← Back
CWE-94

7,033 CVEs • Abstraction: Base • Likelihood of Exploit: Medium

Improper Control of Generation of Code ('Code Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

JSON object

Loading...

CVEs (7,033)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed header in an MP4 file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted length of an MLTI chunk in an IVR file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Cook codec in RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via crafted channel data.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
The RV30 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 does not initialize an unspecified index value, which allows remote attackers to execute arbitrary code via unknown vectors.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
10.0 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted RTSP SETUP request.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The RV10 codec in RealNetworks RealPlayer before 15.0.0 and Mac RealPlayer before 12.0.0.1703 allows remote attackers to execute arbitrary code via a crafted sample height.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted sample size in a RealAudio file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a malformed AAC file.
1Realnetworks
1Realplayer
Apr 29, 2026
Nov 24, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
RealNetworks RealPlayer before 15.0.0 allows remote attackers to execute arbitrary code via a crafted QCELP stream.
1Dell
1Kace K2000 Systems Deployment Appliance
Apr 29, 2026
Nov 12, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
The Dell KACE K2000 System Deployment Appliance allows remote attackers to execute arbitrary commands by leveraging database write access.
1Mozilla
2Firefox
Thunderbird
Apr 29, 2026
Nov 9, 2011
N/A· v4
N/A· v3
9.3 HIGH· v2
Mozilla Firefox 4.x through 7.0 and Thunderbird 5.0 through 7.0 perform access control without checking for use of the NoWaiverWrapper wrapper, which allows remote attackers to gain privileges via a crafted web site.
1Php
1Php
Apr 29, 2026
Nov 3, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behav...Show more
The is_a function in PHP 5.3.7 and 5.3.8 triggers a call to the __autoload function, which makes it easier for remote attackers to execute arbitrary code by providing a crafted URL and leveraging potentially unsafe behavior in certain PEAR packages and custom autoloaders.Show less
1John Bradshaw
1Np Gallery Plugin
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
6.8 MEDIUM· v2
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: som...Show more
PHP remote file inclusion vulnerability in nucleus/plugins/NP_gallery.php in the NP_Gallery plugin 0.94 for Nucleus allows remote attackers to execute arbitrary PHP code via a URL in the DIR_NUCLEUS parameter. NOTE: some of these details are obtained from third party information.Show less
1Groonesworld
1Simple Contact Form
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in contact/contact.php in Groone's Simple Contact Form allows remote attackers to execute arbitrary PHP code via a URL in the abspath parameter.
1Maulana Al Matien
1Ardeacore Php Framework
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. NOTE: some of...Show more
PHP remote file inclusion vulnerability in ardeaCore/lib/core/ardeaInit.php in ardeaCore PHP Framework 2.2 allows remote attackers to execute arbitrary PHP code via a URL in the pathForArdeaCore parameter. NOTE: some of these details are obtained from third party information.Show less
1Phpldapadmin Project
1Phpldapadmin
Apr 29, 2026
Nov 2, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as ex...Show more
The masort function in lib/functions.php in phpLDAPadmin 1.2.x before 1.2.2 allows remote attackers to execute arbitrary PHP code via the orderby parameter (aka sortby variable) in a query_engine action to cmd.php, as exploited in the wild in October 2011.Show less
1Familycms
1Family Connections Who Is Chatting
Apr 29, 2026
Nov 1, 2011
N/A· v4
N/A· v3
7.5 HIGH· v2
PHP remote file inclusion vulnerability in mod_chatting/themes/default/header.php in Family Connections Who is Chatting 2.2.3 allows remote attackers to execute arbitrary PHP code via a URL in the TMPL[path] parameter.
2Cisco
Microsoft
2Ciscoworks Common Services
Windows
Apr 29, 2026
Oct 20, 2011
N/A· v4
N/A· v3
9.0 HIGH· v2
The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, C...Show more
The Home Page component in Cisco CiscoWorks Common Services before 4.1 on Windows, as used in CiscoWorks LAN Management Solution, Cisco Security Manager, Cisco Unified Service Monitor, Cisco Unified Operations Manager, CiscoWorks QoS Policy Manager, and CiscoWorks Voice Manager, allows remote authenticated users to execute arbitrary commands via a crafted URL, aka Bug IDs CSCtq48990, CSCtq63992, CSCtq64011, CSCtq64019, CSCtr23090, and CSCtt25535.Show less
1Cisco
1Show And Share
Apr 29, 2026
Oct 20, 2011
N/A· v4
N/A· v3
6.5 MEDIUM· v2
Cisco Show and Share 5(2), 5.2(1), and 5.2(2) before 5.2(2.1) allows remote authenticated users to upload and execute arbitrary code by leveraging video upload privileges, aka Bug ID CSCto69857.
1Dlink
2Dcs 2121
Dcs 2121 Firmware
Apr 29, 2026
Oct 16, 2011
N/A· v4
N/A· v3
9.0 HIGH· v2
recorder_test.cgi on the D-Link DCS-2121 camera with firmware 1.04 allows remote attackers to execute arbitrary commands via shell metacharacters in the Password field, related to a "semicolon injection" vulnerability.