CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,465 vulnerabilities with CWE-94
CVE-2026-4165 LOW
Worksuite HR, CRM and Project Management <=5.5.25 - XSS
CVSS 2.4
CVE-2026-3476 HIGH
Code Injection vulnerability affecting in SOLIDWORKS Desktop from Release 2025 through Release 2026
CVSS 7.8
CVE-2026-32719 MEDIUM
AnythingLLM <=1.11.1 Plugin Import - Zip Slip Code Execution
CVSS 4.2
CVE-2026-32640 CRITICAL
(SimpleEval) Objects (including modules) can leak dangerous modules through to direct access inside the sandbox.
CVSS 9.8
CVE-2026-3910 HIGH KEV
Google Chrome < 146.0.7680.75 - Remote Code Execution via Crafted HTML Page
CVSS 8.8
CVE-2026-32414 HIGH
Advanced Woo Labels <=2.36 - Code Injection
CVSS 7.2
CVE-2026-32367 CRITICAL
Modal Dialog <=3.5.16 - Code Injection
CVSS 9.1
CVE-2026-32304 CRITICAL
locutus < 3.0.14 - Remote Code Execution via create_function
CVSS 9.8
CVE-2026-26954 CRITICAL
SandboxJS < 0.8.34 - Sandbox Escape via Function Array Manipulation
CVSS 10.0
CVE-2026-25817 HIGH
HMS Networks Ewon Flexy <15.0s4 - RCE
CVSS 8.8
CVE-2026-21671 CRITICAL
Veeam Backup & Replication - Authenticated RCE
CVSS 9.1
CVE-2026-21669 CRITICAL
Veeam Backup & Replication 13.0.0.496-13.0.1 - Authenticated Remote Code Execution
CVSS 9.9
CVE-2026-4039 MEDIUM
OpenClaw 2026.2.19-2 - Code Injection
CVSS 6.3
CVE-2026-3993 MEDIUM
itsourcecode Payroll Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3990 MEDIUM
CesiumJS <= 1.137.0 - Cross-Site Scripting in Sandcastle Standalone HTML
CVSS 4.3
CVE-2026-3984 LOW
Campcodes Division Regional Athletic Meet Game Result Matrix System...
CVSS 3.5
CVE-2026-3983 LOW
Campcodes Division Regional Athletic Meet Game Result Matrix System...
CVSS 3.5
CVE-2026-3982 MEDIUM
itsourcecode University Management System 1.0 - XSS
CVSS 4.3
CVE-2026-3968 MEDIUM
AutohomeCorp frostmourne <1.0 - Code Injection
CVSS 6.3
CVE-2026-3962 MEDIUM
Jcharis Machine-Learning-Web-Apps - XSS
CVSS 4.3
CVE-2026-3955 MEDIUM
elecV2P <= 3.8.3 - Remote Code Execution via runJSFile Function
CVSS 6.3
CVE-2026-3951 MEDIUM
LockerProject Locker 0.0.0-0.1.0 - XSS
CVSS 4.3
CVE-2026-31861 HIGH
Cloud CLI <1.24.0 - Command Injection
CVSS 8.8
CVE-2026-31857 HIGH
Craft CMS 5.x < 5.9.9 and 4.x < 4.17.4 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2026-30741 CRITICAL
OpenClaw Agent Platform 2026.2.6 - RCE
CVSS 9.8
Details
Vulnerabilities 6,465
Exploit Likelihood Medium