VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 108 of 350
  • CVE-2023-0877HigFeb 17, 2023
    risk 0.51cvss 8.8epss 0.04

    Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.

  • CVE-2022-27537HigFeb 1, 2023
    risk 0.51cvss 7.8epss 0.00

    Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential…

  • CVE-2022-42268HigJan 13, 2023
    risk 0.51cvss 7.8epss 0.01

    Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a…

  • CVE-2022-44702HigDec 13, 2022
    risk 0.51cvss 7.8epss 0.01

    Windows Terminal Remote Code Execution Vulnerability

  • CVE-2022-41061HigNov 9, 2022
    risk 0.51cvss 7.8epss 0.01

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2022-32924HigNov 1, 2022
    risk 0.51cvss 7.8epss 0.01

    The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.

  • CVE-2022-41576HigOct 14, 2022
    risk 0.51cvss 7.8epss 0.00

    The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.

  • CVE-2022-40274HigSep 30, 2022
    risk 0.51cvss 7.8epss 0.00

    Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.

  • CVE-2022-36006HigAug 15, 2022
    risk 0.51cvss 7.9epss 0.02

    Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted…

  • CVE-2022-30580HigAug 10, 2022
    risk 0.51cvss 7.8epss 0.01

    Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.

  • CVE-2022-35779HigAug 9, 2022
    risk 0.51cvss 7.8epss 0.01

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

  • CVE-2022-30175HigAug 9, 2022
    risk 0.51cvss 7.8epss 0.01

    Azure RTOS GUIX Studio Remote Code Execution Vulnerability

  • CVE-2022-29221HigMay 24, 2022
    risk 0.51cvss 8.8epss 0.05

    Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully…

  • CVE-2022-26982HigApr 5, 2022
    risk 0.51cvss 7.2epss 0.09

    SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the…

  • CVE-2022-23614HigFeb 4, 2022
    risk 0.51cvss 8.8epss 0.08

    Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to…

  • CVE-2022-23120HigJan 20, 2022
    risk 0.51cvss 7.8epss 0.06

    A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to…

  • CVE-2021-43208HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.04

    3D Viewer Remote Code Execution Vulnerability

  • CVE-2021-42298HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.05

    Microsoft Defender Remote Code Execution Vulnerability

  • CVE-2021-42296HigNov 10, 2021
    risk 0.51cvss 7.8epss 0.01

    Microsoft Word Remote Code Execution Vulnerability

  • CVE-2021-42057HigNov 4, 2021
    risk 0.51cvss 7.8epss 0.01

    Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.