CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,712 vulnerabilities with CWE-94
CVE-2026-7873 CRITICAL
IBM Langflow OSS 1.0.0-1.10.0 - Authenticated OS Command Execution
CVSS 9.9
CVE-2026-10134 CRITICAL
Unauthenticated Server-Side RCE via PythonCodeStructuredTool in Public Flows
CVSS 10.0
CVE-2026-10109 CRITICAL
IBM® Db2® is vulnerable to remote code execution due to improper pre-auth DRDA handshake handling
CVSS 9.8
CVE-2026-58138 CRITICAL
Orkes Conductor 3.21.21 < 3.30.2 Unauthenticated RCE via GraalVM Script Evaluators
CVSS 9.8
CVE-2026-48192 MEDIUM
Siemens Mendix Studio Pro 10.11 - Improper Control of Generation of Code ('Code Injection')
CVSS 5.4
CVE-2026-58116 CRITICAL
LLaMA-Factory 0.9.5 Remote Code Execution via WebUI Model Path
CVSS 9.8
CVE-2026-37637 CRITICAL
Alexantr filemanager 1.0 - Remote Code Execution via filemanager.php
CVSS 9.1
CVE-2026-13749 HIGH
Snowflake CLI Arbitrary Code Execution via Snowpark Annotation Processor Template Injection
CVSS 8.8
CVE-2026-13570 LOW
SourceCodester Inventory Management System User Registration Endpoint users_handler.php cross site scripting
CVSS 3.5
CVE-2026-13567 MEDIUM
code-projects Online Music Site POST Request Feedback.php cross site scripting
CVSS 4.3
CVE-2026-13558 LOW
CodeAstro Complaint Management System Report addreport cross site scripting
CVSS 3.5
CVE-2026-13557 MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
CVSS 4.3
CVE-2026-13556 MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php edit cross site scripting
CVSS 4.3
CVE-2026-13554 MEDIUM
itsourcecode Online Hotel Management System POST Request controller.php add cross site scripting
CVSS 4.3
CVE-2026-13536 MEDIUM
GotoHTTP reg.12x cross site scripting
CVSS 4.3
CVE-2026-13504 LOW
code-projects Project Management System Mail Compose mail.php cross site scripting
CVSS 3.5
CVE-2026-13500 HIGH
antlr ANTLR4 Grammar Action Block OutputFile.java code injection
CVSS 7.3
CVE-2026-13499 MEDIUM
yashpokharna2555 restaurent-management-system Registration login_register.php cross site scripting
CVSS 4.3
CVE-2026-53576 CRITICAL
Kestra: Unauthenticated RCE via /configs path-suffix auth-filter bypass
CVSS 10.0
CVE-2026-55441 HIGH
mise: Arbitrary command execution via task-include files in an untrusted, config-less repository
CVSS 8.6
CVE-2026-33646 CRITICAL
mise: Arbitrary Code Execution via Tera Templates in .tool-versions Files (Trust Bypass)
CVSS 9.6
CVE-2026-57315 HIGH
WordPress Blocksy Companion Pro plugin <= 2.1.45 - Remote Code Execution (RCE) vulnerability
CVSS 8.5
CVE-2026-50741 HIGH
Revive Adserver < 6.0.7 - Improper Control of Generation of Code ('Code Injection')
CVSS 8.8
CVE-2026-55413 CRITICAL
ToolJet - Marketplace Plugin Poisoning Enables Instance-Wide Remote Code Execution
CVE-2026-57456 HIGH
Vim: Arbitrary Code Execution via Python Omni-Completion Docstrings
CVSS 7.8
Details
Vulnerabilities 6,712
Exploit Likelihood Medium