CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,457 vulnerabilities with CWE-94
CVE-2026-46432
HIGH
LMDeploy: Arbitrary code execution via hardcoded trust_remote_code=True in lmdeploy model initialization
CVSS 7.8
CVE-2026-47292
HIGH
Visual Studio Code MSSQL Extension Remote Code Execution Vulnerability
CVSS 7.8
CVE-2026-45583
HIGH
Microsoft Exchange Server Remote Code Execution Vulnerability
CVSS 7.5
CVE-2026-0414
MEDIUM
NETGEAR RBE97x - Arbitrary Code Execution Vulnerability Exists in RBE970
CVE-2026-8795
HIGH
Rapid7 Velociraptor < 0.76.6 - Improper Encoding or Escaping of Output
CVSS 7.8
CVE-2026-11688
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.8
CVE-2026-52778
CRITICAL
YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of Service (DoS)
CVSS 9.8
CVE-2026-11393
CRITICAL
Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import
CVSS 9.0
CVE-2026-25856
HIGH
OpenBullet2 0.3.2 Authenticated RCE via Job Configuration Interface
CVSS 8.8
CVE-2026-11534
LOW
imvks786 student_management_system add.php cross site scripting
CVSS 3.5
CVE-2026-46442
CRITICAL
Flowise: Authenticated Host RCE via POST /api/v1/node-custom-function and NodeVM Sandbox Escape
CVSS 9.9
CVE-2026-11520
LOW
SourceCodester Inventory System header.php cross site scripting
CVSS 3.5
CVE-2026-11518
MEDIUM
SourceCodester Inventory System User Management users.php cross site scripting
CVSS 4.3
CVE-2026-11512
MEDIUM
itsourcecode Hospital Management System billing.php cross site scripting
CVSS 4.3
CVE-2026-11491
LOW
CodeAstro Human Resource Management System Notice Board Management All_notice cross site scripting
CVSS 2.4
CVE-2026-11468
LOW
SourceCodester Hospitals Patient Records Management System page room_types cross site scripting
CVSS 2.4
CVE-2026-11436
MEDIUM
Mage AI Sign-in Flow index.tsx useMutation cross site scripting
CVSS 4.3
CVE-2026-11434
LOW
FluentCMS Blocks Plugin blocks cross site scripting
CVSS 2.4
CVE-2026-49493
HIGH
Markdown Preview Enhanced Arbitrary Code Execution via Bitfield interpretJS()
CVSS 8.8
CVE-2026-11338
LOW
SourceCodester Ship Ferry Ticket Reservation System manage_user cross site scripting
CVSS 2.4
CVE-2026-11337
MEDIUM
tittuvarghese CollegeManagementSystem fetch.php cross site scripting
CVSS 4.3
CVE-2026-11231
HIGH
Google Chrome - Arbitrary Code Execution
CVSS 8.1
CVE-2026-11218
MEDIUM
Google Chrome - Arbitrary Code Execution
CVSS 6.8
CVE-2026-11157
MEDIUM
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 5.4
CVE-2026-10928
HIGH
Google Chrome - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
Details
Vulnerabilities
6,457
Exploit Likelihood
Medium