Threats Tagged 'cwe-94'
View all threats tagged with 'cwe-94'. Filter and sort to focus on specific types of threats.
Stop chasing alerts. Route them.
Start free, then upgrade once to turn Radar into an automated delivery engine for your security stack.
Custom feeds / Automations: email, Slack, webhooks, SIEM/MISP / API access (baseline limits)
API access activates after upgrading in Console -> Billing.
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.
Filter Threats
Narrow down the results by type, severity, or affected countries
Threats Tagged 'cwe-94'
Click on any threat for detailed analysis and mitigation recommendations
CVE-2026-41523: CWE-94: Improper Control of Generation of Code ('Code Injection') in vllm-project vllmCVE-2026-41523 0 vLLM versions prior to 0.22.0 contain a code injection vulnerability due to an assert-based security check bypass when running in Python optimized mode. This allows unauthenticated attackers to execute arbitrary code by publishing a malicious HuggingFace model. The issue is fixed in version 0.22.0. Join the discussion | CVE Database V5 | 06/22/2026, 22:18:14 UTC Added: 06/22/2026, 22:39:45 UTC |
CVE-2026-55388: CWE-94: Improper Control of Generation of Code ('Code Injection') in piscinajs piscinaCVE-2026-55388 0 CVE-2026-55388 is a high-severity code injection vulnerability in the piscina Node.js worker pool library. Versions prior to 4.9.3 and between 4.9.3 and before 5.2.0 are affected. The vulnerability arises because the constructor and run() methods read the filename option via plain member access, which falls through the prototype chain if the caller's options object lacks an own filename property. If Object.prototype.filename is polluted, an attacker can cause arbitrary .mjs code to run in a worker thread. This issue is fixed in versions 4.9.3, 5.2.0, and later. Join the discussion | CVE Database V5 | 06/22/2026, 16:50:40 UTC Added: 06/22/2026, 17:39:41 UTC |
CVE-2026-54271: CWE-94: Improper Control of Generation of Code ('Code Injection') in protobufjs protobufjs-cliCVE-2026-54271 0 CVE-2026-54271 is a high-severity code injection vulnerability in protobufjs-cli, a command line add-on for protobuf.js. Versions prior to 1.3.2 and 2.5.0 contain an incomplete fix for unsafe name handling in static code generation, allowing crafted JSON descriptor input to produce unsafe JavaScript references. This vulnerability does not affect the common case of parsing schemas from .proto files. An attacker able to influence pre-parsed JSON descriptors used in static code generation could inject attacker-controlled code that executes when the generated JavaScript file is run or imported. The issue is a bypass of a previous vulnerability CVE-2026-44295 and is fixed in versions 1.3.2 and 2.5.0. Join the discussion | CVE Database V5 | 06/22/2026, 16:16:05 UTC Added: 06/22/2026, 17:39:39 UTC |
CVE-2026-10789: CWE-94 Improper Control of Generation of Code ('Code Injection') in Autodesk FusionCVE-2026-10789 0 A maliciously crafted webpage, when visited by a user with Autodesk Fusion Desktop running and the MCP extension enabled, can trigger a vulnerability in the MCP extension that could allow arbitrary code execution. A successful exploit may allow code to execute with the privileges of the current user. Join the discussion | CVE Database V5 | 06/22/2026, 17:15:25 UTC Added: 06/22/2026, 17:39:38 UTC |
CVE-2026-9072: CWE-94 Improper Control of Generation of Code ('Code Injection')CVE-2026-9072 0 IBM i 7.6, 7.5, 7.4, and 7.3, IBM WebSphere Application Server, and IBM WebSphere Application Server Liberty - when using Intelligent Management with the WebSphere WebServer Plug-in component - are vulnerable to remote code execution and denial of service. This vulnerability can be exploited when an attacker impersonates backend servers and sends crafted responses to the plug-in. Join the discussion | CVE Database V5 | 06/22/2026, 14:21:35 UTC Added: 06/22/2026, 15:39:23 UTC |
CVE-2026-8858: CWE-94 Improper Control of Generation of Code ('Code Injection')CVE-2026-8858 0 IBM i versions 7.3.0, 7.4.0, 7.5.0, and 7.6.0, along with IBM WebSphere Application Server and Liberty, have a vulnerability in the WebSphere Web Server Plug-in component. This flaw allows remote code execution and denial of service when an attacker impersonates the application server and sends crafted responses to the plug-in. The vulnerability is classified as CWE-94, indicating improper control of code generation (code injection). It has a high severity with a CVSS score of 7.5. Join the discussion | CVE Database V5 | 06/22/2026, 14:16:39 UTC Added: 06/22/2026, 15:39:22 UTC |
CVE-2026-10561: CWE-94 Improper Control of Generation of Code ('Code Injection') in IBM Langflow OSSCVE-2026-10561 0 IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allows an unauthenticated attacker to execute arbitrary code on the host system, resulting in complete compromise Join the discussion | CVE Database V5 | 06/22/2026, 13:22:07 UTC Added: 06/22/2026, 13:54:17 UTC |
CVE-2026-5366: CWE-94 Improper Control of Generation of Code in prefecthq prefecthq/prefectCVE-2026-5366 0 Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to git commands, lacks validation and does not include a `--` separator to distinguish user input from git flags. This allows attackers to inject arbitrary git flags, such as `--upload-pack`, enabling execution of external programs. Additionally, the `directories` parameter can be exploited to inject git flags during sparse-checkout operations. These vulnerabilities allow any user with deployment creation permissions to execute arbitrary commands on worker machines, compromising shared work pools in multi-tenant environments. Join the discussion | CVE Database V5 | 06/20/2026, 16:43:37 UTC Added: 06/20/2026, 17:09:43 UTC |
CVE-2026-54816: CWE-94 Improper Control of Generation of Code ('Code Injection') in Monetizemore Advanced AdsCVE-2026-54816 0 Improper Control of Generation of Code ('Code Injection') vulnerability in Monetizemore Advanced Ads allows Remote Code Inclusion. This issue affects Advanced Ads: from n/a through 2.0.21. Join the discussion | CVE Database V5 | 06/17/2026, 13:37:37 UTC Added: 06/17/2026, 14:01:13 UTC |
CVE-2026-40783: CWE-94 Improper Control of Generation of Code ('Code Injection') in Creative Themes Blocksy Companion ProCVE-2026-40783 0 Contributor Remote Code Execution (RCE) in Blocksy Companion Pro <= 2.1.37 versions. Join the discussion | CVE Database V5 | 06/17/2026, 09:51:10 UTC Added: 06/17/2026, 11:09:00 UTC |
Showing 1 to 10 of 63 results