CWE-94 · 5,488 records
Improper Control of Generation of Code ('Code Injection')
CVEs in this class
5,488 records
| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2022-24816Weaponized | Improper Control of Generation of Code in jai-extgeosolutionsgroup · jai-ext · CWE-94 | Critical10.0 | KEV | 99.9% | Apr 13, 2022 |
100Now | CVE-2025-32432Weaponized | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Critical10.0 | KEV | 99.8% | Apr 25, 2025 |
100Now | CVE-2021-22205Weaponized | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Critical10.0 | KEV | 99.7% | Apr 23, 2021 |
99Now | CVE-2017-9841Weaponized | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST daphpunit project · phpunit · CWE-94 | Critical9.8 | KEV | 100.0% | Jun 27, 2017 |
99Now | CVE-2015-1635Weaponized | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Critical9.8 | KEV | 100.0% | Apr 14, 2015 |
99Now | CVE-2022-22954Weaponized | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Critical9.8 | KEV | 100.0% | Apr 11, 2022 |
99Now | CVE-2022-22963Weaponized | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Critical9.8 | KEV | 99.9% | Apr 1, 2022 |
99Now | CVE-2023-3519Weaponized | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Critical9.8 | KEV | 99.7% | Jul 19, 2023 |
99Now | CVE-2019-16759Weaponized | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring revbulletin · vbulletin · CWE-94 | Critical9.8 | KEV | 99.7% | Sep 24, 2019 |
99Now | CVE-2022-22965Weaponized | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Critical9.8 | KEV | 99.6% | Apr 1, 2022 |
99Now | CVE-2017-7494Weaponized | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Critical9.8 | KEV | 99.4% | May 30, 2017 |
99Now | CVE-2014-6287Weaponized | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackerejetto · http file server · CWE-94 | Critical9.8 | KEV | 99.3% | Oct 7, 2014 |
99Now | CVE-2018-7602Weaponized | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Critical9.8 | KEV | 99.2% | Jul 19, 2018 |
99Now | CVE-2021-44529Weaponized | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code witivanti · endpoint manager cloud services appliance · CWE-94 | Critical9.8 | KEV | 99.1% | Dec 8, 2021 |
99Now | CVE-2022-3236Weaponized | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Critical9.8 | KEV | 98.9% | Sep 23, 2022 |
99Now | CVE-2008-4250Weaponized | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta amicrosoft · windows 2000 · CWE-94 | Critical9.8 | KEV | 98.8% | Oct 23, 2008 |
99Now | CVE-2026-1281Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.7% | Jan 29, 2026 |
99Now | CVE-2026-1340Weaponized | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Critical9.8 | KEV | 98.6% | Jan 29, 2026 |
99Now | CVE-2022-22947Weaponized | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Critical10.0 | KEV | 98.3% | Mar 3, 2022 |
99Now | CVE-2019-7609Weaponized | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Critical10.0 | KEV | 95.3% | Mar 25, 2019 |
98Now | CVE-2023-25717Weaponized | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLoginruckuswireless · ruckus wireless admin · CWE-94 | Critical9.8 | KEV | 98.1% | Feb 13, 2023 |
98Now | CVE-2018-1273Weaponized | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Critical9.8 | KEV | 97.0% | Apr 11, 2018 |
98Now | CVE-2023-33246Weaponized | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration functionapache · rocketmq · CWE-94 | Critical9.8 | KEV | 96.6% | May 24, 2023 |
98Now | CVE-2009-1151Weaponized | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to injephpmyadmin · phpmyadmin · CWE-94 | Critical9.8 | KEV | 96.6% | Mar 26, 2009 |
96Now | CVE-2024-56145Weaponized | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms · craft cms · CWE-94 | Critical9.3 | KEV | 97.4% | Dec 18, 2024 |
- CVE-2022-24816100Now
Improper Control of Generation of Code in jai-ext
CriticalCVSS 10.0KEVWeaponizedEPSS 100%geosolutionsgroup · jai-extApr 13, 2022
- CVE-2025-32432100Now
Craft CMS Allows Remote Code Execution
CriticalCVSS 10.0KEVWeaponizedEPSS 100%craftcms · craft cmsApr 25, 2025
- CVE-2021-22205100Now
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%gitlab · gitlabApr 23, 2021
- CVE-2017-984199Now
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da
CriticalCVSS 9.8KEVWeaponizedEPSS 100%phpunit project · phpunitJun 27, 2017
- CVE-2015-163599Now
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
CriticalCVSS 9.8KEVWeaponizedEPSS 100%microsoft · windows 7Apr 14, 2015
- CVE-2022-2295499Now
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · identity managerApr 11, 2022
- CVE-2022-2296399Now
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring cloud functionApr 1, 2022
- CVE-2023-351999Now
Unauthenticated remote code execution
CriticalCVSS 9.8KEVWeaponizedEPSS 100%citrix · netscaler application delivery controllerJul 19, 2023
- CVE-2019-1675999Now
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vbulletin · vbulletinSep 24, 2019
- CVE-2022-2296599Now
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
CriticalCVSS 9.8KEVWeaponizedEPSS 100%vmware · spring frameworkApr 1, 2022
- CVE-2017-749499Now
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
CriticalCVSS 9.8KEVWeaponizedEPSS 99%samba · sambaMay 30, 2017
- CVE-2014-628799Now
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attacke
CriticalCVSS 9.8KEVWeaponizedEPSS 99%rejetto · http file serverOct 7, 2014
- CVE-2018-760299Now
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
CriticalCVSS 9.8KEVWeaponizedEPSS 99%drupal · drupalJul 19, 2018
- CVE-2021-4452999Now
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager cloud services applianceDec 8, 2021
- CVE-2022-323699Now
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
CriticalCVSS 9.8KEVWeaponizedEPSS 99%sophos · firewallSep 23, 2022
- CVE-2008-425099Now
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a
CriticalCVSS 9.8KEVWeaponizedEPSS 99%microsoft · windows 2000Oct 23, 2008
- CVE-2026-128199Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2026-134099Now
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
CriticalCVSS 9.8KEVWeaponizedEPSS 99%ivanti · endpoint manager mobileJan 29, 2026
- CVE-2022-2294799Now
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
CriticalCVSS 10.0KEVWeaponizedEPSS 98%vmware · spring cloud gatewayMar 3, 2022
- CVE-2019-760999Now
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
CriticalCVSS 10.0KEVWeaponizedEPSS 95%elastic · kibanaMar 25, 2019
- CVE-2023-2571798Now
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin
CriticalCVSS 9.8KEVWeaponizedEPSS 98%ruckuswireless · ruckus wireless adminFeb 13, 2023
- CVE-2018-127398Now
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
CriticalCVSS 9.8KEVWeaponizedEPSS 97%broadcom · spring data commonsApr 11, 2018
- CVE-2023-3324698Now
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
CriticalCVSS 9.8KEVWeaponizedEPSS 97%apache · rocketmqMay 24, 2023
- CVE-2009-115198Now
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje
CriticalCVSS 9.8KEVWeaponizedEPSS 97%phpmyadmin · phpmyadminMar 26, 2009
- CVE-2024-5614596Now
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
CriticalCVSS 9.3KEVWeaponizedEPSS 97%craftcms · craft cmsDec 18, 2024