CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,710 vulnerabilities with CWE-94
CVE-2026-16801 HIGH
Devolutions PowerShell Universal < 2026.2.3 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-16800 HIGH
Devolutions PowerShell Universal < 2026.2.3 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-60122 HIGH
gpsd gpsprof Code Injection via SKY.satellites used Field
CVSS 7.8
CVE-2026-47722 HIGH
nebula-mesh: Host advanced overrides allow YAML injection into agent config.yml
CVE-2026-47668 CRITICAL
DbGate: Unauthenticated Remote Code Execution via JSON Script Runner
CVSS 10.0
CVE-2026-65907 CRITICAL
Jetbrains TeamCity < 2026.1.2, 2025.11.6 - Improper Control of Generation of Code ('Code Injection')
CVSS 9.1
CVE-2026-65906 HIGH
Jetbrains TeamCity < 2026.1.2, 2025.11.6 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-64815 HIGH
Jetbrains IntelliJ Idea < 2026.2 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.1
CVE-2026-64803 HIGH
Jetbrains GoLand < 2026.2 - Improper Control of Generation of Code ('Code Injection')
CVSS 7.8
CVE-2026-64802 HIGH
Jetbrains GoLand < 2026.2 - Improper Control of Generation of Code ('Code Injection')
CVSS 7.8
CVE-2026-59543 CRITICAL
WordPress Advanced Views plugin <= 3.8.11 - Remote Code Execution (RCE) vulnerability
CVSS 9.9
CVE-2026-15011 CRITICAL
Customer Support Ticket System & Helpdesk <= 6.0.5 - Unauthenticated Code Injection via 'path' Parameter
CVSS 9.8
CVE-2026-16606 CRITICAL
Unauthenticated remote code execution (pre-auth RCE) vulnerability in openFT for Linux and Oracle Solaris
CVSS 9.8
CVE-2026-16486 MEDIUM
SourceCodester Class and Exam Timetabling System BSIS.php cross site scripting
CVSS 4.3
CVE-2026-16485 MEDIUM
SourceCodester Class and Exam Timetabling System class.php cross site scripting
CVSS 4.3
CVE-2026-8984 CRITICAL
Autel MaxiCharger Single < V1.03.51 - Remote Code Execution
CVE-2026-43945 HIGH
FUXA Vulnerable to Pre-auth RCE via Path Manipulation & Configuration Injection
CVE-2026-21575 HIGH
Atlassian Sourcetree For Mac - Remote Code Execution
CVSS 7.1
CVE-2026-47398 HIGH
PraisonAI < 4.6.40 agents_generator.py - Arbitrary Code Execution
CVSS 8.1
CVE-2026-65008 CRITICAL
Grav before 2.0.7 Remote Code Execution via Blueprint dynamicData
CVSS 9.8
CVE-2026-52656 CRITICAL
SJCAM AllWinner Tech SJ4000-Air <= 1.4C - Remote Code Execution via Crafted FEX File
CVSS 9.8
CVE-2026-51385 MEDIUM
GRAPHIFY 0.3.2-0.4.29 - Remote Code Execution via URL Validation and Fetch Functions
CVSS 6.9
CVE-2026-60026 HIGH
Joomla Extension - themexpert.com - Authenticated PHP code execution in Quix Page Builder < 6.2.1
CVE-2026-44359 CRITICAL
Meshtastic GitHub repo vulnerable to Arbitrary Code Execution via pull_request_target Fork Checkout in CI Workflow
CVSS 10.0
CVE-2026-16229 MEDIUM
itsourcecode Courier Management System index.php cross site scripting
CVSS 4.3
Details
Vulnerabilities 6,710
Exploit Likelihood Medium