CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,463 vulnerabilities with CWE-94
CVE-2026-6623
LOW
BichitroGan ISP Billing Software Profile users-view cross site scripting
CVSS 2.4
CVE-2026-6622
LOW
BichitroGan ISP Billing Software Customer edit cross site scripting
CVSS 2.4
CVE-2026-6621
HIGH
1024bit extend-deep index.js prototype pollution
CVSS 7.3
CVE-2026-6619
LOW
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
CVSS 3.5
CVE-2026-41282
MEDIUM
ProjectDiscovery Nuclei <3.8.0 - DSL Injection
CVSS 4.0
CVE-2026-6603
HIGH
modelscope agentscope _python.py execute_shell_command code injection
CVSS 7.3
CVE-2026-6600
LOW
langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
CVSS 3.5
CVE-2026-6594
HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-6593
LOW
ComfyUI View Endpoint server.py cross site scripting
CVSS 3.5
CVE-2026-6592
LOW
ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
CVSS 3.5
CVE-2026-6559
MEDIUM
Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting
CVSS 4.3
CVE-2026-41242
CRITICAL
protobufjs Type Fields - Arbitrary Code Execution
CVSS 9.8
CVE-2026-40342
CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-6493
LOW
lukevella rallly Reset Password reset-password-form.tsx cross site scripting
CVSS 3.5
CVE-2026-6486
LOW
classroombookings User Display Name layout.php read cross site scripting
CVSS 3.5
CVE-2026-40322
CRITICAL
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
CVSS 9.0
CVE-2026-40316
HIGH
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
CVSS 8.8
CVE-2026-33435
HIGH
Weblate: Remote code execution during backup restoration
CVSS 8.0
CVE-2026-30993
CRITICAL
Slah CMS <=1.5.0 session() - Remote Code Execution
CVSS 9.8
CVE-2026-39842
CRITICAL
OpenRemote is Vulnerable to Expression Injection
CVSS 9.9
CVE-2026-1509
MEDIUM
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
CVSS 5.4
CVE-2026-25125
MEDIUM
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
CVSS 4.9
CVE-2026-2582
MEDIUM
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2026-40288
CRITICAL
PraisonAI: Critical RCE via `type: job` workflow YAML
CVSS 9.8
CVE-2026-40287
HIGH
PraisonAI has RCE via Automatic tools.py Import
CVSS 8.4
Details
Vulnerabilities
6,463
Exploit Likelihood
Medium