CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,714 vulnerabilities with CWE-94
CVE-2026-42301 HIGH
Improper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2spec
CVSS 7.8
CVE-2026-42298 CRITICAL
Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CVSS 10.0
CVE-2026-41486 HIGH
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVSS 8.8
CVE-2026-29202 HIGH
cPanel 11.86.0.0-11.136.0.8 - Authenticated Perl Code Injection via create_user Plugin
CVSS 8.8
CVE-2026-44336 CRITICAL
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
CVSS 9.6
CVE-2026-44334 HIGH
PraisonAI: Unauthenticated RCE via `tool_override.py`
CVSS 8.4
CVE-2026-41512 CRITICAL
Remote code execution via JavaScript injection in `BrowserAutomation::PlaywrightService`
CVSS 9.9
CVE-2026-41507 CRITICAL
Remote Code Execution (RCE) via String Literal Injection into math-codegen
CVSS 9.8
CVE-2026-25077 HIGH
Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
CVSS 8.8
CVE-2026-8136 LOW
SourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting
CVSS 2.4
CVE-2026-43944 CRITICAL
electerm: dangerous code can be run through links or command line
CVSS 9.6
CVE-2026-42203 HIGH
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVSS 8.8
CVE-2026-41900 HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
CVSS 8.8
CVE-2026-41645 MEDIUM
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
CVSS 5.3
CVE-2026-8117 MEDIUM
SourceCodester Pizzafy Ecommerce System index.php cross site scripting
CVSS 4.3
CVE-2026-41692 MEDIUM
i18nextify is vulnerable to DOM XSS via javascript:/data: URL schemes in translated href/src attributes
CVSS 4.7
CVE-2026-44244 HIGH
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
CVSS 7.8
CVE-2026-42214 HIGH
Improper Control of Generation of Code ('Code Injection') in dail8859/NotepadNext
CVSS 7.8
CVE-2026-36458 CRITICAL
ChestnutCMS v1.5.10 - SQL Injection
CVSS 9.8
CVE-2026-8094 CRITICAL
Mozilla Firefox and Thunderbird 140.10.2 - WebRTC Code Injection
CVSS 9.8
CVE-2026-41139 HIGH
Unsafe array index getter in mathjs
CVSS 8.8
CVE-2026-8021 MEDIUM
Google Chrome < 148.0.7778.96 - Script Injection in UI via Crafted HTML Page
CVSS 4.2
CVE-2026-35255 MEDIUM
Oracle Cloud Native Environment Command Line Interface - Arbitrary Code Execution
CVSS 6.6
CVE-2026-7841 HIGH
GeoVision ASManager 6.2.0 - Authenticated Remote Code Execution via ASWebCommon.srf Endpoint
CVSS 8.8
CVE-2026-38431 CRITICAL
ERPNext <= 15.103.1 - Server-Side Template Injection
CVSS 9.8
Details
Vulnerabilities 6,714
Exploit Likelihood Medium