CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

Code injection vulnerabilities

command / template injection343 advisories90 exploitedlatest 2026-08-25

Code injection covers OS command injection, template injection and similar flaws where attacker input is executed as code by the application. These bugs are easy to weaponize — often a single crafted HTTP request — and are among the fastest classes to move from disclosure to in-the-wild exploitation.

Classification is assigned by the CSIRTS enrichment pipeline from the advisory text. The list below shows the latest advisories tagged code injection, newest first, across national CERTs, vendor PSIRTs and vulnerability databases — exploited marks CVEs in the CISA KEV catalog.

Latest code injection advisories

Other vulnerability classes

Remote code execution (2023)Privilege escalation (1548)Authentication bypass (1066)Denial of service (2105)Information disclosure (1543)Memory corruption (1308)Path traversal (235)Cross-site scripting (315)Unsafe deserialization (83)SQL injection (143)Server-side request forgery (109)
New code injection advisories, in your inbox. The daily briefing covers every advisory in this class the morning after it lands. Subscribe free — one email every morning after 06:00 UTC, one-click unsubscribe. Tracking specific products instead? Watch them from any product page and get alerted only when they ship a new advisory.