CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,527 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 1 of 151
- CVE-2025-37164CRITICALCVSS 10.0EG 10.0⚠ KEV2025-12-16
A remote code execution issue exists in HPE OneView.
- CVE-2025-32432CRITICALCVSS 10.0EG 10.0⚠ KEV2025-04-25
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Starting from version 3.0.0-RC1 to before 3.9.15, 4.0.0-RC1 to before 4.14.15, and 5.0.0-RC1 to before 5.6.17, Craft is vulnerable to rem…
- CVE-2022-24816CRITICALCVSS 10.0EG 10.0⚠ KEV2022-04-13
JAI-EXT is an open-source project which aims to extend the Java Advanced Imaging (JAI) API. Programs allowing Jiffle script to be provided via network request can lead to a Remote Code Execution as the Jiffle script is compiled into Java c…
- CVE-2022-22947CRITICALCVSS 10.0EG 10.0⚠ KEV2022-03-03
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuator endpoint is enabled, exposed and unsecured. A remote attacker could make a maliciously crafted r…
- CVE-2021-22205CRITICALCVSS 10.0EG 10.0⚠ KEV2021-04-23
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9. GitLab was not properly validating image files that were passed to a file parser which resulted in a remote command execution.
- CVE-2019-7609CRITICALCVSS 10.0EG 10.0⚠ KEV2019-03-25
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could …
- CVE-2019-10758CRITICALCVSS 9.9EG 9.9⚠ KEV2019-12-24
mongo-express before 0.54.0 is vulnerable to Remote Code Execution via endpoints that uses the `toBSON` method. A misuse of the `vm` dependency to perform `exec` commands in a non-safe environment.
- CVE-2026-60004CRITICALCVSS 9.8EG 9.8⚠ KEV2026-08-26
Gitea before 1.27.1 allows remote code execution via the diffpatch API through Git hook installation.
- CVE-2026-9198CRITICALCVSS 9.8EG 9.8⚠ KEV2026-07-17
IBM Langflow OSS 1.0.0 through 1.10.0 allows unauthenticated attackers to chain /api/v1/auto_login (mints SUPERUSER tokens to any network caller) with /api/v1/validate/code (executes user code via exec()) to achieve full RCE on default Lan…
- CVE-2026-33017CRITICALCVSS 9.8EG 9.8⚠ KEV2026-03-20
Langflow is a tool for building and deploying AI-powered agents and workflows. In versions prior to 1.9.0, the POST /api/v1/build_public_tmp/{flow_id}/flow endpoint allows building public flows without requiring authentication. When the op…
- CVE-2025-67038CRITICALCVSS 9.8EG 9.8⚠ KEV2026-03-11
An issue was discovered in Lantronix EDS5000 2.1.0.0R3. The HTTP RPC module executes a shell command to write logs when user's authentication fails. The username is directly concatenated with the command without any sanitization. This allo…
- CVE-2026-1340CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-29
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-1281CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-29
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
- CVE-2026-20045CRITICALCVSS 9.8EG 9.8⚠ KEV2026-01-21
A vulnerability in Cisco Unified Communications Manager (Unified CM), Cisco Unified Communications Manager Session Management Edition (Unified CM SME), Cisco Unified Communications Manager IM & Presence Service (Unified CM IM&P), C…
- CVE-2025-54068CRITICALCVSS 9.8EG 9.8⚠ KEV2025-07-17
Livewire is a full-stack framework for Laravel. In Livewire v3 up to and including v3.6.3, a vulnerability allows unauthenticated attackers to achieve remote command execution in specific scenarios. The issue stems from how certain compone…
- CVE-2025-3248CRITICALCVSS 9.8EG 9.8⚠ KEV2025-04-07
Langflow versions prior to 1.3.0 are susceptible to code injection in the /api/v1/validate/code endpoint. A remote and unauthenticated attacker can send crafted HTTP requests to execute arbitrary code.
- CVE-2025-24893CRITICALCVSS 9.8EG 9.8⚠ KEV2025-02-20
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any guest can perform arbitrary remote code execution through a request to `SolrSearch`. This impacts the confidentiality, integrity a…
- CVE-2024-56145CRITICALCVSS 9.8EG 9.8⚠ KEV2024-12-18
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. Users of affected versions are affected by this vulnerability if their php.ini configuration has `register_argc_argv` enabled. For these …
- CVE-2024-36401CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-01
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users throug…
- CVE-2024-23692CRITICALCVSS 9.8EG 9.8⚠ KEV2024-05-31
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a…
- CVE-2024-4040CRITICALCVSS 9.8EG 9.8⚠ KEV2024-04-22
A server side template injection vulnerability in CrushFTP in all versions before 10.7.1 and 11.1.0 on all platforms allows unauthenticated remote attackers to read files from the filesystem outside of the VFS Sandbox, bypass authenticatio…
- CVE-2023-3519CRITICALCVSS 9.8EG 9.8⚠ KEV2023-07-19
Unauthenticated remote code execution
- CVE-2023-33246CRITICALCVSS 9.8EG 9.8⚠ KEV2023-05-24
For RocketMQ versions 5.1.0 and below, under certain conditions, there is a risk of remote command execution. Several components of RocketMQ, including NameServer, Broker, and Controller, are leaked on the extranet and lack permission v…
- CVE-2023-29492CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-11
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
- CVE-2023-25717CRITICALCVSS 9.8EG 9.8⚠ KEV2023-02-13
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin?login_username=admin&password=password$(curl substring.
- CVE-2022-3236CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-23
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- CVE-2022-22954CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-11
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection. A malicious actor with network access can trigger a server-side template injection that may result in rem…
- CVE-2022-22965CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-01
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deplo…
- CVE-2022-22963CRITICALCVSS 9.8EG 9.8⚠ KEV2022-04-01
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to provide a specially crafted SpEL as a routing-expression that may result in remote code execution …
- CVE-2021-44529CRITICALCVSS 9.8EG 9.8⚠ KEV2021-12-08
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
- CVE-2021-22502CRITICALCVSS 9.8EG 9.8⚠ KEV2021-02-08
Remote Code execution vulnerability in Micro Focus Operation Bridge Reporter (OBR) product, affecting version 10.40. The vulnerability could be exploited to allow Remote Code Execution on the OBR server.
- CVE-2020-25223CRITICALCVSS 9.8EG 9.8⚠ KEV2020-09-25
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
- CVE-2020-5902CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-01
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vuln…
- CVE-2020-5847CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-16
Unraid through 6.8.0 allows Remote Code Execution.
- CVE-2020-8644CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-05
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- CVE-2019-4716CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-18
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
- CVE-2019-16759CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-24
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
- CVE-2019-11581CRITICALCVSS 9.8EG 9.8⚠ KEV2019-08-09
There was a server-side template injection vulnerability in Jira Server and Data Center, in the ContactAdministrators and the SendBulkMail actions. An attacker is able to remotely execute code on systems that run a vulnerable version of Ji…
- CVE-2018-14667CRITICALCVSS 9.8EG 9.8⚠ KEV2018-11-06
The RichFaces Framework 3.X through 3.3.4 is vulnerable to Expression Language (EL) injection via the UserResource resource. A remote, unauthenticated attacker could exploit this to execute arbitrary code using a chain of java serialized o…
- CVE-2018-7602CRITICALCVSS 9.8EG 9.8⚠ KEV2018-07-19
A remote code execution vulnerability exists within multiple subsystems of Drupal 7.x and 8.x. This potentially allows attackers to exploit multiple attack vectors on a Drupal site, which could result in the site being compromised. This vu…
- CVE-2018-1273CRITICALCVSS 9.8EG 9.8⚠ KEV2018-04-11
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerability caused by improper neutralization of special elements. An unauthenticated remote malicious user (…
- CVE-2017-9841CRITICALCVSS 9.8EG 9.8⚠ KEV2017-06-27
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST data beginning with a "<?php " substring, as demonstrated by an attack on a site with an exposed /ven…
- CVE-2017-7494CRITICALCVSS 9.8EG 9.8⚠ KEV2017-05-30
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious client to upload a shared library to a writable share, and then cause the server to load and execute i…
- CVE-2015-7450CRITICALCVSS 9.8EG 9.8⚠ KEV2016-01-02
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…
- CVE-2015-1635CRITICALCVSS 9.8EG 9.8⚠ KEV2015-04-14
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution V…
- CVE-2014-6287CRITICALCVSS 9.8EG 9.8⚠ KEV2014-10-07
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackers to execute arbitrary programs via a %00 sequence in a search action.
- CVE-2013-4810CRITICALCVSS 9.8EG 9.8⚠ KEV2013-09-16
HP ProCurve Manager (PCM) 3.20 and 4.0, PCM+ 3.20 and 4.0, Identity Driven Manager (IDM) 4.0, and Application Lifecycle Management allow remote attackers to execute arbitrary code via a marshalled object to (1) EJBInvokerServlet or (2) JMX…
- CVE-2009-1151CRITICALCVSS 9.8EG 9.8⚠ KEV2009-03-26
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inject arbitrary PHP code into a configuration file via the save action.
- CVE-2008-4250CRITICALCVSS 9.8EG 9.8⚠ KEV2008-10-23
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta allows remote attackers to execute arbitrary code via a crafted RPC request that triggers the overfl…
- CVE-2026-72530CRITICALCVSS 9.0EG 9.0⚠ KEV2026-08-19
A remote unauthorized attacker with network access via port 4307/TCP to the TrueConf server versions 5.3.X to 5.3.9, 5.4.X to 5.4.9, 5.5.X to 5.5.5, and earlier could use a specially crafted script to break out of the isolated environment …
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →