CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,712 vulnerabilities with CWE-94
CVE-2026-7873
CRITICAL
IBM Langflow OSS 1.0.0-1.10.0 - Authenticated OS Command Execution
CVSS 9.9
CVE-2026-10134
CRITICAL
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CVSS 10.0
CVE-2026-10109
CRITICAL
IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
CVSS 9.8
CVE-2026-58138
CRITICAL
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVSS 9.8
CVE-2026-48192
MEDIUM
Siemens Mendix Studio Pro 10.11 - Improper Control of Generation of Code ('Code Injection')
CVSS 5.4
CVE-2026-58116
CRITICAL
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVSS 9.8
CVE-2026-37637
CRITICAL
Alexantr filemanager 1.0 - Remote Code Execution via filemanager.php
CVSS 9.1
CVE-2026-13749
HIGH
Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection
CVSS 8.8
CVE-2026-13570
LOW
SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting
CVSS 3.5
CVE-2026-13567
MEDIUM
code-projects Online Music Site POST Request Feedback.php cross site scripting
CVSS 4.3
CVE-2026-13558
LOW
CodeAstro Complaint Management System Report addreport cross site scripting
CVSS 3.5
CVE-2026-13557
MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
CVSS 4.3
CVE-2026-13556
MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
CVSS 4.3
CVE-2026-13554
MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
CVSS 4.3
CVE-2026-13536
MEDIUM
GotoHTTP reg.12x cross site scripting
CVSS 4.3
CVE-2026-13504
LOW
code-projects Project Management System Mail Compose mail.php cross site scripting
CVSS 3.5
CVE-2026-13500
HIGH
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
CVSS 7.3
CVE-2026-13499
MEDIUM
yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
CVSS 4.3
CVE-2026-53576
CRITICAL
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVSS 10.0
CVE-2026-55441
HIGH
mise: Arbitrary command execution via task-include files in an untrusted, config-less repository
CVSS 8.6
CVE-2026-33646
CRITICAL
mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
CVSS 9.6
CVE-2026-57315
HIGH
WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE) vulnerability
CVSS 8.5
CVE-2026-50741
HIGH
Revive Adserver < 6.0.7 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-55413
CRITICAL
ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution
CVE-2026-57456
HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVSS 7.8
Details
Vulnerabilities
6,712
Exploit Likelihood
Medium