← Back to feed Search feed

CWE-94 Code Injection vulnerabilities

88 CVEs — updated 2026-09-18 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-53710MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_saCRITICAL10.056%ileNVD2026-09-15
CVE-2026-62104Unauthenticated Remote Code Execution (RCE) in Migratico Lite <= 2.6.8 versions.CRITICAL10.047%ileNVD2026-09-17
CVE-2026-92937vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GCRITICAL10.055%ileNVD2026-09-17
CVE-2026-93603vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridgeCRITICAL10.0NVD2026-09-18
CVE-2026-78159The The Events Calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and includingCRITICAL9.854%ileNVD2026-09-12
CVE-2026-57131PraisonAI is a multi-agent teams system. Prior to 4.6.58, praisonai.jobs.server.create_app mounts praisonai.jobs.router.CRITICAL9.860%ileNVD2026-09-14
CVE-2026-62379Open Access Management (OpenAM) is an access management solution. Prior to 16.1.2, the pre-authentication /authservice PCRITICAL9.850%ileNVD2026-09-15
CVE-2026-57141PraisonAI is a multi-agent teams system. Prior to 1.7.2, the codeMode tool in src/praisonai-ts/src/tools/builtins/code-mCRITICAL9.843%ileNVD2026-09-15
CVE-2026-90999Sentry Seer is vulnerable to a multi-stage trust-boundary violation that allows unauthenticated attacker-controlled teleCRITICAL9.813%ileNVD2026-09-16
CVE-2026-51990An issue in Sogou Sogou Input Method < 16.3.0.3498 (fixed in 16.3.0.3498) allows a remote attacker to execute arbitrary CRITICAL9.861%ileNVD2026-09-16
CVE-2026-45140Chamilo LMS is an open-source learning management system. Prior to 2.0.1, Chamilo LMS allows an unauthenticated remote aCRITICAL9.861%ileNVD2026-09-17
CVE-2026-75031In the interchange/interchange project, a critical remote code execution (RCE) vulnerability was found in the “quick quCRITICAL9.8NVD2026-09-18
CVE-2026-82340IBM Guardium Data Protection 12.2 is vulnerable to unauthenticated insecure deserialization and attacker-controlled reflCRITICAL9.8NVD2026-09-18
CVE-2026-73453An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary cCRITICAL9.553%ileNVD2026-09-16
CVE-2026-85192Joomla Extension - regularlabs.com - Authenticated, privileged remote code execution in Conditional Content extension foCRITICAL9.441%ileNVD2026-09-14
CVE-2026-89082HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, CRITICAL9.342%ileNVD2026-09-16
CVE-2026-89083HP has identified potential security vulnerabilities in the HP Advance software that may enable elevation of privilege, CRITICAL9.342%ileNVD2026-09-16
CVE-2026-54237Wavelog is web-based amateur radio logging software. From 1.8 until 2.4.2, Wavelog exposes /install/ajax.php and /instalCRITICAL9.345%ileNVD2026-09-17
CVE-2026-73456Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI)CRITICAL9.253%ileNVD2026-09-16
CVE-2026-84738The AF Companion WordPress plugin before 2.2.0 does not validate the type of files uploaded through one of its import fCRITICAL9.113%ileNVD2026-09-18
CVE-2026-88795The wpShopGermany IT-RECHT KANZLEI WordPress plugin before 2.4 does not generate its API authentication token securely, CRITICAL9.040%ileNVD2026-09-17
CVE-2026-47252Anyquery is an SQL query engine built on top of SQLite. Prior to 0.4.5, authenticated users with INSERT or UPDATE accessCRITICAL9.038%ileNVD2026-09-17
CVE-2026-16428IBM DataStage on Cloud Pak for Data 5.4.0.0 IBM DataStage could allow a remote authenticated attacker to execute arbitraHIGH8.844%ileNVD2026-09-14
CVE-2026-19780Koha Eval Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbiHIGH8.860%ileNVD2026-09-15
CVE-2026-92125Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier does not reject the @GroovyASTTransformationClass annotHIGH8.843%ileNVD2026-09-16
CVE-2026-84858ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox BypHIGH8.851%ileNVD2026-09-16
CVE-2026-15815Grafana OSS and Grafana Enterprise did not safely resolve symbolic links when extracting plugin archives. A crafted plugHIGH8.857%ileNVD2026-09-17
CVE-2026-54612Vvveb is a powerful and easy to use CMS with page builder to build websites, blogs or ecommerce stores. From 1.0.0 untilHIGH8.841%ileNVD2026-09-17
CVE-2026-33625LMDeploy is a toolkit for compressing, deploying, and serving large language models. Versions 012.1 through 0.12.2 contaHIGH8.8NVD2026-09-18
CVE-2026-93759Mongoid does not neutralize a string-typed query criterion supplied to its query builder, and instead passes it to the dHIGH8.8NVD2026-09-18
CVE-2026-14380DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ProfileHIGH8.843%ileMicrosoft2026-07-14
CVE-2026-68489Static Code Injection in Plesk extensions "Ruby" before 1.6.6 and "Node.js Toolkit" before 2.5.0 allows remote authenticHIGH8.730%ileNVD2026-09-14
CVE-2026-73464On affected platforms running Arista EOS with gRPC Network Management Interface (gNMI) enabled, a specially crafted requHIGH8.741%ileNVD2026-09-16
CVE-2026-92593Craft CMS versions 5.10.0 through 5.10.12 contain an incomplete fix for CVE-2026-55794: the Controller::getPostedRedirecHIGH8.736%ileNVD2026-09-16
CVE-2026-73166Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in theHIGH8.651%ileNVD2026-09-16
CVE-2026-73170Nozomi Networks Labs identified a CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability in theHIGH8.643%ileNVD2026-09-16
CVE-2026-90553vLLM before 0.28.0 contains a remote code execution vulnerability in the LlavaOnevision2 processor loader that ignores tHIGH8.511%ileNVD2026-09-12
CVE-2026-91719Code injection in XML in Google Chrome prior to 153.0.8010.47 allowed a remote attacker to bypass web origin policy via HIGH8.118%ileNVD2026-09-15
CVE-2026-83408Vulnerability in the Oracle GraalVM for JDK, Oracle GraalVM product of Oracle Java SE (component: Compiler). The suppoHIGH8.125%ileNVD2026-09-15
CVE-2026-92127Jenkins Script Security Plugin 1415.v9a_f9b_3a_c253d and earlier automatically approves the classpath entries in an itemHIGH8.040%ileNVD2026-09-16
CVE-2026-63325Redocly CLI makes OpenAPI validation, linting, and documentation workflows easier. Prior to version 2.33.0 of @redocly/rHIGH7.811%ileNVD2026-09-16
CVE-2026-86320A flaw was found in flatpak-builder where Git hooks are not disabled when applying patch sources with use-git-am: true. HIGH7.813%ileNVD2026-09-17
CVE-2026-55895Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameHIGH7.85%ileMicrosoft2026-06-09
CVE-2026-92784@refinedev/inferencer through 7.0.0 fails to escape API field names when interpolating them into generated JSX source coHIGH7.738%ileNVD2026-09-16
CVE-2026-76550The WP Import Export Lite WordPress plugin before 3.9.34 does not validate a user-supplied output path when writing expoHIGH7.254%ileNVD2026-09-16
CVE-2026-76551The WP Import Export Lite WordPress plugin before 3.9.33 does not restrict which PHP function may be applied to exportedHIGH7.254%ileNVD2026-09-16
CVE-2026-61552Icinga 2 is an open source monitoring system. From 2.4 until 2.14.9, 2.15.4, and 2.16.2, the /v1/objects API writes attaHIGH7.2NVD2026-09-18
CVE-2026-77147Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Syncope. An administrator with adequaMEDIUM6.521%ileNVD2026-09-14
CVE-2026-77281Caddy is an extensible server platform that uses TLS by default. In version 2.11.3 and earlier, three configuration-depeMEDIUM6.530%ileNVD2026-09-17
CVE-2026-90527A vulnerability was detected in quequnlong shiyi-blog up to 1.2.1. Affected is an unknown function of the file blog-admiMEDIUM5.320%ileNVD2026-09-13
CVE-2026-90571A vulnerability was found in Exrick xmall up to 19e7917d5ed3bd2a2421a3a246ad494c133ba94c. Impacted is an unknown functioMEDIUM5.320%ileNVD2026-09-13
CVE-2026-90583A security flaw has been discovered in kagisearch smallweb up to 0ecb9c48edbf98dc7e934b54fbac43869e64b4cf. The affected MEDIUM5.321%ileNVD2026-09-13
CVE-2026-90848A weakness has been identified in Governikus AusweisApp up to 2.5.4. Affected is an unknown function of the component StMEDIUM5.318%ileNVD2026-09-15
CVE-2026-90528A flaw has been found in TDuckApp tduck-platform up to 5.3. Affected by this vulnerability is an unknown functionality oMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90529A vulnerability has been found in DataEase up to 2.10.25/2.10.26. Affected by this issue is the function buildTooltip ofMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90563A vulnerability was determined in maliangnansheng bbs-springboot 3.0.0. This affects the function utils.toToc of the filMEDIUM5.111%ileNVD2026-09-13
CVE-2026-90564A vulnerability was identified in quequnlong shiyi-blog 1.0.0-1.2.1. This impacts the function SysChatMsgMapper.getChatMMEDIUM5.110%ileNVD2026-09-13
CVE-2026-90567A security vulnerability has been detected in quequnlong shiyi-blog up to 1.2.1. Affected by this issue is the function MEDIUM5.126%ileNVD2026-09-13
CVE-2026-90568A vulnerability was detected in moxi624 Mogu Blog v2 up to 5.2. This affects the function BlogSortServiceImpl.addBlogSorMEDIUM5.124%ileNVD2026-09-13
CVE-2026-90602A vulnerability was determined in Anil-matcha Open-Generative-AI up to 1.0.11/2.0.0. Affected by this vulnerability is tMEDIUM5.127%ileNVD2026-09-13
CVE-2026-92214A flaw has been found in a2ui-project a2ui up to 0.10.7. Affected is an unknown function of the file samples/community/cMEDIUM5.118%ileNVD2026-09-16
CVE-2026-93505A vulnerability was found in SveltyCMS 0.0.6. This vulnerability affects unknown code of the file src/utils/media/media-MEDIUM5.1NVD2026-09-18
CVE-2026-90569A flaw has been found in linlinjava litemall 1.5.0/1.6.0/1.7.0/1.8.0. This vulnerability affects the function AdminTopicMEDIUM4.828%ileNVD2026-09-13
CVE-2026-90570A vulnerability has been found in linlinjava litemall 1.4.0/1.5.0/1.6.0/1.7.0/1.8.0. This issue affects the function AdmMEDIUM4.828%ileNVD2026-09-13
CVE-2026-57583OpenZeppelin Contracts Wizard is a web application to interactively build a contract out of components from OpenZeppelinLOW3.33%ileNVD2026-09-14
CVE-2026-90488A vulnerability was determined in Xuxueli xxl-job up to 3.4.2. This affects the function GroovyClassLoader.parseClass ofLOW2.114%ileNVD2026-09-13
CVE-2026-90491A weakness has been identified in sanjevirau gsubs up to 1.0.3. Impacted is the function showQuerySuccessPage of the filLOW2.116%ileNVD2026-09-13
CVE-2026-90581A vulnerability was determined in cym1102 nginxWebUI up to 4.4.2. This issue affects the function MainController.autoUpdLOW2.116%ileNVD2026-09-13
CVE-2026-90615A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknLOW2.120%ileNVD2026-09-14
CVE-2026-90795A vulnerability was determined in itsourcecode Loan Management System 1.0. The impacted element is an unknown function oLOW2.138%ileNVD2026-09-14
CVE-2026-91854A vulnerability was identified in code-projects Record Management System 1.0. Affected is an unknown function of the filLOW2.120%ileNVD2026-09-15
CVE-2026-90489A vulnerability was identified in Xuxueli xxl-job up to 3.5.0. This vulnerability affects unknown code of the file /jobiLOW2.09%ileNVD2026-09-13
CVE-2026-90497A vulnerability was determined in Fengoffice Feng Office up to 3.11.13.11. Affected by this vulnerability is the functioLOW2.09%ileNVD2026-09-13
CVE-2026-90502A vulnerability was detected in stilleshan ServerStatus 1.0/2.0. Impacted is an unknown function of the file server/src/LOW2.09%ileNVD2026-09-13
CVE-2026-90604A security flaw has been discovered in Totolink A3002MU Hh-B20211125.1046. This affects an unknown part of the componentLOW2.010%ileNVD2026-09-14
CVE-2026-90694A vulnerability has been found in SourceCodester Inventory Management System 1.0. Affected is an unknown function of theLOW2.010%ileNVD2026-09-14
CVE-2026-90695A vulnerability was found in SourceCodester Inventory Management System 1.0. Affected by this vulnerability is an unknowLOW2.010%ileNVD2026-09-14
CVE-2026-90696A vulnerability was determined in SourceCodester Inventory Management System 1.0. Affected by this issue is some unknownLOW2.010%ileNVD2026-09-14
CVE-2026-90709A security vulnerability has been detected in Yot CMS up to 3.3.1. Affected by this issue is the function eval of the fiLOW2.015%ileNVD2026-09-14
CVE-2026-90835A flaw has been found in michaelliao itranswarp up to 2.19. The impacted element is the function Markdown.toHtml of the LOW2.010%ileNVD2026-09-14
CVE-2026-90845A flaw has been found in PHPGurukul Daily Expense Tracker System 1.1. This issue affects some unknown processing of the LOW2.010%ileNVD2026-09-15
CVE-2026-92381A weakness has been identified in PbootCMS up to 3.2.22. This affects the function decode_string of the file apps/admin/LOW2.024%ileNVD2026-09-16
CVE-2026-92418A vulnerability was determined in ChangeWeDer crm up to c07bd4c97141521af6475034bc58523beed51bbd. This vulnerability affLOW2.026%ileNVD2026-09-16
CVE-2026-90850A vulnerability was detected in PHPGurukul Hostel Management System 3.0. Affected by this issue is some unknown functionLOW1.912%ileNVD2026-09-15
CVE-2026-92385A vulnerability has been found in SourceCodester Online Food Ordering System 1.0. The affected element is an unknown funLOW1.929%ileNVD2026-09-16
CVE-2026-79249Chromium: CVE-2026-79249 Code injection in BisectionUNKNOWN14%ileMicrosoft2026-08-11
CVE-2026-47162Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory nameUNKNOWN18%ileMicrosoft2026-06-09
CVE-2026-47167Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regexUNKNOWN3%ileMicrosoft2026-06-09