CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 110 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2018-0675 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2018 | AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors. | ||
| CVE-2018-0674 | Hig | 0.51 | 7.8 | 0.01 | Sep 4, 2018 | AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors. | ||
| CVE-2016-4397 | Hig | 0.51 | 7.8 | 0.01 | Aug 6, 2018 | A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software. | ||
| CVE-2018-5158 | Hig | 0.51 | 8.8 | 0.10 | Jun 11, 2018 | The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR <… | ||
| CVE-2018-10517 | Hig | 0.51 | 7.2 | 0.12 | Apr 27, 2018 | In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element. | ||
| CVE-2017-16670 | Hig | 0.51 | 7.8 | 0.02 | Feb 19, 2018 | The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file. | ||
| CVE-2018-6574 | Hig | 0.51 | 7.8 | 0.08 | Feb 7, 2018 | Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked. | ||
| CVE-2017-15103 | Hig | 0.51 | 8.8 | 0.06 | Dec 18, 2017 | A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege… | ||
| CVE-2014-8872 | Hig | 0.51 | 7.8 | 0.01 | Aug 29, 2017 | Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50. | ||
| CVE-2017-1469 | Hig | 0.51 | 7.8 | 0.00 | Aug 14, 2017 | IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468. | ||
| CVE-2017-11421 | Hig | 0.51 | 7.8 | 0.01 | Jul 18, 2017 | gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript… | ||
| CVE-2015-6531 | Hig | 0.51 | 7.8 | 0.03 | Jun 1, 2017 | Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file. | ||
| CVE-2016-1602 | Hig | 0.51 | 7.8 | 0.01 | Mar 23, 2017 | A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root). | ||
| CVE-2005-3302 | Hig | 0.51 | 7.3 | 0.04 | Oct 24, 2005 | Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call. | ||
| CVE-2026-75827 | Hig | 0.50 | 8.8 | 0.01 | Aug 18, 2026 | Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function… | ||
| CVE-2026-72819 | Hig | 0.50 | 8.8 | 0.01 | Aug 14, 2026 | Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array… | ||
| CVE-2026-48054 | Hig | 0.50 | 8.8 | 0.00 | Aug 6, 2026 | OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri`… | ||
| CVE-2026-51401 | Hig | 0.50 | 7.7 | 0.00 | Aug 4, 2026 | An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c | ||
| CVE-2026-69100 | Hig | 0.50 | 8.8 | 0.01 | Aug 4, 2026 | LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or… | ||
| CVE-2026-54653 | Hig | 0.50 | 8.8 | 0.00 | Jul 28, 2026 | datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory… |
- risk 0.51cvss 7.8epss 0.01
AttacheCase ver.3.3.0.0 and earlier allows an arbitrary script execution via unspecified vectors.
- risk 0.51cvss 7.8epss 0.01
AttacheCase ver.2.8.4.0 and earlier allows an arbitrary script execution via unspecified vectors.
- risk 0.51cvss 7.8epss 0.01
A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.
- risk 0.51cvss 8.8epss 0.10
The PDF viewer does not sufficiently sanitize PostScript calculator functions, allowing malicious JavaScript to be injected through a crafted PDF file. This JavaScript can then be run with the permissions of the PDF viewer by its worker. This vulnerability affects Firefox ESR <…
- risk 0.51cvss 7.2epss 0.12
In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encoded PHP code in a data element.
- risk 0.51cvss 7.8epss 0.02
The project import functionality in SoapUI 5.3.0 allows remote attackers to execute arbitrary Java code via a crafted request parameter in a WSDL project file.
- risk 0.51cvss 7.8epss 0.08
Go before 1.8.7, Go 1.9.x before 1.9.4, and Go 1.10 pre-releases before Go 1.10rc2 allow "go get" remote command execution during source code build, by leveraging the gcc or clang plugin feature, because -fplugin= and -plugin= arguments were not blocked.
- risk 0.51cvss 8.8epss 0.06
A security-check flaw was found in the way the Heketi 5 server API handled user requests. An authenticated Heketi user could send specially crafted requests to the Heketi server, resulting in remote command execution as the user running Heketi server and possibly privilege…
- risk 0.51cvss 7.8epss 0.01
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
- risk 0.51cvss 7.8epss 0.00
IBM InfoSphere Information Server 9.1, 11.3, and 11.5 could allow a local user to gain elevated privileges by placing arbitrary files in installation directories. IBM X-Force ID: 128468.
- risk 0.51cvss 7.8epss 0.01
gnome-exe-thumbnailer before 0.9.5 is prone to a VBScript Injection when generating thumbnails for MSI files, aka the "Bad Taste" issue. There is a local attack if the victim uses the GNOME Files file manager, and navigates to a directory containing a .msi file with VBScript…
- risk 0.51cvss 7.8epss 0.03
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
- risk 0.51cvss 7.8epss 0.01
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running supportconfig (usually root).
- risk 0.51cvss 7.3epss 0.04
Eval injection vulnerability in bvh_import.py in Blender 2.36 allows attackers to execute arbitrary Python code via a hierarchy element in a .bvh file, which is supplied to an eval function call.
- risk 0.50cvss 8.8epss 0.01
Grav before 2.0.15 contains an arbitrary file write vulnerability in the Blueprint dynamic-data bare-function validation that uses an incomplete denylist instead of a positive allowlist. Attackers with page-edit or blueprint-config access can invoke the error_log function…
- risk 0.50cvss 8.8epss 0.01
Grav CMS before 2.0.13 contains a remote code execution vulnerability in the Flex Objects plugin settings validation that allows authenticated users to execute arbitrary code by uploading a ZIP file containing PHP code. Attackers can bypass routine name validation by using array…
- risk 0.50cvss 8.8epss 0.00
OpenZeppelin Contracts Wizardis a web application to interactively build a contract out of components from OpenZeppelin Contracts. Versions prior to 0.10.9 generate a Hardhat test file (`test/test.ts`) by interpolating user-supplied `opts.name` (ERC20/ERC721) and `opts.uri`…
- risk 0.50cvss 7.7epss 0.00
An issue in Vim Project v9.2.0389 and earlier allows a local attacker to execute arbitrary code via the vms_fixfilename() function within file vim/src/os_vms.c
- risk 0.50cvss 8.8epss 0.01
LAMP Rapid Development Platform through 5.6.2, fixed in commit 84b0c27, contains a remote code execution vulnerability in GlueFactory that executes unsandboxed Groovy scripts from database template fields without compilation restrictions or whitelisting. Attackers can write or…
- risk 0.50cvss 8.8epss 0.00
datamodel-code-generator generates Pydantic v2 models, dataclasses, TypedDict, and msgspec.Struct from OpenAPI, JSON Schema, GraphQL, Avro, Protobuf, and raw JSON, YAML, or CSV. From 0.17.0 until 0.60.2, datamodel-code-generator preserves attacker-controlled default_factory…