CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,710 vulnerabilities with CWE-94
CVE-2026-16220 MEDIUM
code-projects Online Examination System account.php cross site scripting
CVSS 4.3
CVE-2026-16205 LOW
Pluck CMS Albums albums.admin.php htmlspecialchars_decode cross site scripting
CVSS 2.4
CVE-2026-16204 MEDIUM
zevorn rt-claw Telegram-to-AI Tool Execution Flow script.c tool_run_script_execute code injection
CVSS 6.3
CVE-2026-16203 LOW
SourceCodester Class and Exam Timetabling System forCYS.php cross site scripting
CVSS 3.5
CVE-2026-16202 LOW
SourceCodester Class and Exam Timetabling System CYS.php cross site scripting
CVSS 3.5
CVE-2026-16156 LOW
SourceCodester Class and Exam Timetabling System forexam.php cross site scripting
CVSS 3.5
CVE-2026-16155 LOW
SourceCodester Class and Exam Timetabling System schoolyr.php cross site scripting
CVSS 3.5
CVE-2026-16151 MEDIUM
CartoDB carto-api-client filters.ts addFilter prototype pollution
CVSS 6.3
CVE-2026-16150 MEDIUM
RobinHerbots Inputmask Internal Deep Merge Helper extend.js extendAliases prototype pollution
CVSS 6.3
CVE-2026-9147 HIGH
uproot 5.7.4 and prior Code Injection via TStreamerInfo Metadata
CVSS 7.8
CVE-2026-47869 HIGH
VMware Avi Load Balancer Remote Code Execution Vulnerability
CVSS 8.7
CVE-2026-47867 HIGH
VMware Avi Load Balancer Remote Code Execution Vulnerability
CVSS 8.7
CVE-2026-8635 CRITICAL
IBM Langflow OSS - Arbitrary Code Execution in Python Interpreter Component
CVSS 9.9
CVE-2026-8481 CRITICAL
IBM Langflow Oss < 1.10.0 - Remote Code Execution
CVSS 9.9
CVE-2026-8056 HIGH
IBM Langflow OSS 1.0.0-1.10.0 - API Graph Parameter Injection
CVSS 8.8
CVE-2026-52199 CRITICAL
Generic OEM UZ801_v2.1 4G LTE Router 3.4.3 - Remote Code Execution via sbin/adbd Component
CVSS 9.1
CVE-2026-9135 CRITICAL
Policies Component Dynamic CodeInput Fields Bypass Custom Component Validation
CVSS 9.9
CVE-2026-16073 LOW
AstrBotDevs AstrBot T2I Feature base.py NetworkRenderStrategy.render cross site scripting
CVSS 3.5
CVE-2026-9762 HIGH
IBM Db2 11.5.0-11.5.9 and 12.1.0-12.1.4 - JDBC URL Remote Code Execution
CVSS 7.8
CVE-2026-9198 CRITICAL
IBM Langflow OSS 1.0.0-1.10.0 - Unauthenticated Remote Code Execution
CVSS 9.8
CVE-2026-16008 MEDIUM
sagold json-schema-library propertyDependencies.ts parsePropertyDependencies prototype pollution
CVSS 6.3
CVE-2026-46512 CRITICAL
Frogman: Dialplan template parameters interpolated into extensions_custom.conf without escaping
CVSS 9.9
CVE-2026-46621 CRITICAL
Yamcs: Authenticated Remote Code Execution (RCE) via Jython Algorithm Code Injection
CVSS 9.1
CVE-2026-46562 CRITICAL
Yamcs: Remote Code Execution via Mission Database algorithm override
CVSS 9.8
CVE-2026-44632 CRITICAL
Yamcs: Server-Side Code Injection (RCE) via Janino Expression Engine in `JavaExprAlgorithmExecutionFactory`
CVSS 9.1
Details
Vulnerabilities 6,710
Exploit Likelihood Medium