CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,710 vulnerabilities with CWE-94
CVE-2026-59866
CRITICAL
Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2026-59865
CRITICAL
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-53597
HIGH
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
CVE-2026-59862
HIGH
Kiota: Code Generation Literal Injection in the Python Generator
CVSS 7.5
CVE-2026-59861
HIGH
Kiota: Code Generation Literal Injection in Kiota Ruby Generator
CVSS 7.5
CVE-2026-59860
HIGH
Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59859
HIGH
Kiota: Code Generation Literal Injection in the PHP Generator
CVE-2026-55576
HIGH
MaaAssistantArknights: PR-title expression injection in release-preparation.yml
CVE-2026-30618
CRITICAL
Fay 4.3.1 - Remote Code Execution via MCP STDIO Server Command Injection
CVSS 9.8
CVE-2026-45534
CRITICAL
DataEase: RCE Vulnerability
CVE-2026-62350
HIGH
TDengine: UDF lead to RCE
CVSS 7.2
CVE-2026-61446
HIGH
PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery
CVSS 8.4
CVE-2026-61433
HIGH
PraisonAI before 4.6.78 Code Injection via API deployment generator
CVSS 7.8
CVE-2026-58655
HIGH
Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
CVSS 8.8
CVE-2026-46640
HIGH
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVSS 8.8
CVE-2026-46633
CRITICAL
Twig: PHP code injection via `{% use %}` template name
CVSS 9.8
CVE-2026-42049
HIGH
jadx: RCE Via Groovy Code Injection in Gradle Export
CVE-2026-38450
CRITICAL
Aetopia DAM 1.0.0 - RCE via Add/Update Project Name & Description Parameters
CVSS 9.8
CVE-2026-48322
CRITICAL
Adobe ColdFusion 2025 < 10 - Arbitrary Code Execution
CVSS 9.6
CVE-2026-50650
HIGH
Microsoft - .NET Framework Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-15410
HIGH
KEV
Sonicwall SMA1000 - Improper Control of Generation of Code ('Code Injection')
CVSS 7.2
CVE-2026-15715
MEDIUM
SourceCodester Class and Exam Timetabling System exam.php cross site scripting
CVSS 4.3
CVE-2026-56185
MEDIUM
Windows Admin Center Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-15702
MEDIUM
tamagui config.ts updateConfig prototype pollution
CVSS 6.3
CVE-2026-15699
MEDIUM
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
CVSS 6.3
Details
Vulnerabilities
6,710
Exploit Likelihood
Medium