CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,138 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 126 of 143
- CVE-2026-29075CRITICALCVSS 9.8EG 9.82026-03-06
Mesa is an open-source Python library for agent-based modeling, simulating complex systems and exploring emergent behaviors. In version 3.5.0 and prior, checking out of untrusted code in benchmarks.yml workflow may lead to code execution i…
- CVE-2026-29091HIGHCVSS 8.1EG 8.12026-03-06
Locutus brings stdlibs of other programming languages to JavaScript for educational purposes. Prior to version 3.0.0, a remote code execution (RCE) flaw was discovered in the locutus project, specifically within the call_user_func_array fu…
- CVE-2026-29102HIGHCVSS 8.8EG 8.82026-03-19
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. Prior to versions 7.15.1 and 8.9.3, an Authenticated Remote Code Execution (RCE) vulnerability exists in SuiteCRM modules. Versions 7…
- CVE-2026-29103HIGHCVSS 7.2EG 7.22026-03-19
SuiteCRM is an open-source, enterprise-ready Customer Relationship Management (CRM) software application. A Critical Remote Code Execution (RCE) vulnerability exists in SuiteCRM 7.15.0 and 8.9.2, allowing authenticated administrators to ex…
- CVE-2026-29202HIGHCVSS 8.8EG 8.82026-05-08
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
- CVE-2026-2932MEDIUMCVSS 4.8EG 4.82026-02-22
A security flaw has been discovered in YiFang CMS up to 2.0.5. The impacted element is the function update of the file app/db/admin/D_adPosition.php of the component Extended Management Module. Performing a manipulation of the argument nam…
- CVE-2026-2933MEDIUMCVSS 4.8EG 4.82026-02-22
A weakness has been identified in YiFang CMS up to 2.0.5. This affects the function update of the file app/db/admin/D_adManage.php of the component Extended Management Module. Executing a manipulation of the argument Name can lead to cross…
- CVE-2026-2934MEDIUMCVSS 4.8EG 4.82026-02-22
A security vulnerability has been detected in YiFang CMS up to 2.0.5. This impacts the function update of the file app/db/admin/D_friendLinkGroup.php of the component Extended Management Module. The manipulation of the argument Name leads …
- CVE-2026-2939MEDIUMCVSS 4.8EG 4.82026-02-22
A vulnerability was found in itsourcecode Student Management System 1.0. The impacted element is an unknown function of the file /add_student/ of the component Add Student Module. The manipulation results in cross site scripting. It is pos…
- CVE-2026-2943MEDIUMCVSS 4.3EG 4.32026-02-22
A vulnerability was identified in SapneshNaik Student Management System up to f4b4f0928f0b5551a28ee81ae7e7fe47d9345318. This impacts an unknown function of the file index.php. Such manipulation of the argument Error leads to cross site scr…
- CVE-2026-2946MEDIUMCVSS 5.4EG 5.42026-02-22
A security vulnerability has been detected in rymcu forest up to 0.0.5. Affected by this issue is the function XssUtils.replaceHtmlCode of the file src/main/java/com/rymcu/forest/util/XssUtils.java of the component Article Content/Comments…
- CVE-2026-2947MEDIUMCVSS 5.4EG 5.42026-02-22
A vulnerability was detected in rymcu forest up to 0.0.5. This affects the function updateUserInfo of the file - src/main/java/com/rymcu/forest/web/api/user/UserInfoController.java of the component User Profile Handler. The manipulation re…
- CVE-2026-2964CRITICALCVSS 9.8EG 9.82026-02-23
A vulnerability was identified in higuma web-audio-recorder-js 0.1/0.1.1. Impacted is the function extend in the library lib/WebAudioRecorder.js of the component Dynamic Config Handling. Such manipulation leads to improperly controlled mod…
- CVE-2026-2965LOWCVSS 2.4EG 2.42026-02-23
A security flaw has been discovered in 07FLYCMS, 07FLY-CMS and 07FlyCRM up to 1.2.9. The affected element is an unknown function of the file /admin/SysModule/edit.html of the component System Extension Module. Performing a manipulation of …
- CVE-2026-2971MEDIUMCVSS 6.1EG 6.12026-02-23
A vulnerability was found in a466350665 Smart-SSO up to 2.1.1. Affected by this issue is some unknown functionality of the file smart-sso-server/src/main/resources/templates/login.html of the component Login. Performing a manipulation of t…
- CVE-2026-2972MEDIUMCVSS 5.4EG 5.42026-02-23
A vulnerability was determined in a466350665 Smart-SSO up to 2.1.1. This affects the function Save of the file smart-sso-server/src/main/java/openjoe/smart/sso/server/controller/admin/UserController.java of the component Role Edit Page. Ex…
- CVE-2026-29859CRITICALCVSS 9.8EG 9.82026-03-18
An arbitrary file upload vulnerability in aaPanel v7.57.0 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2026-29955HIGHCVSS 8.8EG 8.82026-04-13
The `/registercrd` endpoint in KubePlus 4.14 in the kubeconfiggenerator component is vulnerable to command injection. The component uses `subprocess.Popen()` with `shell=True` parameter to execute shell commands, and the user-supplied `cha…
- CVE-2026-30117CRITICALCVSS 9.8EG 9.82026-05-19
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execute arbitrary code via uploading a crafted…
- CVE-2026-30120CRITICALCVSS 9.8EG 9.82026-06-15
remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability.
- CVE-2026-3027MEDIUMCVSS 6.1EG 6.12026-02-23
A vulnerability was found in erzhongxmu JEEWMS up to 3.7. This affects an unknown part of the file src/main/webapp/plug-in/ueditor/jsp/getContent.jsp of the component UEditor. The manipulation of the argument myEditor results in cross site…
- CVE-2026-3028MEDIUMCVSS 6.1EG 6.12026-02-23
A vulnerability was determined in erzhongxmu JEEWMS up to 3.7. This vulnerability affects the function doAdd of the file src/main/java/com/jeecg/demo/controller/JeecgListDemoController.java. This manipulation of the argument Name causes cr…
- CVE-2026-30305CRITICALCVSS 9.8EG 9.82026-03-30
Syntx's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structures;…
- CVE-2026-30306CRITICALCVSS 9.8EG 9.82026-03-30
In its design for automatic terminal command execution, SakaDev offers two options: Execute safe commands and execute all commands. The description for the former states that commands determined by the model to be safe will be automaticall…
- CVE-2026-30307CRITICALCVSS 9.8EG 9.82026-03-30
Roo Code's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on fragile regular expressions to parse command structur…
- CVE-2026-30308CRITICALCVSS 9.8EG 9.82026-03-30
In its design for automatic terminal command execution, HAI Build Code Generator offers two options: Execute safe commands and Execute all commands. The description for the former states that commands determined by the model to be safe wil…
- CVE-2026-30313CRITICALCVSS 9.8EG 9.82026-03-30
DSAI-Cline's command auto-approval module contains a critical OS command injection vulnerability that renders its whitelist security mechanism completely ineffective. The system relies on string-based parsing to validate commands; while it…
- CVE-2026-30402CRITICALCVSS 9.8EG 9.82026-03-19
An issue in wgcloud v.2.3.7 and before allows a remote attacker to execute arbitrary code via the test connection function
- CVE-2026-3041LOWCVSS 2.4EG 2.42026-02-23
A security vulnerability has been detected in xingfuggz BaykeShop up to 1.3.20. Impacted is an unknown function of the file src/baykeshop/contrib/article/templates/baykeshop/sidebar/custom.html of the component Article Sidebar Module. Such…
- CVE-2026-3043MEDIUMCVSS 6.1EG 6.12026-02-24
A flaw has been found in itsourcecode Event Management System 1.0. The impacted element is an unknown function of the file /admin/navbar.php. Executing a manipulation of the argument page can lead to cross site scripting. The attack may be…
- CVE-2026-30457CRITICALCVSS 9.8EG 9.82026-03-26
An issue in the /parser/dwoo component of Daylight Studio FuelCMS v1.5.2 allows attackers to execute arbitrary code via crafted PHP code.
- CVE-2026-30460HIGHCVSS 8.8EG 8.82026-04-07
Daylight Studio FuelCMS v1.5.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability in the Blocks module.
- CVE-2026-30479CRITICALCVSS 9.1EG 9.12026-04-09
A Dynamic-link Library Injection vulnerability in OSGeo Project MapServer before v8.0 allows attackers to execute arbitrary code via a crafted executable.
- CVE-2026-3050MEDIUMCVSS 5.4EG 5.42026-02-24
A flaw has been found in horilla-opensource horilla up to 1.0.2. Impacted is an unknown function of the file static/assets/js/global.js of the component Leads Module. This manipulation of the argument Notes causes cross site scripting. The…
- CVE-2026-3054MEDIUMCVSS 6.1EG 6.12026-02-24
A vulnerability was identified in Alinto SOGo 5.12.3/5.12.4. This impacts an unknown function. The manipulation of the argument hint leads to cross site scripting. The attack can be initiated remotely. The exploit is publicly available and…
- CVE-2026-30618CRITICALCVSS 9.8EG 9.82026-07-15
xszyou Fay 4.3.1 contains a remote code execution vulnerability in its MCP STDIO server management and command execution handling. A remote attacker can access the publicly exposed MCP management interface and configure an MCP STDIO server…
- CVE-2026-30643CRITICALCVSS 9.8EG 9.82026-04-01
An issue was discovered in DedeCMS 5.7.118 allowing attackers to execute code via crafted setup tag values in a module upload.
- CVE-2026-30694CRITICALCVSS 9.8EG 9.82026-03-19
An issue in DedeCMS v.5.7.118 and before allows a remote attacker to execute arbitrary code via the array_filter component
- CVE-2026-3070MEDIUMCVSS 6.1EG 6.12026-02-24
A vulnerability was detected in SourceCodester Modern Image Gallery App 1.0. Affected by this vulnerability is an unknown functionality of the file upload.php. The manipulation of the argument filename results in cross site scripting. The …
- CVE-2026-30741CRITICALCVSS 9.8EG 9.82026-03-11
A remote code execution (RCE) vulnerability in OpenClaw Agent Platform v2026.2.6 allows attackers to execute arbitrary code via a Request-Side prompt injection attack.
- CVE-2026-30875HIGHCVSS 8.8EG 8.82026-03-16
Chamilo LMS is a learning management system. Prior to version 1.11.36, an arbitrary file upload vulnerability in the H5P Import feature allows authenticated users with Teacher role to achieve Remote Code Execution (RCE). The H5P package va…
- CVE-2026-30887CRITICALCVSS 9.9EG 9.92026-03-10
OneUptime is a solution for monitoring and managing online services. Prior to 10.0.18, OneUptime allows project members to run custom Playwright/JavaScript code via Synthetic Monitors to test websites. However, the system executes this unt…
- CVE-2026-30960CRITICALCVSS 9.4EG 9.42026-03-10
rssn is a scientific computing library for Rust, combining a high-performance symbolic computation engine with numerical methods support and physics simulations functionalities. The vulnerability exists in the JIT (Just-In-Time) compilatio…
- CVE-2026-30993CRITICALCVSS 9.8EG 9.82026-04-15
Slah CMS v1.5.0 and below was discovered to contain a remote code execution (RCE) vulnerability in the session() function at config.php. This vulnerability is exploitable via a crafted input.
- CVE-2026-31018HIGHCVSS 8.8EG 8.82026-04-21
In Dolibarr ERP & CRM <= 22.0.4, PHP code detection and editing permission enforcement in the Website module is not applied consistently to all input parameters, allowing an authenticated user restricted to HTML/JavaScript editing to injec…
- CVE-2026-31040CRITICALCVSS 9.8EG 9.82026-04-08
A vulnerability was identified in stata-mcp prior to v1.13.0 where insufficient validation of user-supplied Stata do-file content can lead to command execution.
- CVE-2026-31048CRITICALCVSS 9.8EG 9.82026-04-13
An issue in the <code>pickle</code> protocol of Pyro v3.x allows attackers to execute arbitrary code via supplying a crafted pickled string message.
- CVE-2026-3120HIGHCVSS 7.2EG 7.22026-05-04
Improper Control of Generation of Code ('Code Injection') vulnerability in Profelis Information and Consulting Trade and Industry Limited Company SambaBox allows OS Command Injection. This issue affects SambaBox: from 5.1 before 5.3.
- CVE-2026-31217CRITICALCVSS 9.8EG 9.82026-05-12
The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user supplies a directory path via the --mode…
- CVE-2026-31220CRITICALCVSS 9.8EG 9.82026-05-12
PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged users to submit Python functions (via @…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →