CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,710 vulnerabilities with CWE-94
CVE-2026-59866 CRITICAL
Kiota: Arbitrary file write + code-injection via x-ms-kiota-info clientClassName and clientNamespaceName
CVE-2026-59865 CRITICAL
Kiota: Command injection via x-ms-kiota-info dependencyInstallCommand surfaced by `kiota info`
CVE-2026-53597 HIGH
Prompty: Arbitrary code execution via JavaScript frontmatter in TypeScript loader
CVE-2026-59862 HIGH
Kiota: Code Generation Literal Injection in the Python Generator
CVSS 7.5
CVE-2026-59861 HIGH
Kiota: Code Generation Literal Injection in Kiota Ruby Generator
CVSS 7.5
CVE-2026-59860 HIGH
Kiota: XML Doc-Comment Newline Breakout Code Injection
CVE-2026-59859 HIGH
Kiota: Code Generation Literal Injection in the PHP Generator
CVE-2026-55576 HIGH
MaaAssistantArknights: PR-title expression injection in release-preparation.yml
CVE-2026-30618 CRITICAL
Fay 4.3.1 - Remote Code Execution via MCP STDIO Server Command Injection
CVSS 9.8
CVE-2026-45534 CRITICAL
DataEase: RCE Vulnerability
CVE-2026-62350 HIGH
TDengine: UDF lead to RCE
CVSS 7.2
CVE-2026-61446 HIGH
PraisonAI before 1.6.78 Remote Code Execution via Plugin Auto-Discovery
CVSS 8.4
CVE-2026-61433 HIGH
PraisonAI before 4.6.78 Code Injection via API deployment generator
CVSS 7.8
CVE-2026-58655 HIGH
Grav Flex Objects - Server-Side Template Injection via Dynamic Titles
CVSS 8.8
CVE-2026-46640 HIGH
Twig: Arbitrary PHP code execution via `_self.(<string>)` macro-reference compilation
CVSS 8.8
CVE-2026-46633 CRITICAL
Twig: PHP code injection via `{% use %}` template name
CVSS 9.8
CVE-2026-42049 HIGH
jadx: RCE Via Groovy Code Injection in Gradle Export
CVE-2026-38450 CRITICAL
Aetopia DAM 1.0.0 - RCE via Add/Update Project Name & Description Parameters
CVSS 9.8
CVE-2026-48322 CRITICAL
Adobe ColdFusion 2025 < 10 - Arbitrary Code Execution
CVSS 9.6
CVE-2026-50650 HIGH
Microsoft - .NET Framework Elevation of Privilege Vulnerability
CVSS 7.8
CVE-2026-15410 HIGH KEV
Sonicwall SMA1000 - Improper Control of Generation of Code ('Code Injection')
CVSS 7.2
CVE-2026-15715 MEDIUM
SourceCodester Class and Exam Timetabling System exam.php cross site scripting
CVSS 4.3
CVE-2026-56185 MEDIUM
Windows Admin Center Information Disclosure Vulnerability
CVSS 6.5
CVE-2026-15702 MEDIUM
tamagui config.ts updateConfig prototype pollution
CVSS 6.3
CVE-2026-15699 MEDIUM
spencermountain compromise Public Root API extend.js nlp.extend prototype pollution
CVSS 6.3
Details
Vulnerabilities 6,710
Exploit Likelihood Medium