CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,184 vulnerabilities with CWE-94
CVE-2026-6619
LOW
langgenius dify ImagePreview image-preview.tsx openInNewTab cross site scripting
CVSS 3.5
CVE-2026-41282
MEDIUM
ProjectDiscovery Nuclei <3.8.0 - DSL Injection
CVSS 4.0
CVE-2026-6603
HIGH
modelscope agentscope _python.py execute_shell_command code injection
CVSS 7.3
CVE-2026-6600
LOW
langflow-ai langflow Frontend React Component Rendering edit-message.tsx cross site scripting
CVSS 3.5
CVE-2026-6594
HIGH
brikcss merge prototype pollution
CVSS 7.3
CVE-2026-6593
LOW
ComfyUI View Endpoint server.py cross site scripting
CVSS 3.5
CVE-2026-6592
LOW
ComfyUI userdata Endpoint user_manager.py getuserdata cross site scripting
CVSS 3.5
CVE-2026-6559
MEDIUM
Wavlink WL-WN579A3 login.cgi sub_401F80 cross site scripting
CVSS 4.3
CVE-2026-41242
CRITICAL
protobufjs has an arbitrary code execution issue
CVSS 9.8
CVE-2026-40342
CRITICAL
Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution
CVSS 9.9
CVE-2026-6493
LOW
lukevella rallly Reset Password reset-password-form.tsx cross site scripting
CVSS 3.5
CVE-2026-6486
LOW
classroombookings User Display Name layout.php read cross site scripting
CVSS 3.5
CVE-2026-40322
CRITICAL
SiYuan: Mermaid `javascript:` Link Injection Leads to Stored XSS and Electron RCE
CVSS 9.0
CVE-2026-40316
HIGH
OWASP BLT has RCE in Github Actions via untrusted Django model execution in workflow
CVSS 8.8
CVE-2026-33435
HIGH
Weblate: Remote code execution during backup restoration
CVSS 8.0
CVE-2026-30993
CRITICAL
Slah CMS <=1.5.0 - RCE
CVSS 9.8
CVE-2026-39842
CRITICAL
OpenRemote is Vulnerable to Expression Injection
CVSS 9.9
CVE-2026-1509
MEDIUM
Avada (Fusion) Builder <= 3.15.1 - Authenticated (Subscriber+) Limited Arbitrary WordPress Action Execution
CVSS 5.4
CVE-2026-25125
MEDIUM
October CMS: Environment Variable Exfiltration via INI Parser Interpolation
CVSS 4.9
CVE-2026-2582
MEDIUM
Germanized for WooCommerce <= 3.20.5 - Unauthenticated Arbitrary Shortcode Execution
CVSS 6.5
CVE-2026-40288
CRITICAL
PraisonAI: Critical RCE via `type: job` workflow YAML
CVSS 9.8
CVE-2026-40287
HIGH
PraisonAI has RCE via Automatic tools.py Import
CVSS 8.4
CVE-2026-39421
MEDIUM
MaxKB: Sandbox escape via ctypes and unhooked SYS_pkey_mprotect
CVSS 6.3
CVE-2026-27675
LOW
Code Injection vulnerability in SAP Landscape Transformation
CVSS 2.0
CVE-2026-27674
MEDIUM
Code Injection vulnerability in SAP NetWeaver Application Server Java (Web Dynpro Java)
CVSS 6.1
Details
Vulnerabilities
6,184
Exploit Likelihood
Medium