CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,527 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 2 of 151
- CVE-2026-65660CRITICALCVSS 8.8EG 9.0⚠ KEV2026-08-11
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2026-34197CRITICALCVSS 8.8EG 9.0⚠ KEV2026-04-07
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ. Apache ActiveMQ Classic exposes the Jolokia JMX-HTTP bridge at /api/jolokia/ on the web console…
- CVE-2026-3910CRITICALCVSS 8.8EG 9.0⚠ KEV2026-03-12
Inappropriate implementation in V8 in Google Chrome prior to 146.0.7680.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
- CVE-2025-62593CRITICALCVSS 8.8EG 9.0⚠ KEV2025-11-26
Ray is an AI compute engine. Prior to version 2.52.0, developers working with Ray as a development tool can be exploited via a critical RCE vulnerability exploitable via Firefox and Safari. This vulnerability is due to an insufficient guar…
- CVE-2025-49704CRITICALCVSS 8.8EG 9.0⚠ KEV2025-07-08
Improper control of generation of code ('code injection') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
- CVE-2025-3928CRITICALCVSS 8.8EG 9.0⚠ KEV2025-04-25
Commvault Web Server has an unspecified vulnerability that can be exploited by a remote, authenticated attacker. According to the Commvault advisory: "Webservers can be compromised through bad actors creating and executing webshells." Fixe…
- CVE-2022-43769CRITICALCVSS 8.8EG 9.0⚠ KEV2023-04-03
Hitachi Vantara Pentaho Business Analytics Server prior to versions 9.4.0.1 and 9.3.0.2, including 8.3.x allow certain web services to set property values which contain Spring templates that are interpreted downstream.
- CVE-2023-22952CRITICALCVSS 8.8EG 9.0⚠ KEV2023-01-11
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
- CVE-2021-22894CRITICALCVSS 8.8EG 9.0⚠ KEV2021-05-27
A buffer overflow vulnerability exists in Pulse Connect Secure before 9.1R11.4 allows a remote authenticated attacker to execute arbitrary code as the root user via maliciously crafted meeting room.
- CVE-2020-9377CRITICALCVSS 8.8EG 9.0⚠ KEV2020-07-09
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2019-9082CRITICALCVSS 8.8EG 9.0⚠ KEV2019-02-24
ThinkPHP before 3.2.4, as used in Open Source BMS v1.1.1 and other products, allows Remote Command Execution via public//?s=index/\think\app/invokefunction&function=call_user_func_array&vars[0]=system&vars[1][]= followed by the command.
- CVE-2017-9822CRITICALCVSS 8.8EG 9.0⚠ KEV2017-07-20
DNN (aka DotNetNuke) before 9.1.1 has Remote Code Execution via a cookie, aka "2017-08 (Critical) Possible remote code execution on DNN sites."
- CVE-2014-4148CRITICALCVSS 8.8EG 9.0⚠ KEV2014-10-15
win32k.sys in the kernel-mode drivers in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows r…
- CVE-2013-3163CRITICALCVSS 8.8EG 9.0⚠ KEV2013-07-10
Microsoft Internet Explorer 8 through 10 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted web site, aka "Internet Explorer Memory Corruption Vulnerability," a different vulner…
- CVE-2013-1347CRITICALCVSS 8.8EG 9.0⚠ KEV2013-05-05
Microsoft Internet Explorer 8 does not properly handle objects in memory, which allows remote attackers to execute arbitrary code by accessing an object that (1) was not properly allocated or (2) is deleted, as exploited in the wild in May…
- CVE-2012-1856CRITICALCVSS 8.8EG 9.0⚠ KEV2012-08-15
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3,…
- CVE-2012-0158CRITICALCVSS 8.8EG 9.0⚠ KEV2012-04-10
The (1) ListView, (2) ListView2, (3) TreeView, and (4) TreeView2 ActiveX controls in MSCOMCTL.OCX in the Common Controls in Microsoft Office 2003 SP3, 2007 SP2 and SP3, and 2010 Gold and SP1; Office 2003 Web Components SP3; SQL Server 2000…
- CVE-2009-0556CRITICALCVSS 8.8EG 9.0⚠ KEV2009-04-03
Microsoft Office PowerPoint 2000 SP3, 2002 SP3, and 2003 SP3, and PowerPoint in Microsoft Office 2004 for Mac, allows remote attackers to execute arbitrary code via a PowerPoint file with an OutlineTextRefAtom containing an an invalid inde…
- CVE-2009-0238CRITICALCVSS 8.8EG 9.0⚠ KEV2009-02-25
Microsoft Office Excel 2000 SP3, 2002 SP3, 2003 SP3, and 2007 SP1; Excel Viewer 2003 Gold and SP3; Excel Viewer; Compatibility Pack for Word, Excel, and PowerPoint 2007 File Formats SP1; and Excel in Microsoft Office 2004 and 2008 for Mac …
- CVE-2021-39144CRITICALCVSS 8.5EG 9.0⚠ KEV2021-08-23
XStream is a simple library to serialize objects to XML and back again. In affected versions this vulnerability may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processed input stre…
- CVE-2020-17144CRITICALCVSS 8.4EG 9.0⚠ KEV2020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2025-6204CRITICALCVSS 8.0EG 9.0⚠ KEV2025-08-04
An Improper Control of Generation of Code (Code Injection) vulnerability affecting DELMIA Apriso from Release 2020 through Release 2025 could allow an attacker to execute arbitrary code.
- CVE-2025-23209CRITICALCVSS 8.0EG 9.0⚠ KEV2025-01-18
Craft is a flexible, user-friendly CMS for creating custom digital experiences on the web and beyond. This is an remote code execution (RCE) vulnerability that affects Craft 4 and 5 installs where your security key has already been comprom…
- CVE-2024-8069CRITICALCVSS 8.0EG 9.0⚠ KEV2024-11-12
Limited remote code execution with privilege of a NetworkService Account access in Citrix Session Recording if the attacker is an authenticated user on the same intranet as the session recording server
- CVE-2023-7101CRITICALCVSS 7.8EG 9.0⚠ KEV2023-12-24
Spreadsheet::ParseExcel version 0.65 is a Perl module used for parsing Excel files. Spreadsheet::ParseExcel is vulnerable to an arbitrary code execution (ACE) vulnerability due to passing unvalidated input from a file into a string-type ��…
- CVE-2017-8759CRITICALCVSS 7.8EG 9.0⚠ KEV2017-09-13
Microsoft .NET Framework 2.0, 3.5, 3.5.1, 4.5.2, 4.6, 4.6.1, 4.6.2 and 4.7 allow an attacker to execute code remotely via a malicious document or application, aka ".NET Framework Remote Code Execution Vulnerability."
- CVE-2014-6352CRITICALCVSS 7.8EG 9.0⚠ KEV2014-10-22
Microsoft Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allow remote attackers to execute arbitrary code via a crafted OLE object,…
- CVE-2013-3906CRITICALCVSS 7.8EG 9.0⚠ KEV2013-11-06
GDI+ in Microsoft Windows Vista SP2 and Server 2008 SP2; Office 2003 SP3, 2007 SP3, and 2010 SP1 and SP2; Office Compatibility Pack SP3; and Lync 2010, 2010 Attendee, 2013, and Basic 2013 allows remote attackers to execute arbitrary code v…
- CVE-2010-0188CRITICALCVSS 7.8EG 9.0⚠ KEV2010-02-22
Unspecified vulnerability in Adobe Reader and Acrobat 8.x before 8.2.1 and 9.x before 9.3.1 allows attackers to cause a denial of service (application crash) or possibly execute arbitrary code via unknown vectors.
- CVE-2009-3129CRITICALCVSS 7.8EG 9.0⚠ KEV2009-11-11
Microsoft Office Excel 2002 SP3, 2003 SP3, and 2007 SP1 and SP2; Office 2004 and 2008 for Mac; Open XML File Format Converter for Mac; Office Excel Viewer 2003 SP3; Office Excel Viewer SP1 and SP2; and Office Compatibility Pack for Word, E…
- CVE-2009-1862CRITICALCVSS 7.8EG 9.0⚠ KEV2009-07-23
Unspecified vulnerability in Adobe Reader and Acrobat 9.x through 9.1.2, and Adobe Flash Player 9.x through 9.0.159.0 and 10.x through 10.0.22.87, allows remote attackers to execute arbitrary code or cause a denial of service (memory corru…
- CVE-2009-0557CRITICALCVSS 7.8EG 9.0⚠ KEV2009-06-10
Excel in Microsoft Office 2000 SP3, Office XP SP3, Office 2003 SP3, and Office 2004 and 2008 for Mac; Excel in 2007 Microsoft Office System SP1 and SP2; Open XML File Format Converter for Mac; Microsoft Office Excel Viewer 2003 SP3; Micros…
- CVE-2024-21351CRITICALCVSS 7.6EG 9.0⚠ KEV2024-02-13
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2026-15410CRITICALCVSS 7.2EG 9.0⚠ KEV2026-07-14
Post-authentication improper control of generation of code ('Code Injection') vulnerability has been identified in the SMA1000 Appliance Management Console (AMC) which in specific conditions could potentially enable a remote authenticated …
- CVE-2025-4428CRITICALCVSS 7.2EG 9.0⚠ KEV2025-05-13
Remote Code Execution in API component in Ivanti Endpoint Manager Mobile 12.5.0.0 and prior on unspecified platforms allows authenticated attackers to execute arbitrary code via crafted API requests.
- CVE-2023-41179CRITICALCVSS 7.2EG 9.0⚠ KEV2023-09-19
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute…
- CVE-2023-24955CRITICALCVSS 7.2EG 9.0⚠ KEV2023-05-09
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2021-22900CRITICALCVSS 7.2EG 9.0⚠ KEV2021-05-27
A vulnerability allowed multiple unrestricted uploads in Pulse Connect Secure before 9.1R11.4 that could lead to an authenticated administrator to perform a file write via a maliciously crafted archive upload in the administrator web inter…
- CVE-2020-8243CRITICALCVSS 7.2EG 9.0⚠ KEV2020-09-30
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
- CVE-2020-8218CRITICALCVSS 7.2EG 9.0⚠ KEV2020-07-30
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
- CVE-2019-0193CRITICALCVSS 7.2EG 9.0⚠ KEV2019-08-01
In Apache Solr, the DataImportHandler, an optional but popular module to pull in data from databases and other sources, has a feature in which the whole DIH configuration can come from a request's "dataConfig" parameter. The debug mode of …
- CVE-2022-41223CRITICALCVSS 6.8EG 9.0⚠ KEV2022-11-22
The Director database component of MiVoice Connect through 19.3 (22.22.6100.0) could allow an authenticated attacker to conduct a code-injection attack via crafted data due to insufficient restrictions on the database data type.
- CVE-2021-22204CRITICALCVSS 6.8EG 9.0⚠ KEV2021-04-23
Improper neutralization of user data in the DjVu file format in ExifTool versions 7.44 and up allows arbitrary code execution when parsing the malicious image
- CVE-2025-1976CRITICALCVSS 6.7EG 9.0⚠ KEV2025-04-24
Brocade Fabric OS versions starting with 9.1.0 have root access removed, however, a local user with admin privilege can potentially execute arbitrary code with full root privileges on Fabric OS versions 9.1.0 through 9.1.1d6.
- CVE-2024-20359CRITICALCVSS 6.0EG 9.0⚠ KEV2024-04-24
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allo…
- CVE-2023-6548CRITICALCVSS 5.5EG 9.0⚠ KEV2024-01-17
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execu…
- CVE-2026-42696CRITICALCVSS 10.0EG 10.02026-10-10
Unauthenticated Remote Code Execution (RCE) in SiteVault – Backup, Restore, Migration & Cloning <= 1.5.19 versions.
- CVE-2026-105857CRITICALCVSS 10.0EG 10.02026-10-06
Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary versions before 4.0.0-canary.34, an attacker can craft a form submission that executes code remotely…
- CVE-2026-105135CRITICALCVSS 10.0EG 10.02026-10-04
A vulnerability has been found in InternLM MindSearch 0.1.0. This issue affects the function ExecutionAction.run of the file mindsearch/agent/graph.py of the component Planner Agent. The manipulation of the argument inputs leads to code in…
- CVE-2026-96349CRITICALCVSS 10.0EG 10.02026-09-30
Unauthenticated Remote Code Execution (RCE) in SiteSkite <= 2.1.8 versions.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Book a Demo →