CWE-94
7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,044)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource. |
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. D...Show more |
In the Upload Modules page in GeniXCMS 1.1.4, remote authenticated users can execute arbitrary PHP code via a .php file in a ZIP archive of a module. |
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php. |
1Ansible Vault Project 1Ansible Vault May 13, 2026 Sep 14, 2017 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 An exploitable vulnerability exists in the yaml loading functionality of ansible-vault before 1.0.5. A specially crafted vault can execute arbitrary python commands resulting in command execution. An attacker can insert...Show more |
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability." |
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path param...Show more |
1Gwolle Guestbook Project 1Gwolle Guestbook May 13, 2026 Sep 11, 2017 N/A· v4 9.0 CRITICAL· v3 6.8 MEDIUM· v2 PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspa...Show more |
HelpDEZk 1.1.1 allows remote authenticated users to execute arbitrary PHP code by uploading a .php attachment and then requesting it in the helpdezk\app\uploads\helpdezk\attachments\ directory. |
1Mcafee 2Livesafe Security Scan PlusMay 13, 2026 Sep 1, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A Code Injection vulnerability in the non-certificate-based authentication mechanism in McAfee Live Safe versions prior to 16.0.3 and McAfee Security Scan Plus (MSS+) versions prior to 3.11.599.3 allows network attackers...Show more |
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, o...Show more |
3Debian RedhatRubygems8Debian Linux Enterprise Linux DesktopEnterprise Linux Server+5 moreMay 13, 2026 Aug 31, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences. |
1Ibm 1Emptoris Services Procurement May 13, 2026 Aug 30, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 IBM Emptoris Services Procurement 10.0.0.5 could allow a remote attacker to include arbitrary files. A remote attacker could send a specially-crafted URL to specify a malicious file from a remote system, which could allo...Show more |
baserCMS 3.0.14 and earlier, 4.0.5 and earlier allows an attacker to execute arbitrary PHP code on the server via unspecified vectors. |
1Nippon Antenna 1Scr02hd Firmware May 13, 2026 Aug 29, 2017 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 "Dokodemo eye Smart HD" SCR02HD Firmware 1.0.3.1000 and earlier allows authenticated attackers to conduct code injection attacks via unspecified vectors. |
1Avm 2Fritz!box 6810 Lte Firmware Fritz!box 6840 Lte FirmwareMay 13, 2026 Aug 29, 2017 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. |
A vulnerability in the administrative web interface of Cisco Prime Infrastructure could allow an authenticated, remote attacker to modify a page in the web interface of the affected application. The vulnerability is due...Show more |
Code injection in openSUSE when running some source services used in the open build service 2.1 before March 11 2011. |
1Ibm 1Infosphere Information Server May 13, 2026 Aug 14, 2017 N/A· v4 7.8 HIGH· v3 4.6 MEDIUM· v2 IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468. |
1Lenovo 11163 Firmware H50 30g FirmwareIdeacentre 300 20ish Firmware+108 moreMay 13, 2026 Aug 10, 2017 N/A· v4 6.8 MEDIUM· v3 7.2 HIGH· v2 A vulnerability has been identified in some Lenovo products that use UEFI (BIOS) code developed by American Megatrends, Inc. (AMI). With this vulnerability, conditions exist where an attacker with administrative privileg...Show more |