VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 101 of 350
  • CVE-2023-0625HigSep 25, 2023
    risk 0.52cvss 8.0epss 0.01

    Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.

  • CVE-2023-0462HigSep 20, 2023
    risk 0.52cvss 8.0epss 0.01

    An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.

  • CVE-2023-38484HigSep 6, 2023
    risk 0.52cvss 8.0epss 0.00

    Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to gain access to and change underlying…

  • CVE-2023-38576HigAug 18, 2023
    risk 0.52cvss 8.0epss 0.00

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS commands on a certain management console.

  • CVE-2023-37565HigJul 13, 2023
    risk 0.52cvss 8.0epss 0.01

    Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1.03 and earlier, WRC-1167GEBK-S v1.03…

  • CVE-2022-47879HigMay 12, 2023
    risk 0.52cvss 7.5epss 0.06

    A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability affects installations running version…

  • CVE-2021-37774HigJan 19, 2023
    risk 0.52cvss 8.0epss 0.01

    An issue was discovered in function httpProcDataSrv in TL-WDR7660 2.0.30 that allows attackers to execute arbitrary code.

  • CVE-2022-34663HigJul 12, 2022
    risk 0.52cvss 8.0epss 0.01

    A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM M2200, RUGGEDCOM M2200F, RUGGEDCOM…

  • CVE-2022-21122CriJun 8, 2022
    risk 0.52cvss 9.0epss 0.03

    The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constructor.

  • CVE-2022-24915HigMar 10, 2022
    risk 0.52cvss 8.0epss 0.01

    The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section where the information is displayed. Injection can be done on…

  • CVE-2022-21686CriJan 26, 2022
    risk 0.52cvss 9.0epss 0.02

    PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1.7.8.3. There are no known workarounds.

  • CVE-2020-15150CriSep 1, 2020
    risk 0.52cvss 9.0epss 0.03

    There is a vulnerability in Paginator (Elixir/Hex package) which makes it susceptible to Remote Code Execution (RCE) attacks via input parameters to the paginate() function. This will potentially affect all current users of Paginator prior to version 1.0.0. The vulnerability has…

  • CVE-2019-7610CriMar 25, 2019
    risk 0.52cvss 9.0epss 0.04

    Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execute javascript code. This could possibly…

  • CVE-2026-67961HigAug 17, 2026
    risk 0.51cvss 7.8epss 0.00

    An issue in O2OA v.10.0.2 allows a local attacker to execute arbitrary code via the the sandbox mechanism of the Invoke script execution.

  • CVE-2026-13094HigAug 12, 2026
    risk 0.51cvss 7.8epss 0.00

    IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file.

  • CVE-2026-66150HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via SNMP.

  • CVE-2026-66149HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper Control of Generation of Code ('Code Injection') Vulnerability in the SonicWall Email Security appliance allows an authenticated attacker with access to the SonicWall Email Security restricted CLI can inject arbitrary OS commands that execute as root via netmask.

  • CVE-2026-70338HigAug 11, 2026
    risk 0.51cvss 7.8epss 0.00

    Improper control of generation of code ('code injection') in Microsoft PowerShell allows an unauthorized attacker to bypass a security feature locally.

  • CVE-2026-55522HigAug 5, 2026
    risk 0.51cvss 7.8epss 0.00

    PraisonAI is a multi-agent teams system. In versions 3.9.26 through 4.6.57 of praiseonai and 0.12.12 through 1.6.57 of praiseonaiagents, the workflow "include" feature is vulnerable to code execution. Workflow._execute_include() implicitly imports and runs an included recipe's…

  • CVE-2026-43945HigJul 21, 2026
    risk 0.51cvss epss 0.01

    FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. Versions 1.2.11 until 1.3.1 allow an unauthenticated remote attacker to achieve Full Remote Code Execution (RCE) as root. The exploit succeeds even when the platform is configured in its most secure state…