CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 109 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-40485 | Hig | 0.51 | 7.8 | 0.03 | Oct 13, 2021 | Microsoft Excel Remote Code Execution Vulnerability | ||
| CVE-2021-25470 | Hig | 0.51 | 7.9 | 0.00 | Oct 6, 2021 | An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE. | ||
| CVE-2021-25808 | Hig | 0.51 | 7.8 | 0.01 | Jul 23, 2021 | A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file. | ||
| CVE-2021-22117 | Hig | 0.51 | 7.8 | 0.01 | May 18, 2021 | RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins. | ||
| CVE-2021-31198 | Hig | 0.51 | 7.8 | 0.05 | May 11, 2021 | Microsoft Exchange Server Remote Code Execution Vulnerability | ||
| CVE-2020-35754 | Hig | 0.51 | 7.2 | 0.10 | Jan 28, 2021 | OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab. | ||
| CVE-2020-17091 | Hig | 0.51 | 7.8 | 0.02 | Nov 11, 2020 | Microsoft Teams Remote Code Execution Vulnerability | ||
| CVE-2020-8224 | Hig | 0.51 | 7.8 | 0.01 | Aug 10, 2020 | A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory. | ||
| CVE-2019-4000 | Hig | 0.51 | 7.8 | 0.01 | Feb 25, 2020 | Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges. | ||
| CVE-2013-2267 | Hig | 0.51 | 7.2 | 0.09 | Jan 27, 2020 | PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system. | ||
| CVE-2019-1157 | Hig | 0.51 | 7.8 | 0.04 | Aug 14, 2019 | A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by… | ||
| CVE-2019-5443 | Hig | 0.51 | 7.8 | 0.01 | Jul 2, 2019 | A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything… | ||
| CVE-2019-0091 | Hig | 0.51 | 7.8 | 0.01 | May 17, 2019 | Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access. | ||
| CVE-2019-10863 | Hig | 0.51 | 7.2 | 0.13 | Apr 4, 2019 | A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server. | ||
| CVE-2018-19002 | Hig | 0.51 | 7.8 | 0.03 | Feb 5, 2019 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash. | ||
| CVE-2019-3575 | Hig | 0.51 | 7.8 | 0.00 | Jan 3, 2019 | Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load. | ||
| CVE-2018-8415 | Hig | 0.51 | 7.8 | 0.01 | Nov 14, 2018 | A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server… | ||
| CVE-2018-2491 | Hig | 0.51 | 7.8 | 0.01 | Nov 13, 2018 | When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the… | ||
| CVE-2018-14630 | Hig | 0.51 | 8.8 | 0.04 | Sep 17, 2018 | moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within… | ||
| CVE-2018-11781 | Hig | 0.51 | 7.8 | 0.01 | Sep 17, 2018 | Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax. |
- risk 0.51cvss 7.8epss 0.03
Microsoft Excel Remote Code Execution Vulnerability
- risk 0.51cvss 7.9epss 0.00
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
- risk 0.51cvss 7.8epss 0.01
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
- risk 0.51cvss 7.8epss 0.01
RabbitMQ installers on Windows prior to version 3.8.16 do not harden plugin directory permissions, potentially allowing attackers with sufficient local filesystem permissions to add arbitrary plugins.
- risk 0.51cvss 7.8epss 0.05
Microsoft Exchange Server Remote Code Execution Vulnerability
- risk 0.51cvss 7.2epss 0.10
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
- risk 0.51cvss 7.8epss 0.02
Microsoft Teams Remote Code Execution Vulnerability
- risk 0.51cvss 7.8epss 0.01
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
- risk 0.51cvss 7.8epss 0.01
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
- risk 0.51cvss 7.2epss 0.09
PHP Code Injection vulnerability in FUDforum Bulletin Board Software 3.0.4 could allow remote attackers to execute arbitrary code on the system.
- risk 0.51cvss 7.8epss 0.04
A remote code execution vulnerability exists when the Windows Jet Database Engine improperly handles objects in memory. An attacker who successfully exploited this vulnerability could execute arbitrary code on a victim system. An attacker could exploit this vulnerability by…
- risk 0.51cvss 7.8epss 0.01
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked by a privileged user it can do anything…
- risk 0.51cvss 7.8epss 0.01
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
- risk 0.51cvss 7.2epss 0.13
A command injection vulnerability exists in TeemIp versions before 2.4.0. The new_config parameter of exec.php allows one to create a new PHP file with the exception of config information. The malicious PHP code sent is executed instantaneously and is not saved on the server.
- risk 0.51cvss 7.8epss 0.03
LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash.
- risk 0.51cvss 7.8epss 0.00
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
- risk 0.51cvss 7.8epss 0.01
A tampering vulnerability exists in PowerShell that could allow an attacker to execute unlogged code, aka "Microsoft PowerShell Tampering Vulnerability." This affects Windows 7, PowerShell Core 6.1, Windows Server 2012 R2, Windows RT 8.1, PowerShell Core 6.0, Windows Server…
- risk 0.51cvss 7.8epss 0.01
When opening a deep link URL in SAP Fiori Client with log level set to "Debug", the client application logs the URL to the log file. If this URL contains malicious JavaScript code it can eventually run inside the built-in log viewer of the application in case user opens the…
- risk 0.51cvss 8.8epss 0.04
moodle before versions 3.5.2, 3.4.5, 3.3.8, 3.1.14 is vulnerable to an XML import of ddwtos could lead to intentional remote code execution. When importing legacy 'drag and drop into text' (ddwtos) type quiz questions, it was possible to inject and execute PHP code from within…
- risk 0.51cvss 7.8epss 0.01
Apache SpamAssassin 3.4.2 fixes a local user code injection in the meta rule syntax.