CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,295)
page 15 of 365| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2026-75414 | Cri | 0.64 | 9.8 | 0.00 | Aug 26, 2026 | In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability. | ||
| CVE-2026-52103 | Cri | 0.64 | 9.8 | 0.01 | Aug 26, 2026 | A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message. | ||
| CVE-2026-52490 | Cri | 0.64 | 9.8 | 0.00 | Aug 24, 2026 | An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c | ||
| CVE-2026-73992 | Cri | 0.64 | 9.9 | 0.01 | Aug 20, 2026 | Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions. | ||
| CVE-2026-32444 | Cri | 0.64 | 9.9 | 0.00 | Aug 18, 2026 | Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions. | ||
| CVE-2026-67960 | Cri | 0.64 | 9.8 | 0.00 | Aug 17, 2026 | An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components | ||
| CVE-2026-67926 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module | ||
| CVE-2026-50772 | Cri | 0.64 | 9.8 | 0.01 | Aug 17, 2026 | An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function. | ||
| CVE-2026-73487 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2026 | Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate… | ||
| CVE-2026-73268 | Cri | 0.64 | 9.9 | 0.00 | Aug 12, 2026 | A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate… | ||
| CVE-2026-16051 | Cri | 0.64 | 9.8 | 0.01 | Aug 12, 2026 | The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to… | ||
| CVE-2026-72765 | Cri | 0.64 | 9.9 | 0.00 | Aug 11, 2026 | n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command… | ||
| CVE-2026-55799 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2026 | Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | ||
| CVE-2026-44416 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2026 | Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue. | ||
| CVE-2026-42537 | Cri | 0.64 | 9.8 | 0.01 | Aug 10, 2026 | Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue. | ||
| CVE-2026-65548 | Cri | 0.64 | 9.9 | 0.00 | Aug 6, 2026 | Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions. | ||
| CVE-2026-71278 | Cri | 0.64 | 9.8 | 0.00 | Aug 5, 2026 | rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication. | ||
| CVE-2026-70553 | Cri | 0.64 | 9.8 | 0.01 | Aug 4, 2026 | MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply… | ||
| CVE-2026-51785 | Cri | 0.64 | 9.8 | 0.01 | Jul 31, 2026 | An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request | ||
| CVE-2026-17561 | Cri | 0.64 | 9.8 | 0.00 | Jul 31, 2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115. |
- risk 0.64cvss 9.8epss 0.00
In AntFlow V2.0.0, ActivitiTest.java enables users to execute JUEL expressions without filtering the user input, which leads to a command execution vulnerability.
- risk 0.64cvss 9.8epss 0.01
A zero-click remote code execution (RCE) vulnerability in the /Terminal/Notification.hs component of SimpleX Chat before v6.5 allows attackers to execute arbitrary commands in the context of the application without user interaction via sending a crafted payload in a text message.
- risk 0.64cvss 9.8epss 0.00
An issue in libtiff 85f2ac8e0b01cb7db2bbecf4a3b891bdbef67938 allows an attacker to execute arbitrary code via the process_command_opts() function in tools/tiffcrop.c
- risk 0.64cvss 9.9epss 0.01
Subscriber Remote Code Execution (RCE) in Query Wrangler <= 1.5.57 versions.
- risk 0.64cvss 9.9epss 0.00
Contributor Remote Code Execution (RCE) in Cwicly <= 1.4.4 versions.
- risk 0.64cvss 9.8epss 0.00
An issue in PbootCMS v.3.2.15 allows an attacker to execute arbitrary code via the MemberController.php, UserController.php, CommentController.php, ContentController.php, and helper.php components
- risk 0.64cvss 9.8epss 0.01
An issue in JeecgBoot v.3.9.2 allows a remote attacker to execute arbitrary code via the files Parameter in JeecgBoot AI Chat Module
- risk 0.64cvss 9.8epss 0.01
An issue in Squirro Cognitive Search < 3.14.2 allows a remote attacker to execute arbitrary code via a crafted payload to the password reset function.
- risk 0.64cvss 9.8epss 0.01
Flowise before 3.1.3 contains a regex-based Python code validator bypass in CSV and Airtable Agent nodes that allows unauthenticated attackers to inject malicious code via prompt injection. Attackers can exploit unblocked pandas functions like pd.read_json() to exfiltrate…
- risk 0.64cvss 9.9epss 0.00
A flaw was found in the cluster-curator-controller component of multicluster engine (MCE). A tenant with create or update permissions on ClusterCurator resources can inject an arbitrary Job specification. This is possible because the CreateJob() function does not validate…
- risk 0.64cvss 9.8epss 0.01
The wpmudev-updates WordPress plugin before 5.0.1 does not verify the integrity of the packages installed through its remote management interface, nor protect those requests against replay, allowing an attacker able to obtain or replay a valid signed management request to…
- risk 0.64cvss 9.9epss 0.00
n8n before 2.31.5 and before 2.32.1 contain a sandbox escape vulnerability in expression evaluation. An authenticated user with permission to create or modify workflows can craft expressions using arrow-function bodies to bypass the expression sandbox, triggering system command…
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution Vulnerability in GraalScriptEngineCreator in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution via Arbitrary Class Instantiation in plugin-schema-registry component in Apache Ranger <= 2.8.0. Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- risk 0.64cvss 9.8epss 0.01
Remote Code Execution via JDBC URL Injection in Apache Ranger <= 2.8.0 Users are recommended to upgrade to version 2.9.0, which fixes this issue.
- risk 0.64cvss 9.9epss 0.00
Contributor Remote Code Execution (RCE) in Betheme <= 28.4.2 versions.
- risk 0.64cvss 9.8epss 0.00
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.
- risk 0.64cvss 9.8epss 0.01
MaxSite CMS contains a remote code execution vulnerability that allows unauthenticated attackers to inject arbitrary PHP code into the application configuration file by submitting crafted POST requests to the install endpoint after installation is complete. Attackers can supply…
- risk 0.64cvss 9.8epss 0.01
An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted request
- risk 0.64cvss 9.8epss 0.00
Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and Consulting Trade Ltd. Co. Logsign SIEM allows Code Injection. This issue affects Logsign SIEM: before 6.4.115.