CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,710 vulnerabilities with CWE-94
CVE-2026-61444
CRITICAL
PraisonAI before 4.6.78 Code Injection via f-string
CVSS 9.1
CVE-2026-15321
LOW
MyEMS Admin Backend svg.py on_post cross site scripting
CVSS 2.4
CVE-2026-54769
CRITICAL
Langroid: Sandbox Escape to Remote Code Execution via Incomplete `eval()` Mitigation in TableChatAgent
CVSS 10.0
CVE-2026-15311
LOW
NousResearch hermes-agent Matrix Adapter matrix.py MatrixAdapter._markdown_to_html cross site scripting
CVSS 3.5
CVE-2026-59858
HIGH
Vim: Arbitrary Code Execution via C Omni-Completion
CVSS 7.8
CVE-2026-59856
HIGH
Vim: Arbitrary Code Execution via PHP Omni-Completion
CVSS 7.8
CVE-2026-59833
HIGH
SiYuan: Stored XSS to RCE in SiYuan via a per-attribute URL-scheme sanitizer gap in Lute (form action / SVG xlink:href)
CVE-2026-59826
CRITICAL
Metabase: Arbitrary Code Execution via Database Connection Detail Bypass
CVSS 9.1
CVE-2026-15202
MEDIUM
YzmCMS Header yzmphp.php get_url cross site scripting
CVSS 4.3
CVE-2026-15195
MEDIUM
apidevtools json-schema-ref-parser pointer.ts Pointer.set prototype pollution
CVSS 6.3
CVE-2026-59216
HIGH
Open WebUI: Cross-user code-interpreter and tool execution via unvalidated Socket.IO event-caller session_id
CVSS 7.7
CVE-2026-15187
MEDIUM
enquirer Public Package API Enquirer.set prototype pollution
CVSS 4.3
CVE-2026-52200
CRITICAL
Generic OEM UZ801 4G LTE Router 3.4.3 - Unauthenticated Remote Code Execution via MifiService /ajax API Endpoint
CVSS 9.8
CVE-2026-35211
MEDIUM
OpenCTI < 7.260401.0 - Authenticated Painless Script Denial of Service
CVSS 6.5
CVE-2026-59821
HIGH
LiteLLM: Custom Code Guardrails production endpoints bypass code safety checks
CVSS 7.2
CVE-2026-53951
HIGH
Copier: trust-prefix bypass via path traversal runs tasks unprompted
CVE-2026-55408
HIGH
Koodo Reader: Remote code execution via malicious epub file
CVE-2026-53751
HIGH
DataEase: H2 JDBC URL Filter Bypass Leads to Remote Code Execution (RCE)
CVE-2026-53511
HIGH
calibre: Arbitrary Code Execution in Template Formatter via Book Metadata
CVE-2026-43921
HIGH
FOSSBilling vulnerable to arbitrary PHP code injection via unescaped config serialization
CVE-2026-57572
CRITICAL
Crawl4AI: Unauthenticated RCE via Chromium launch-argument injection in browser_config.extra_args
CVSS 10.0
CVE-2026-48614
CRITICAL
Webpros Plesk < 18.0.78 - Improper Control of Generation of Code ('Code Injection')
CVSS 9.9
CVE-2026-14791
LOW
crater-invoice-inc crater Invoice Note InvoicesRequest.php getFormattedString cross site scripting
CVSS 3.5
CVE-2026-14752
LOW
mjperpinosa stumasy add_into_dictionary.php add_definition cross site scripting
CVSS 3.5
CVE-2026-14749
HIGH
mjperpinosa stumasy calculate.php eval code injection
CVSS 7.3
Details
Vulnerabilities
6,710
Exploit Likelihood
Medium