVE-2018-7271. |
1Mcafee 1Mcafee Threat Intelligence Exchange Nov 21, 2024 Jun 13, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Code Injection vulnerability in the ePolicy Orchestrator (ePO) extension in McAfee Threat Intelligence Exchange (TIE) Server 2.1.0 and earlier allows remote attackers to execute arbitrary HTML code to be reflected in the...Show more |
4Canonical DebianMozilla+1 more9Debian Linux Enterprise Linux DesktopEnterprise Linux Server+6 moreNov 25, 2025 Jun 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF view...Show more |
3Debian MozillaRedhat8Debian Linux Enterprise LinuxEnterprise Linux Desktop+5 moreNov 25, 2025 Jun 11, 2018 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 The Developer Tools feature suffers from a XUL injection vulnerability due to improper sanitization of the web page source code. In the worst case, this could allow arbitrary code execution when opening a malicious page...Show more |
1Puppet 3Pe Razor Server Puppet EnterpriseRazor ServerJun 17, 2026 Jun 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The previous version of Puppet Enterprise 2018.1 is vulnerable to unsafe code execution when upgrading pe-razor-server. Affected releases are Puppet Enterprise: 2018.1.x versions prior to 2018.1.1 and razor-server and pe...Show more |
1Crestron 1Crestron Toolbox Protocol Firmware Nov 21, 2024 Jun 8, 2018 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Crestron TSW-1060, TSW-760, TSW-560, TSW-1060-NC, TSW-760-NC, and TSW-560-NC devices before 2.001.0037.001 allow unauthenticated remote code execution via a Bash shell service in Crestron Toolbox Protocol (CTP). |
Based on details posted by the ElectronJS team; A remote code execution vulnerability has been discovered in Google Chromium that affects all recent versions of Electron. Any Electron app that accesses remote content is...Show more |
dns-sync is a sync/blocking dns resolver. If untrusted user input is allowed into the resolve() method then command injection is possible. |
A remote code execution vulnerability was found within the pg module when the remote database or query specifies a specially crafted column name. There are 2 likely scenarios in which one would likely be vulnerable. 1) E...Show more |
Growl adds growl notification support to nodejs. Growl before 1.10.2 does not properly sanitize input before passing it to exec, allowing for arbitrary command execution. |