CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,712 vulnerabilities with CWE-94
CVE-2026-54057
HIGH
Kitty vulnerable to command injection via unsanitized OSC 21 query reply
CVSS 7.8
CVE-2026-12130
LOW
CodeAstro Human Resource Management System Projects Management Add_Projects cross site scripting
CVSS 3.5
CVE-2026-12129
LOW
CodeAstro Human Resource Management System Dashboard add_tod cross site scripting
CVSS 3.5
CVE-2026-42890
MEDIUM
actual Allows Electron to Run As Node
CVE-2026-42851
HIGH
@kitty-edit DCS + --color=geninclude vulnerable to Unauthenticated in-process RCE
CVSS 7.8
CVE-2026-45833
HIGH
ChromaDB - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-54133
CRITICAL
jmespath.php has CompilerRuntime code injection via unescaped function names
CVSS 9.8
CVE-2026-52860
HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
CVE-2026-52858
HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion
CVSS 7.8
CVE-2026-47167
MEDIUM
Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regex
CVSS 5.3
CVE-2026-47162
HIGH
Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory name
CVSS 8.8
CVE-2026-44495
HIGH
Axios: Credential Theft and Response Hijacking via Prototype Pollution Gadget in Config Merge
CVSS 7.0
CVE-2026-50223
HIGH
Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Leads to Remote Code Execution
CVSS 8.8
CVE-2026-45558
CRITICAL
Roxy-WI: Authenticated RCE on every managed HAProxy load balancer via `option` field config injection in section save
CVSS 9.9
CVE-2026-46517
HIGH
LMDeploy: Hardcoded trust_remote_code=True is an implicit unsafe remote-code load path with no user opt-out
CVSS 7.8
CVE-2026-46432
HIGH
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVSS 7.8
CVE-2026-47292
HIGH
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-45583
HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-0414
MEDIUM
NETGEAR RBE97x - Arbitrary Code Execution Vulnerability Exists in RBE970
CVSS 4.5
CVE-2026-8795
HIGH
Rapid7 Velociraptor < 0.76.6 - Improper Encoding or Escaping of Output
CVSS 7.8
CVE-2026-11688
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-52778
CRITICAL
YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)
CVSS 9.8
CVE-2026-11393
CRITICAL
Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import
CVSS 9.0
CVE-2026-25856
HIGH
OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface
CVSS 8.8
CVE-2026-11534
LOW
imvks786 student_management_system add.php cross site scripting
CVSS 3.5
Details
Vulnerabilities
6,712
Exploit Likelihood
Medium