CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 108 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0877 | Hig | 0.51 | 8.8 | 0.04 | Feb 17, 2023 | Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11. | ||
| CVE-2022-27537 | Hig | 0.51 | 7.8 | 0.00 | Feb 1, 2023 | Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential… | ||
| CVE-2022-42268 | Hig | 0.51 | 7.8 | 0.01 | Jan 13, 2023 | Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a… | ||
| CVE-2022-44702 | Hig | 0.51 | 7.8 | 0.01 | Dec 13, 2022 | Windows Terminal Remote Code Execution Vulnerability | ||
| CVE-2022-41061 | Hig | 0.51 | 7.8 | 0.01 | Nov 9, 2022 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2022-32924 | Hig | 0.51 | 7.8 | 0.01 | Nov 1, 2022 | The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges. | ||
| CVE-2022-41576 | Hig | 0.51 | 7.8 | 0.00 | Oct 14, 2022 | The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices. | ||
| CVE-2022-40274 | Hig | 0.51 | 7.8 | 0.00 | Sep 30, 2022 | Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled. | ||
| CVE-2022-36006 | Hig | 0.51 | 7.9 | 0.02 | Aug 15, 2022 | Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted… | ||
| CVE-2022-30580 | Hig | 0.51 | 7.8 | 0.01 | Aug 10, 2022 | Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset. | ||
| CVE-2022-35779 | Hig | 0.51 | 7.8 | 0.01 | Aug 9, 2022 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | ||
| CVE-2022-30175 | Hig | 0.51 | 7.8 | 0.01 | Aug 9, 2022 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | ||
| CVE-2022-29221 | Hig | 0.51 | 8.8 | 0.05 | May 24, 2022 | Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully… | ||
| CVE-2022-26982 | Hig | 0.51 | 7.2 | 0.09 | Apr 5, 2022 | SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the… | ||
| CVE-2022-23614 | Hig | 0.51 | 8.8 | 0.08 | Feb 4, 2022 | Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to… | ||
| CVE-2022-23120 | Hig | 0.51 | 7.8 | 0.06 | Jan 20, 2022 | A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to… | ||
| CVE-2021-43208 | Hig | 0.51 | 7.8 | 0.04 | Nov 10, 2021 | 3D Viewer Remote Code Execution Vulnerability | ||
| CVE-2021-42298 | Hig | 0.51 | 7.8 | 0.05 | Nov 10, 2021 | Microsoft Defender Remote Code Execution Vulnerability | ||
| CVE-2021-42296 | Hig | 0.51 | 7.8 | 0.01 | Nov 10, 2021 | Microsoft Word Remote Code Execution Vulnerability | ||
| CVE-2021-42057 | Hig | 0.51 | 7.8 | 0.01 | Nov 4, 2021 | Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases. |
- risk 0.51cvss 8.8epss 0.04
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
- risk 0.51cvss 7.8epss 0.00
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate these potential…
- risk 0.51cvss 7.8epss 0.01
Omniverse Kit contains a vulnerability in the reference applications Create, Audio2Face, Isaac Sim, View, Code, and Machinima. These applications allow executable Python code to be embedded in Universal Scene Description (USD) files to customize all aspects of a scene. If a…
- risk 0.51cvss 7.8epss 0.01
Windows Terminal Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kernel privileges.
- risk 0.51cvss 7.8epss 0.00
The rphone module has a script that can be maliciously modified.Successful exploitation of this vulnerability may cause irreversible programs to be implanted on user devices.
- risk 0.51cvss 7.8epss 0.00
Gridea version 0.9.3 allows an external attacker to execute arbitrary code remotely on any client attempting to view a malicious markdown file through Gridea. This is possible because the application has the 'nodeIntegration' option enabled.
- risk 0.51cvss 7.9epss 0.02
Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute arbitrary code via specially crafted…
- risk 0.51cvss 7.8epss 0.01
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
- risk 0.51cvss 7.8epss 0.01
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- risk 0.51cvss 8.8epss 0.05
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include} file name. Sites that cannot fully…
- risk 0.51cvss 7.2epss 0.09
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that administrators are intended to have the…
- risk 0.51cvss 8.8epss 0.08
Twig is an open source template language for PHP. When in a sandbox mode, the `arrow` parameter of the `sort` filter must be a closure to avoid attackers being able to run arbitrary PHP functions. In affected versions this constraint was not properly enforced and could lead to…
- risk 0.51cvss 7.8epss 0.06
A code injection vulnerability in Trend Micro Deep Security and Cloud One - Workload Security Agent for Linux version 20 and below could allow an attacker to escalate privileges and run arbitrary code in the context of root. Please note: an attacker must first obtain access to…
- risk 0.51cvss 7.8epss 0.04
3D Viewer Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.05
Microsoft Defender Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Microsoft Word Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
Obsidian Dataview through 0.4.12-hotfix1 allows eval injection. The evalInContext function in executes user input, which allows an attacker to craft malicious Markdown files that will execute arbitrary code once opened. NOTE: 0.4.13 provides a mitigation for some use cases.