CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,714 vulnerabilities with CWE-94
CVE-2026-42301
HIGH
Improper Input Validation leading to Improper Control of Generation of Code ('Code Injection') in pyp2spec
CVSS 7.8
CVE-2026-42298
CRITICAL
Postiz: Arbitrary Code Execution and Token Exfiltration in pr-docker-build.yml via untrusted Dockerfile.dev
CVSS 10.0
CVE-2026-41486
HIGH
Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization
CVSS 8.8
CVE-2026-29202
HIGH
cPanel 11.86.0.0-11.136.0.8 - Authenticated Perl Code Injection via create_user Plugin
CVSS 8.8
CVE-2026-44336
CRITICAL
PraisonAI MCP `tools/call` path-traversal and RCE via Python `.pth` injection
CVSS 9.6
CVE-2026-44334
HIGH
PraisonAI: Unauthenticated RCE via `tool_override.py`
CVSS 8.4
CVE-2026-41512
CRITICAL
Remote code execution via JavaScript injection in `BrowserAutomation::PlaywrightService`
CVSS 9.9
CVE-2026-41507
CRITICAL
Remote Code Execution (RCE) via String Literal Injection into math-codegen
CVSS 9.8
CVE-2026-25077
HIGH
Apache CloudStack: Unauthenticated Command Injection in Direct Download Templates
CVSS 8.8
CVE-2026-8136
LOW
SourceCodester Pharmacy Sales and Inventory System index.php users cross site scripting
CVSS 2.4
CVE-2026-43944
CRITICAL
electerm: dangerous code can be run through links or command line
CVSS 9.6
CVE-2026-42203
HIGH
LiteLLM: Server-Side Template Injection in /prompts/test endpoint
CVSS 8.8
CVE-2026-41900
HIGH
OpenLearnX has Critical Remote Code Execution Through Python Sandbox Escape via Code Execution Environment
CVSS 8.8
CVE-2026-41645
MEDIUM
Nuclei: Environment variable disclosure via Response-Derived DSL Expressions
CVSS 5.3
CVE-2026-8117
MEDIUM
SourceCodester Pizzafy Ecommerce System index.php cross site scripting
CVSS 4.3
CVE-2026-41692
MEDIUM
i18nextify is vulnerable to DOM XSS via javascript:/data: URL schemes in translated href/src attributes
CVSS 4.7
CVE-2026-44244
HIGH
GitPython: Newline injection in config_writer().set_value() enables RCE via core.hooksPath
CVSS 7.8
CVE-2026-42214
HIGH
Improper Control of Generation of Code ('Code Injection') in dail8859/NotepadNext
CVSS 7.8
CVE-2026-36458
CRITICAL
ChestnutCMS v1.5.10 - SQL Injection
CVSS 9.8
CVE-2026-8094
CRITICAL
Mozilla Firefox and Thunderbird 140.10.2 - WebRTC Code Injection
CVSS 9.8
CVE-2026-41139
HIGH
Unsafe array index getter in mathjs
CVSS 8.8
CVE-2026-8021
MEDIUM
Google Chrome < 148.0.7778.96 - Script Injection in UI via Crafted HTML Page
CVSS 4.2
CVE-2026-35255
MEDIUM
Oracle Cloud Native Environment Command Line Interface - Arbitrary Code Execution
CVSS 6.6
CVE-2026-7841
HIGH
GeoVision ASManager 6.2.0 - Authenticated Remote Code Execution via ASWebCommon.srf Endpoint
CVSS 8.8
CVE-2026-38431
CRITICAL
ERPNext <= 15.103.1 - Server-Side Template Injection
CVSS 9.8
Details
Vulnerabilities
6,714
Exploit Likelihood
Medium