CWE-94: Code Injection — known CVE vulnerabilities
CVEs classified under CWE-94 (Code Injection), ordered by CVSS severity, with EPSS exploit prediction and CISA KEV status.
CVEs (50)
CVE-2026-105857 — CVSS 10.0 (critical): Payload is a free and open source headless content management system. In @payloadcms/plugin-form-builder versions before 3.90.0 and canary…
CVE-2026-55107 — CVSS 10.0 (critical): Kobako is a Ruby gem that embeds a Wasm-isolated mruby interpreter inside applications, allowing execution of untrusted Ruby scripts…
CVE-2026-102425 — CVSS 10.0 (critical): Joomla Extension - balbooa.com - Unauthenticated RCE via field shortcode injection in Balbooa Forms < 2.4.3.4 - Balbooa Forms supports…
CVE-2026-89275 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-84412 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-75721 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-75703 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-75699 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-73369 — CVSS 10.0 (critical): Adobe Campaign Classic (ACC) is affected by an Improper Control of Generation of Code ('Code Injection') vulnerability that could result in…
CVE-2026-93603 — CVSS 10.0 (critical): vm2 through 3.12.0 (fixed in 3.12.1) does not correctly handle a nullish `this` receiver in the apply trap of its bridge (lib/bridge.js)…
CVE-2026-92937 — CVSS 10.0 (critical): vm2 3.11.6 is vulnerable to a sandbox escape leading to remote code execution in the host Node.js process. The fix for GHSA-m283-3h24-438v…
CVE-2026-73456 — CVSS 10.0 (critical): Under certain circumstances on affected platforms running Arista EOS with gRPC Network Packet Sampling Interface (gNPSI) enabled, an…
CVE-2026-73453 — CVSS 10.0 (critical): An unauthenticated P4Runtime (Programming Protocol-Independent Packet Processors Runtime) client can achieve arbitrary code execution under…
CVE-2026-53710 — CVSS 10.0 (critical): MCP Context Forge is an AI gateway, registry, and proxy for MCP, A2A, REST, and gRPC APIs. Prior to 1.0.2, the python_sandbox_server in…
CVE-2026-14560 — CVSS 10.0 (critical): The teddy-bear-customize-addon WordPress plugin through 1.0.5 does not properly validate uploaded files, relying on a client-supplied…
CVE-2026-6876: ServiceNow has remediated a sandbox escape security issue that was identified in the ServiceNow AI Platform. This security issue could…
CVE-2026-18885: ServiceNow has remediated a code injection vulnerability that was identified in the ServiceNow AI platform. This vulnerability could enable…
CVE-2026-81096 — CVSS 10.0 (critical): ToolUniverse ran caller-supplied Python inside a sandbox that could be escaped, on a server that required no authentication. The executor…
CVE-2026-76605: Joomla Extension - fabrikar.com - Remote code execution via image element in Fabrik < 4.7.2.
CVE-2026-76604: Joomla Extension - fabrikar.com - Unauthenticated remote code execution via PHP form element in Fabrik < 4.7.2 - The PHP form element is…
CVE-2026-67364: Joomla Extension - balbooa.com - Pre-auth PHP Code Injection in Balbooa Forms < 2.4.3.2 - The form's optional custom-PHP post-submission…
CVE-2026-73299 — CVSS 10.0 (critical): Prompty is a markdown file format (.prompty) for LLM prompts. Prior to 0.1.5 and 2.0.0-beta.5, the TypeScript Nunjucks renderer evaluated…
CVE-2026-67282: Joomla Extension - fabrikar.com - Unauthenticated remote code execution in Fabrik < 4.6.8 - An unauthenticated attacker could execute…
CVE-2026-45618 — CVSS 10.0 (critical): LiquidJS is a Shopify/GitHub Pages compatible template engine. Prior to version 10.26.0, it is possible to execute arbitrary code with…
CVE-2026-58231 — CVSS 10.0 (critical): SAP Commerce Cloud allows an unauthenticated attacker to abuse a default authentication client and submit specially crafted input to…
CVE-2026-66915: Joomla Extension - fabrikar.com - Remote code execution in Fabrik < 4.7.2 - An unauthenticated attacker could execute arbitrary code by…
CVE-2026-64633: A vulnerability allowing remote unauthenticated code execution on the agent host.
CVE-2026-65880: Joomla Extension - balbooa.com - Unauthenticated remote code execution in Balbooa Forms < 2.4.3 - An insecure form processing logic allowed…
CVE-2025-71389 — CVSS 10.0 (critical): Cal.com (calcom/cal.diy) before 5.9.9 is vulnerable to unauthenticated remote code execution because it bundles a version of Next.js whose…
CVE-2026-44359 — CVSS 10.0 (critical): Meshtastic is an open source mesh networking solution. Prior to version 2.7.21.1370b23, the Meshtastic GitHub repository's main_matrix.yml…
CVE-2026-57811 — CVSS 10.0 (critical): Improper Control of Generation of Code ('Code Injection') vulnerability in Realtyna Realtyna Organic IDX plugin real-estate-listing-realtyna…
CVE-2026-61447 — CVSS 10.0 (critical): PraisonAI before 1.6.78 contains a remote code execution vulnerability in CodeAgent._execute_python() that executes LLM-generated Python…
CVE-2026-54769 — CVSS 10.0 (critical): Langroid is a framework for building large-language-model-powered applications. Versions prior to 0.65.2 are vulnerable to a critical…
CVE-2026-10134 — CVSS 10.0 (critical): IBM Langflow OSS 1.0.0 through 1.9.3 allows an attacker to read every secret available to the Langflow process, read and modify every flow…
CVE-2026-53576 — CVSS 10.0 (critical): Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API…
CVE-2026-10561 — CVSS 10.0 (critical): IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication…
CVE-2026-25470 — CVSS 10.0 (critical): Unauthenticated Remote Code Execution (RCE) in ACPT (Pro) - Custom Post Types Plugin for WordPress <= 2.0.47 versions.
CVE-2026-52704 — CVSS 10.0 (critical): Improper Control of Generation of Code ('Code Injection') vulnerability in Edgar Rojas WooCommerce PDF Invoice Builder allows Remote Code…
CVE-2026-45132 — CVSS 10.0 (critical): CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow…
CVE-2026-45131 — CVSS 10.0 (critical): CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml)…