VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 308 of 350
  • CVE-2026-14407HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-14383HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.00

    Inappropriate implementation in V8 in Google Chrome prior to 150.0.7871.46 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)

  • CVE-2026-58454HigJul 1, 2026
    risk 0.00cvss 7.5epss 0.01

    JAIOTlink C492A-W6 Wi-Fi IP cameras running firmware 4.8.30.57701411 contain a remote code execution vulnerability that allows authenticated attackers to execute arbitrary shell scripts by writing to the writable persistent JFFS2 storage path and triggering execution through the…

  • CVE-2026-8857HigJul 1, 2026
    risk 0.00cvss 8.8epss 0.01

    A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, 1.43.9.

  • CVE-2026-24249HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-24248HigJul 1, 2026
    risk 0.00cvss 7.8epss 0.00

    NVIDIA Megatron Bridge for Linux contains a vulnerability where an attacker could cause improper control of code generation. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and information disclosure.

  • CVE-2026-56264HigJun 30, 2026
    risk 0.00cvss 8.1epss 0.00

    Crawl4AI before 0.8.7 contains an arbitrary JavaScript execution vulnerability in the Docker API server's /execute_js endpoint, which accepts and executes arbitrary user-supplied JavaScript in the server's browser context with --disable-web-security enabled. An attacker can…

  • CVE-2026-58449CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    txtai through 9.10.0, fixed in commit 11b32da, exposes an API /reindex endpoint whose function body parameter is resolved through txtai.util.Resolver, which performs __import__ and getattr on the caller-supplied dotted path with no allowlist. When the API is exposed with no…

  • CVE-2026-7873CriJun 30, 2026
    risk 0.00cvss 9.9epss 0.00

    IBM Langflow OSS 1.0.0 through 1.10.0 allows authenticated attackers to execute arbitrary OS commands and read sensitive files including credentials, enabling complete system compromise and lateral movement.

  • CVE-2026-10134CriJun 30, 2026
    risk 0.00cvss 10.0epss 0.00

    IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow, conversation, message, file upload, and saved component in the Langflow database, can connect to internal services, abuse cloud metadata…

  • CVE-2026-10109CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling.

  • CVE-2026-58138CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.07

    Orkes Conductor 3.21.21 before 3.30.2 contains an unauthenticated remote code execution vulnerability that allows remote attackers to execute arbitrary OS commands by submitting inline workflow definitions containing malicious JavaScript or Python expressions to the workflow API…

  • CVE-2026-58116CriJun 30, 2026
    risk 0.00cvss 9.8epss 0.01

    LLaMA-Factory through 0.9.5 contains a remote code execution vulnerability that allows attackers with WebUI access to execute arbitrary Python code by supplying a malicious model path in the Chat or Training interfaces. The application passes user-supplied model path input…

  • CVE-2026-37637CriJun 29, 2026
    risk 0.00cvss 9.1epss 0.00

    An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

  • CVE-2026-13749HigJun 29, 2026
    risk 0.00cvss 8.8epss 0.00

    Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. An attacker could exploit this by supplying crafted project content that is…

  • CVE-2026-13570LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. Performing a manipulation of the argument full_name results in cross site scripting.…

  • CVE-2026-13567MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST Request Handler. The manipulation of the argument fname/femail/faddress/fmessage results in cross site scripting. The…

  • CVE-2026-13558LowJun 29, 2026
    risk 0.00cvss 3.5epss 0.00

    A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component Report Handler. Performing a manipulation of the argument Report Title results in cross site scripting.…

  • CVE-2026-13557MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request Handler. Such manipulation of the argument Name leads to cross site…

  • CVE-2026-13556MedJun 29, 2026
    risk 0.00cvss 4.3epss 0.00

    A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request Handler. This manipulation of the argument Name causes cross site scripting. The…