CWE-94
7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,044)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Bitdefender 3Antivirus Plus Internet SecurityTotal SecurityMay 13, 2026 Mar 21, 2017 N/A· v4 6.7 MEDIUM· v3 7.2 HIGH· v2 Code injection vulnerability in Bitdefender Total Security 12.0 (and earlier), Internet Security 12.0 (and earlier), and Antivirus Plus 12.0 (and earlier) allows a local attacker to bypass a self-protection mechanism, in...Show more |
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request paramete...Show more |
Adobe Campaign versions 16.4 Build 8724 and earlier have a code injection vulnerability. |
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequent...Show more |
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password. |
1Simplemachines 1Simple Machines Forum May 13, 2026 Feb 9, 2017 N/A· v4 8.8 HIGH· v3 6.8 MEDIUM· v2 LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop. |
1Simplemachines 1Simple Machines Forum May 13, 2026 Feb 9, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter. |
1Php Gettext Project 1Php Gettext May 13, 2026 Feb 7, 2017 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header. |
1Owncloud 1Owncloud Desktop Client May 13, 2026 Jan 23, 2017 N/A· v4 8.4 HIGH· v3 4.6 MEDIUM· v2 ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive. |
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php. |
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making...Show more |
includes/classes/ia.core.users.php in Subrion CMS 4.0.5 allows remote attackers to conduct PHP Object Injection attacks via crafted serialized data in a salt cookie in a login request. |
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated priv...Show more |
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed. |
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled. |
4Debian FedoraprojectKde+1 more4Debian Linux FedoraKmail+1 moreMay 6, 2026 Dec 23, 2016 N/A· v4 7.3 HIGH· v3 7.5 HIGH· v2 Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space int...Show more |
2Kde Opensuse3Kde Cli Tools LeapOpensuseMay 6, 2026 Dec 23, 2016 N/A· v4 4.9 MEDIUM· v3 4.0 MEDIUM· v2 A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user. |
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334. |
2Apport Project Canonical2Apport Ubuntu LinuxMay 6, 2026 Dec 17, 2016 N/A· v4 7.8 HIGH· v3 9.3 HIGH· v2 An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary P...Show more |
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected. |