← Back to feed Search feed

CWE-94 Code Injection vulnerabilities

51 CVEs — updated 2026-08-04 · vulnfeed

CVE / IDTitleSeverityCVSSEPSSSourceDate
CVE-2026-64633A vulnerability allowing remote unauthenticated code execution on the agent host.CRITICAL10.0NVD2026-08-04
CVE-2026-13435IBM Langflow OSS 1.0.0 through 1.10.1 contains an improper input validation vulnerability in the PythonREPL sandbox implCRITICAL9.921%ileNVD2026-07-30
CVE-2026-12946IBM Langflow OSS 1.0.0 through 1.10.0 could allow a remote attacker to inject arbitrary code on the system, due to the iCRITICAL9.927%ileNVD2026-07-30
CVE-2026-13423The Streamit WordPress theme through 4.5.0 does not perform any authorization or nonce verification on one of its unauthCRITICAL9.842%ileNVD2026-07-29
CVE-2026-14900The Cost Calculator Builder PRO plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and iCRITICAL9.849%ileNVD2026-07-29
CVE-2026-17561Improper Control of Generation of Code ('Code Injection') vulnerability in Innotim Software, Telecommunications and ConsCRITICAL9.824%ileNVD2026-07-31
CVE-2026-51785An issue in Hugo Leisink Hiawatha v.12.1 and before allows a remote attacker to execute arbitrary code via a crafted reqCRITICAL9.864%ileNVD2026-07-31
CVE-2024-3660Arbitrary code injection vulnerability in Keras framework < 2.13CRITICAL9.876%ileMicrosoft2024-04-09
CVE-2026-69254Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, executeJavaScriCRITICAL9.4NVD2026-08-04
CVE-2026-69256Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent noCRITICAL9.4NVD2026-08-04
CVE-2026-69259Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the SQLite RecoCRITICAL9.4NVD2026-08-04
CVE-2026-68770sentence-transformers contains a security control bypass vulnerability that allows attackers to achieve arbitrary code eCRITICAL9.341%ileNVD2026-07-31
CVE-2026-67340ArcadeDB before 26.7.2 (arcadedb-engine) allows trigger scripts to look up host classes in java.lang.* (via Java.type) bCRITICAL9.342%ileNVD2026-08-01
CVE-2026-18667A vulnerability in Tenable Sensor Proxy allows a remote attacker to execute code with elevated privileges by inducing anCRITICAL9.329%ileNVD2026-08-03
CVE-2026-69255Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the CSVAgent inCRITICAL9.2NVD2026-08-04
CVE-2026-14602The Remote API WordPress plugin through 0.2 does not authenticate a request before deserializing user-supplied input, alCRITICAL9.042%ileNVD2026-07-30
CVE-2026-69251Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, Flowise record CRITICAL9.0NVD2026-08-04
CVE-2026-69253Flowise is a drag-and-drop user interface for building customized large language model (LLM) flows. Prior to version 3.1CRITICAL9.0NVD2026-08-04
CVE-2026-11393AgentCore CLI Bedrock Agent Import Vulnerable to Code Injection via Improper Triple-Quote EscapingHIGH9.025%ileGitHub2026-07-29
CVE-2026-54653datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH8.828%ileNVD2026-07-28
CVE-2026-17922Inappropriate implementation in Enterprise in Google Chrome prior to 151.0.7922.72 allowed a remote attacker to execute HIGH8.833%ileNVD2026-07-30
CVE-2026-14380DBI versions before 1.650 for Perl are vulnerable to code injection via caller-influenced ProfileHIGH8.839%ileMicrosoft2026-07-14
CVE-2026-16881A code injection vulnerability exists in the LINE Android app prior to version 26.7.2. The profile rendering componentHIGH8.718%ileNVD2026-08-04
CVE-2026-69100LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability iHIGH8.7NVD2026-08-04
CVE-2026-69088Grav CMS versions 2.0.7 through 2.0.10 fail to validate fully-qualified static method calls (Class::method) in blueprintHIGH8.614%ileNVD2026-08-03
CVE-2026-61523WebsiteBaker CMS before 2.13.10 contains a code injection vulnerability in the Droplets editor that allows authenticatedHIGH8.647%ileNVD2026-08-03
CVE-2026-58074A vulnerability allowing a high-privileged user to execute arbitrary code on the server.HIGH8.6NVD2026-08-04
CVE-2026-66065Ouroboros is a local-first runtime for AI coding agents that records their actions and applies user-defined policies to HIGH8.422%ileNVD2026-08-03
CVE-2026-54661swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, templatHIGH8.319%ileNVD2026-07-29
CVE-2026-54662swagger-typescript-api generates API clients for Fetch or Axios from OpenAPI specifications. Prior to 13.12.2, src/code-HIGH8.319%ileNVD2026-07-29
CVE-2026-54664swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schHIGH8.319%ileNVD2026-07-29
CVE-2026-54666swagger-typescript-api generates API clients for Fetch or Axios from an OpenAPI Specification. Prior to 13.12.2, src/schHIGH8.321%ileNVD2026-07-29
CVE-2026-53510Savon is a Ruby SOAP client. From 0.9.8 until 2.17.2, Savon::Model .all_operations interpolates attacker-controlled WSDLHIGH8.132%ileNVD2026-07-31
CVE-2026-16144The Kali Forms — Contact Form & Drag-and-Drop Builder plugin for WordPress is vulnerable to Remote Code Execution in allHIGH8.149%ileNVD2026-08-01
CVE-2026-18107A flaw was found in CRIU's handling of restartable sequences (rseq) during checkpoint/restore. A malicious process insidHIGH7.82%ileNVD2026-07-28
CVE-2026-54621datamodel-code-generator generates Python data models from schema definitions. Prior to 0.60.1, GraphQL Union descriptioHIGH7.84%ileNVD2026-07-28
CVE-2026-54654datamodel-code-generator generates Python data models from schema definitions. From 0.14.1 until 0.60.2, the --extra-temHIGH7.84%ileNVD2026-07-28
CVE-2026-54655datamodel-code-generator generates Python data models from schema definitions. From 0.51.0 until 0.60.2, x-python-type vHIGH7.84%ileNVD2026-07-28
CVE-2026-54656datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.85%ileNVD2026-07-28
CVE-2026-55895Vim: Vimscript Code Injection in netrw NetrwLocalRmFile() via crafted filenameHIGH7.85%ileMicrosoft2026-06-09
CVE-2026-66745Artica Proxy before 4.50.000000 Service Pack 7 (fixed in hotfix 20260724-02) contains a session fixation vulnerability tHIGH7.524%ileNVD2026-07-28
CVE-2026-55415datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON SchHIGH7.520%ileNVD2026-07-28
CVE-2026-61536Banks generates meaningful LLM prompts using a simple template language. In versions prior to 2.4.3, banks parses Tool JHIGH7.522%ileNVD2026-07-30
CVE-2026-13392The ElementsKit Elementor Addons WordPress plugin before 3.10.01 does not prevent a custom-widget definition saved by aHIGH7.230%ileNVD2026-07-31
CVE-2026-9198IBM Langflow Code Injection VulnerabilityHIGH78%ileCISA-KEV2026-08-04
CVE-2026-18245Improper control of code generation in Amazon @aws-amplify/codegen-ui-react before 2.20.6 might allow a remote authenticMEDIUM6.441%ileNVD2026-07-30
CVE-2026-65804Improper control of generation of code ('code injection') in Microsoft Edge (Chromium-based) allows an unauthorized attaMEDIUM6.135%ileNVD2026-08-04
CVE-2026-18770A vulnerability has been found in vibesurf-ai VibeSurf up to cd6e519d507cdd4d63061300bf60fb176e1f57e0. Impacted is an unMEDIUM5.5NVD2026-08-04
CVE-2026-18682A security flaw has been discovered in OpenAkita up to 1.27.12. This vulnerability affects unknown code of the file /apiLOW1.316%ileNVD2026-08-03
CVE-2026-47162Vim: Vimscript Code Injection in netrw NetrwBookHistSave() via crafted directory nameUNKNOWN12%ileMicrosoft2026-06-09
CVE-2026-47167Vim: Vimscript Code Injection in cucumber filetype plugin via crafted step-definition regexUNKNOWN3%ileMicrosoft2026-06-09