CWE-94 - Code Injection - Cwe

Threat entity extracted from intelligence sources

Frequency
296
occurrences
First Seen
April 16, 2026
Last Seen
August 31, 2026

Related Threat Clusters

Recent Intelligence Reports

  • CVE-2026-82664 CVE Vulnerability Disclosures / 11h A security vulnerability has been detected in yaojingang GEOFlow up to 2.1.0. This affects an unknown part of the file app/Http/Controllers/Site/HomeController.php of the component JSON-LD Theme Handler. The manipulation of the argument Search leads to cross site scripting. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. Upgrading to version 2.1.1 is able to mitigate this issue. The ide — cve.report · August 31, 2026
  • ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ... — Forkast.News · August 31, 2026
  • ash_ai 6-CVE Cluster Exposes the Full Agent Stack in Elixir's First Coordinated AI ... — Tech.Yahoo · August 31, 2026
  • CVE-2026-82244 - OSV — Osv.Dev · August 30, 2026
  • CVE-2026-82244: Budibase before 3.41.3 Remote Code Execution via Plugin eval() [CRITICAL] CVSS 9.4 Exploit Intelligence - Recent CVEs / 1d Budibase versions before 3.41.3 contain a remote code execution vulnerability in plugin handling that allows authenticated admin users to execute arbitrary code by uploading a malicious plugin tarball. The server calls eval() on plugin JavaScript files without sandboxing in the main Node.js process, enabling attackers to exfiltrate environment variables and c — exploit-intel.com · August 29, 2026
  • CVE-2026-82244 - Exploits & Severity — Feedly · August 29, 2026
  • ServiceNow Patches Max-Severity AI Platform Flaws; Urgent Enterprise Action Needed — Techgig · August 29, 2026
  • ServiceNow patches three maximum severity flaws that could put enterprise data at risk — Csoonline · August 28, 2026

CVSS v3.1 Breakdown