Skip to content
Noroxi

CWE-94 · 5,488 records

Improper Control of Generation of Code ('Code Injection')

CVEs in this class

5,488 records

  • Improper Control of Generation of Code in jai-ext

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    geosolutionsgroup · jai-extApr 13, 2022

  • Craft CMS Allows Remote Code Execution

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    craftcms · craft cmsApr 25, 2025

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    CriticalCVSS 10.0KEVWeaponizedEPSS 100%

    gitlab · gitlabApr 23, 2021

  • Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    phpunit project · phpunitJun 27, 2017

  • HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    microsoft · windows 7Apr 14, 2015

  • VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · identity managerApr 11, 2022

  • In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · spring cloud functionApr 1, 2022

  • Unauthenticated remote code execution

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    citrix · netscaler application delivery controllerJul 19, 2023

  • vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vbulletin · vbulletinSep 24, 2019

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    CriticalCVSS 9.8KEVWeaponizedEPSS 100%

    vmware · spring frameworkApr 1, 2022

  • Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    samba · sambaMay 30, 2017

  • The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attacke

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    rejetto · http file serverOct 7, 2014

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    drupal · drupalJul 19, 2018

  • A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager cloud services applianceDec 8, 2021

  • A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    sophos · firewallSep 23, 2022

  • The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    microsoft · windows 2000Oct 23, 2008

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager mobileJan 29, 2026

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    CriticalCVSS 9.8KEVWeaponizedEPSS 99%

    ivanti · endpoint manager mobileJan 29, 2026

  • In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat

    CriticalCVSS 10.0KEVWeaponizedEPSS 98%

    vmware · spring cloud gatewayMar 3, 2022

  • Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    CriticalCVSS 10.0KEVWeaponizedEPSS 95%

    elastic · kibanaMar 25, 2019

  • Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin

    CriticalCVSS 9.8KEVWeaponizedEPSS 98%

    ruckuswireless · ruckus wireless adminFeb 13, 2023

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    broadcom · spring data commonsApr 11, 2018

  • Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    apache · rocketmqMay 24, 2023

  • Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    CriticalCVSS 9.8KEVWeaponizedEPSS 97%

    phpmyadmin · phpmyadminMar 26, 2009

  • RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms

    CriticalCVSS 9.3KEVWeaponizedEPSS 97%

    craftcms · craft cmsDec 18, 2024

All vulnerability classes