← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Gps Server
1Gps Tracking Software
Nov 21, 2024
Jan 2, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log view...Show more
The writeLog function in fn_common.php in gps-server.net GPS Tracking Software (self hosted) through 3.0 allows remote attackers to inject arbitrary PHP code via a crafted request that is mishandled during admin log viewing, as demonstrated by <?php system($_GET[cmd]); ?> in a login request.Show less
1Readymade Video Sharing Script Project
1Readymade Video Sharing Script
May 13, 2026
Dec 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
Readymade Video Sharing Script 3.2 has HTML Injection via the single-video-detail.php comment parameter.
1Sap
2Business Application Software Integrated Solution
Netweaver Internet Transaction Server
May 13, 2026
Dec 12, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application...Show more
SAP NetWeaver Internet Transaction Server (ITS), SAP Basis from 7.00 to 7.02, 7.30, 7.31, 7.40, from 7.50 to 7.52, allows an attacker with administrator credentials to inject code that can be executed by the application and thereby control the behavior of the application.Show less
1Ibm
1Infosphere Biginsights
May 13, 2026
Dec 7, 2017
N/A· v4
4.4 MEDIUM· v3
3.6 LOW· v2
IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.
1Puppet
1Puppet Agent
May 13, 2026
Dec 6, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug...Show more
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduced in Puppet Agent 1.3.0.Show less
1Squiz
1Matrix
May 13, 2026
Nov 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Squiz Matrix before 5.3.6.1 and 5.4.x before 5.4.1.3. Authenticated users with permissions to edit design assets can cause Remote Code Execution (RCE) via a maliciously crafted time_format tag.
1Typed Function Project
1Typed Function
May 13, 2026
Nov 27, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
typed-function before 0.10.6 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
1Mathjs
1Math.js
May 13, 2026
Nov 27, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
2Debian
Otrs
2Debian Linux
Otrs
May 13, 2026
Nov 21, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell...Show more
Code injection exists in Kernel/System/Spelling.pm in Open Ticket Request System (OTRS) 5 before 5.0.24, 4 before 4.0.26, and 3.3 before 3.3.20. In the agent interface, an authenticated remote attacker can execute shell commands as the webserver user via URL manipulation.Show less
5Busybox
CanonicalDebian+2 more
6Busybox
Debian LinuxEsxi+3 more
May 13, 2026
Nov 20, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any...Show more
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file writes, or other attacks.Show less
1Phpcaptcha
1Securimage
May 13, 2026
Nov 18, 2017
N/A· v4
6.1 MEDIUM· v3
4.3 MEDIUM· v2
HTML Injection in Securimage 3.6.4 and earlier allows remote attackers to inject arbitrary HTML into an e-mail message body via the $_SERVER['HTTP_USER_AGENT'] parameter to example_form.ajax.php or example_form.php.
1Updraftplus
1Updraftplus
May 13, 2026
Nov 17, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associat...Show more
The UpdraftPlus plugin through 1.13.12 for WordPress allows remote PHP code execution because the plupload_action function in /wp-content/plugins/updraftplus/admin.php has a race condition before deleting a file associated with the name parameter. NOTE: the vendor reports that this does not cross a privilege boundaryShow less
1Octobercms
1October
May 13, 2026
Nov 17, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
1Zetacomponents
1Mail
May 13, 2026
Nov 15, 2017
N/A· v4
8.1 HIGH· v3
6.8 MEDIUM· v2
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to exec...Show more
The send function in the ezcMailMtaTransport class in Zeta Components Mail before 1.8.2 does not properly restrict the set of characters used in the ezcMail returnPath property, which might allow remote attackers to execute arbitrary code via a crafted email address, as demonstrated by one containing "-X/path/to/wwwroot/file.php."Show less
1Cacti
1Cacti
May 13, 2026
Nov 15, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Cacti before 1.0.0 allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via a crafted serialized object, related to calling unserialize(stripslashes()).
1Cmsmadesimple
1Cms Made Simple
May 13, 2026
Nov 10, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
In CMS Made Simple 2.1.6, there is Server-Side Template Injection via the cntnt01detailtemplate parameter.
1Enalean
1Tuleap
May 13, 2026
Oct 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily...Show more
An issue was discovered in Enalean Tuleap 9.6 and prior versions. The vulnerability exists because the User::getRecentElements() method is using the unserialize() function with a preference value that can be arbitrarily manipulated by malicious users through the REST API interface, and this can be exploited to inject arbitrary PHP objects into the application scope, allowing an attacker to perform a variety of attacks (including but not limited to Remote Code Execution).Show less
1Artica
1Pandora Fms
May 13, 2026
Oct 27, 2017
N/A· v4
7.2 HIGH· v3
9.0 HIGH· v2
Artica Pandora FMS version 7.0 is vulnerable to remote PHP code execution through the manager files function. This is only exploitable by administrators who upload a PHP file.
1Mobatek
1Mobaxterm
May 13, 2026
Oct 16, 2017
N/A· v4
9.8 CRITICAL· v3
10.0 HIGH· v2
The TELNET service in Mobatek MobaXterm 10.4 does not require authentication, which allows remote attackers to execute arbitrary commands via TCP port 23.
1Hp
1Ucmdb Foundation Software
May 13, 2026
Oct 5, 2017
N/A· v4
8.8 HIGH· v3
6.8 MEDIUM· v2
A remote code execution vulnerability in HP UCMDB Foundation Software versions 10.10, 10.11, 10.20, 10.21, 10.22, 10.30, 10.31, 10.32, and 10.33, could be remotely exploited to allow code execution.