CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,465 vulnerabilities with CWE-94
CVE-2026-4165
LOW
Worksuite HR, CRM and Project Management <=5.5.25 - XSS
CVSS 2.4
CVE-2026-3476
HIGH
Code Injection vulnerability affecting in SOLIDWORKS Desktop from Release 2025 through Release 2026
CVSS 7.8
CVE-2026-32719
MEDIUM
AnythingLLM <=1.11.1 Plugin Import - Zip Slip Code Execution
CVSS 4.2
CVE-2026-32640
CRITICAL
(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox.
CVSS 9.8
CVE-2026-3910
HIGH
KEV
Google Chrome < 146.0.7680.75 - Remote Code Execution via Crafted HTML Page
CVSS 8.8
CVE-2026-32414
HIGH
Advanced Woo Labels <=2.36 - Code Injection
CVSS 7.2
CVE-2026-32367
CRITICAL
Modal Dialog <=3.5.16 - Code Injection
CVSS 9.1
CVE-2026-32304
CRITICAL
locutus < 3.0.14 - Remote Code Execution via create_function
CVSS 9.8
CVE-2026-26954
CRITICAL
SandboxJS < 0.8.34 - Sandbox Escape via Function Array Manipulation
CVSS 10.0
CVE-2026-25817
HIGH
HMS Networks Ewon Flexy <15.0s4 - RCE
CVSS 8.8
CVE-2026-21671
CRITICAL
Veeam Backup & Replication - Authenticated RCE
CVSS 9.1
CVE-2026-21669
CRITICAL
Veeam Backup & Replication 13.0.0.496-13.0.1 - Authenticated Remote Code Execution
CVSS 9.9
CVE-2026-4039
MEDIUM
OpenClaw 2026.2.19-2 - Code Injection
CVSS 6.3
CVE-2026-3993
MEDIUM
itsourcecode Payroll Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3990
MEDIUM
CesiumJS <= 1.137.0 - Cross-Site Scripting in Sandcastle Standalone HTML
CVSS 4.3
CVE-2026-3984
LOW
Campcodes Division Regional Athletic Meet Game Result Matrix System...
CVSS 3.5
CVE-2026-3983
LOW
Campcodes Division Regional Athletic Meet Game Result Matrix System...
CVSS 3.5
CVE-2026-3982
MEDIUM
itsourcecode University Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3968
MEDIUM
AutohomeCorp frostmourne <1.0 - Code Injection
CVSS 6.3
CVE-2026-3962
MEDIUM
Jcharis Machine-Learning-Web-Apps - XSS
CVSS 4.3
CVE-2026-3955
MEDIUM
elecV2P <= 3.8.3 - Remote Code Execution via runJSFile Function
CVSS 6.3
CVE-2026-3951
MEDIUM
LockerProject Locker 0.0.0-0.1.0 - XSS
CVSS 4.3
CVE-2026-31861
HIGH
Cloud CLI <1.24.0 - Command Injection
CVSS 8.8
CVE-2026-31857
HIGH
Craft CMS 5.x < 5.9.9 and 4.x < 4.17.4 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-30741
CRITICAL
OpenClaw Agent Platform 2026.2.6 - RCE
CVSS 9.8
Details
Vulnerabilities
6,465
Exploit Likelihood
Medium