Skip to main content
Press slash or control plus K to focus the search. Use the arrow keys to navigate results and press enter to open a threat.

Threats Tagged 'cwe-94'

View all threats tagged with 'cwe-94'. Filter and sort to focus on specific types of threats.

Pro Console Lifetime

Stop chasing alerts. Route them.

Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.

Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)

View Plans & Pricing

API access activates after upgrading in Console -> Billing.

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now

Filter Threats

Narrow down the results by type, severity, or affected countries

Search threats by title, CVE ID, or description. Maximum 100 characters.
Active filters (1):Tag: cwe-94

Threats Tagged 'cwe-94'

Click on any threat for detailed analysis and mitigation recommendations

CVE-2026-17603: CWE-94 Improper Control of Generation of Code ('Code Injection') in Sonatype Nexus Repository 3CVE-2026-17603
0

Nexus Repository 3 contains a vulnerability where the DataStore configuration API does not sufficiently restrict which HikariCP connection-pool properties can be set. A user with the nx-datastores-update permission can set the connectionInitSql property to execute arbitrary SQL on every new database connection. When using the default H2 database backend, this flaw can lead to remote code execution as the Nexus process user.

Join the discussion
CVE-2026-19230: Cross Site Scripting in SourceCodester Photo Share WebsiteCVE-2026-19230
0

A cross-site scripting (XSS) vulnerability exists in SourceCodester Photo Share Website 1.0 within the Comment Input Box component, specifically in the /social/ajax.php?action=save_upload file. The vulnerability arises from improper handling of the 'content' argument, allowing remote attackers to inject malicious scripts. The vulnerability has a low severity score and requires user interaction to exploit.

Join the discussion
CVE-2026-17603: CWE-94 Improper Control of Generation of Code ('Code Injection') in Sonatype Nexus Repository 3CVE-2026-17603
0

Nexus Repository 3 did not sufficiently restrict which HikariCP connection-pool properties could be set through the DataStore configuration API. A user holding the nx-datastores-update permission could set the connectionInitSql property to execute arbitrary SQL against the configured database on every new connection. On the default H2 database backend, this could be leveraged to achieve remote code execution as the Nexus process user.

Join the discussion
CVE-2026-9196: CWE-94 Improper Control of Generation of Code ('Code Injection') in IBM Langflow OSSCVE-2026-9196
0

IBM Langflow OSS 1.0.0 through 1.10.3 could allow an authenticated attacker to execute unintended code during Agentic Assistant validation due to improper handling of LLM‑generated components. The application executes model‑generated Python code in the backend during validation prior to user approval, which may allow an attacker to trigger side effects such as outbound network access, file system interaction, or data exfiltration with the privileges of the Langflow backend process.

Join the discussion
CVE-2026-19060: Code Injection in FoundationAgents MetaGPTCVE-2026-19060
0

A vulnerability was identified in FoundationAgents MetaGPT up to 0.8.2. This impacts an unknown function. Such manipulation leads to code injection. The attack needs to be performed locally. The exploit is publicly available and might be used. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2026-19110: Cross Site Scripting in DataGearCVE-2026-19110
0

A vulnerability was determined in DataGear up to 5.0.0. The impacted element is the function HtmlTplDashboardWidgetHtmlRenderer of the file HtmlTplDashboardWidgetHtmlRenderer.java of the component Chart Name Handler. This manipulation of the argument Title causes cross site scripting. It is possible to initiate the attack remotely. The exploit has been publicly disclosed and may be utilized. The vendor was contacted early about this disclosure but did not respond in any way.

Join the discussion
CVE-2026-50159: CWE-94: Improper Control of Generation of Code ('Code Injection') in mermaid-js mermaidCVE-2026-50159
0

Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.8 and 11.16.1, Mermaid is vulnerable to CSS injection via sibling combinator selectors generated from diagram-supplied class or id names. An attacker who can supply diagram text can inject arbitrary CSS into the rendered page, potentially altering the appearance or behavior of unrelated page elements. This issue is fixed in versions 10.9.8 and 11.16.1.

Join the discussion
CVE-2026-48054: CWE-94: Improper Control of Generation of Code ('Code Injection') in OpenZeppelin contracts-wizardCVE-2026-48054
0

OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri` (ERC1155) directly into TypeScript string literals at `zip-hardhat.ts:48` and `:50` without any JavaScript string escaping. No authentication is required: an attacker crafts a URL such as `https[:]//wizard[.]openzeppelin[.]com/#/erc20?name=");require("child_process").execSync("...");("` and shares it with a developer. When the victim downloads the resulting zip archive and runs `npx hardhat test`, the injected Node.js code executes with the developer's local OS privileges. Version 0.10.9 fixes the issue.

Join the discussion
CVE-2026-18968: Cross Site Scripting in ttttonyhe OBlogCVE-2026-18968
0

A cross-site scripting (XSS) vulnerability exists in the ttttonyhe OBlog software affecting the /tags.php file via manipulation of the 'day' argument. The vulnerability can be exploited remotely and requires user interaction. The product uses a rolling release system, so specific affected or fixed versions are not disclosed. The vendor has not responded to the disclosure. The CVSS score is 4.3, indicating a low severity issue.

Join the discussion
CVE-2026-66709: CWE-94 Improper Control of Generation of Code ('Code Injection') in WebAppick CTX FeedCVE-2026-66709
0

Shop manager Remote Code Execution (RCE) in CTX Feed <= 6.6.42 versions.

Join the discussion

Showing 1 to 10 of 117 results

Filters:Tag: cwe-94
Page 1 of 12
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses