← Back
CWE-94

7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,044)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Atlassian
1Bamboo
May 13, 2026
Oct 3, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
1Norton
1Remove & Reinstall
May 13, 2026
Sep 28, 2017
N/A· v4
7.0 HIGH· v3
4.4 MEDIUM· v2
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. D...Show more
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to locate the DLL. The vulnerability can be exploited by a simple file write (or potentially an over-write) which results in a foreign DLL running under the context of the application. A Norton Remove & Reinstall update, version 4.4.0.58, has been released which addresses the aforementioned vulnerability.Show less
1Genixcms
1Genixcms
May 13, 2026
Sep 27, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module.
1Vbseo
1Vbseo
May 13, 2026
Sep 15, 2017
N/A· v4
8.8 HIGH· v3
9.0 HIGH· v2
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
1Ansible Vault Project
1Ansible Vault
May 13, 2026
Sep 14, 2017
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert...Show more
An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert python into the vault to trigger this vulnerability.Show less
1Microsoft
1.net Framework
Apr 22, 2026
Sep 13, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
1Alegrocart
1Alegrocart
May 13, 2026
Sep 11, 2017
N/A· v4
7.2 HIGH· v3
6.5 MEDIUM· v2
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path param...Show more
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admin2.Show less
1Gwolle Guestbook Project
1Gwolle Guestbook
May 13, 2026
Sep 11, 2017
N/A· v4
9.0 CRITICAL· v3
6.8 MEDIUM· v2
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspa...Show more
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to frontend/captcha/ajaxresponse.php. NOTE: this can also be leveraged to include and execute arbitrary local files via directory traversal sequences regardless of whether allow_url_include is enabled.Show less
1Helpdezk
1Helpdezk
May 13, 2026
Sep 5, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory.
1Mcafee
2Livesafe
Security Scan Plus
May 13, 2026
Sep 1, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers...Show more
A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers to perform a malicious file execution via a HTTP backend-response.Show less
1Soplanning
1Soplanning
May 13, 2026
Aug 31, 2017
N/A· v4
5.3 MEDIUM· v3
3.5 LOW· v2
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, o...Show more
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2 is being used, the configuration database is down, and smarty/templates_c is not writable to execute arbitrary php code via a crafted database name.Show less
3Debian
RedhatRubygems
8Debian Linux
Enterprise Linux DesktopEnterprise Linux Server+5 more
May 13, 2026
Aug 31, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
1Ibm
1Emptoris Services Procurement
May 13, 2026
Aug 30, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allo...Show more
IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allow the attacker to execute arbitrary code on the vulnerable Web server. IBM X-Force ID: 128105.Show less
1Basercms
1Basercms
May 13, 2026
Aug 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors.
1Nippon Antenna
1Scr02hd Firmware
May 13, 2026
Aug 29, 2017
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
"Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors.
1Avm
2Fritz!box 6810 Lte Firmware
Fritz!box 6840 Lte Firmware
May 13, 2026
Aug 29, 2017
N/A· v4
7.8 HIGH· v3
9.3 HIGH· v2
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
1Cisco
1Prime Infrastructure
May 13, 2026
Aug 17, 2017
N/A· v4
5.4 MEDIUM· v3
4.9 MEDIUM· v2
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due...Show more
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due to improper sanitization of parameter values by the affected application. An attacker could exploit this vulnerability by injecting malicious code into an affected parameter and persuading a user to access a web page that triggers the rendering of the injected code. Cisco Bug IDs: CSCve47074. Known Affected Releases: 3.2(0.0).Show less
1Suse
1Opensuse
May 13, 2026
Aug 17, 2017
N/A· v4
9.8 CRITICAL· v3
9.0 HIGH· v2
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011.
1Ibm
1Infosphere Information Server
May 13, 2026
Aug 14, 2017
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
1Lenovo
11163 Firmware
H50 30g FirmwareIdeacentre 300 20ish Firmware+108 more
May 13, 2026
Aug 10, 2017
N/A· v4
6.8 MEDIUM· v3
7.2 HIGH· v2
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileg...Show more
A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileges or physical access to a system may be able to run specially crafted code that can allow them to bypass system protections such as Device Guard and Hyper-V.Show less