CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,458 vulnerabilities with CWE-94
CVE-2026-8094 CRITICAL
Mozilla Firefox and Thunderbird 140.10.2 - WebRTC Code Injection
CVSS 9.8
CVE-2026-8021 MEDIUM
Google Chrome < 148.0.7778.96 - Script Injection in UI via Crafted HTML Page
CVSS 4.2
CVE-2026-35255 MEDIUM
Oracle Cloud Native Environment Command Line Interface - Arbitrary Code Execution
CVSS 6.6
CVE-2026-7841 HIGH
GeoVision ASManager 6.2.0 - Authenticated Remote Code Execution via ASWebCommon.srf Endpoint
CVSS 8.8
CVE-2026-38431 CRITICAL
ERPNext <= 15.103.1 - Server-Side Template Injection
CVSS 9.8
CVE-2026-42238 CRITICAL
Unauthenticated Remote Code Execution via Backup Restore in nginx-ui
CVSS 9.8
CVE-2026-42234 HIGH
n8n: Python Task Runner Sandbox Escape
CVSS 8.8
CVE-2026-42090 CRITICAL
Notesnook: RCE via stored XSS in note export rendering
CVSS 9.6
CVE-2026-26332 CRITICAL
vm2: Sandbox Escape
CVSS 9.8
CVE-2026-24781 CRITICAL
vm2: Sandbox Breakout Through Inspect
CVSS 9.8
CVE-2026-24120 CRITICAL
vm2: Sandbox Breakout Through Promise Species
CVSS 9.8
CVE-2026-24118 CRITICAL
VM2 Sandbox Breakout Through __lookupGetter__
CVSS 9.8
CVE-2026-40563 HIGH
Apache Atlas: Script injection allows access to unintended data
CVSS 8.1
CVE-2026-36365 HIGH
Lymphatus caesium-image-compressor - Code Injection
CVSS 7.8
CVE-2026-3120 HIGH
RCE in Profelis Informatics' SambaBox
CVSS 7.2
CVE-2026-7703 HIGH
AV Stumpfl Pixera Two Media Server Websocket API code injection
CVSS 7.3
CVE-2026-7700 MEDIUM
langflow-ai langflow LambdaFilterComponent lambda_filter.p eval code injection
CVSS 6.3
CVE-2026-7677 LOW
kerwincui FastBee System Notice SysNoticeController.java add cross site scripting
CVSS 3.5
CVE-2026-7669 MEDIUM
sgl-project SGLang HuggingFace Transformer hf_transformers_utils.py get_tokenizer deserialization
CVSS 5.6
CVE-2026-2052 HIGH
Widget Options <= 4.2.2 - Authenticated (Contributor+) Remote Code Execution via Display Logic
CVSS 8.8
CVE-2026-7596 MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Slide Generator generate-slide.py data.get cross site scripting
CVSS 4.3
CVE-2026-7595 MEDIUM
nextlevelbuilder ui-ux-pro-max-skill Tailwind Config Generator tailwind_config_gen.py _format_plugins code injection
CVSS 6.3
CVE-2026-7580 MEDIUM
Exiftool JPEG/QuickTime/MOV/MP4 GM.pm Process_mrld code injection
CVSS 5.3
CVE-2026-42994 CRITICAL
Bitwarden CLI 2026.4.0 - Supply Chain Attack
CVSS 9.8
CVE-2026-7508 MEDIUM
Bootstrap CMS Page Creation show.blade.php code injection
CVSS 6.3
Details
Vulnerabilities 6,458
Exploit Likelihood Medium