VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 119 of 350
  • CVE-2025-23251HigApr 22, 2025
    risk 0.49cvss 7.6epss 0.01

    NVIDIA NeMo Framework contains a vulnerability where a user could cause an improper control of generation of code by remote code execution. A successful exploit of this vulnerability might lead to code execution and data tampering.

  • CVE-2024-10572HigMar 20, 2025
    risk 0.49cvss 7.5epss 0.01

    In h2oai/h2o-3 version 3.46.0.1, the `run_tool` command exposes classes in the `water.tools` package through the `ast` parser. This includes the `XGBoostLibExtractTool` class, which can be exploited to shut down the server and write large files to arbitrary directories, leading…

  • CVE-2025-22136HigJan 8, 2025
    risk 0.49cvss epss 0.00

    Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.217 , Tabby enables several high-risk Electron Fuses, including RunAsNode, EnableNodeCliInspectArguments, and EnableNodeOptionsEnvironmentVariable. These fuses create potential code injection…

  • CVE-2024-50715HigDec 27, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the /youtubeInfo.php component.

  • CVE-2024-55580HigDec 9, 2024
    risk 0.49cvss 7.5epss 0.00

    An issue was discovered in Qlik Sense Enterprise for Windows before November 2024 IR. Unprivileged users with network access may be able to execute remote commands that could cause high availability damages, including high integrity and confidentiality risks. This is fixed in…

  • CVE-2024-10382HigNov 20, 2024
    risk 0.49cvss 7.5epss 0.00

    There exists a code execution vulnerability in the Car App Android Jetpack Library. CarAppService uses deserialization logic that allows construction of arbitrary java classes. This can lead to arbitrary code execution when combined with specific Java deserialization gadgets. An…

  • CVE-2024-44757HigNov 18, 2024
    risk 0.49cvss 7.5epss 0.00

    An arbitrary file download vulnerability in the component /Basics/DownloadInpFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to download arbitrary files and access sensitive information via a crafted interface request.

  • CVE-2024-48279HigOct 15, 2024
    risk 0.49cvss 7.6epss 0.01

    A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in a POST HTTP request.

  • CVE-2024-46639HigSep 23, 2024
    risk 0.49cvss 7.6epss 0.00

    A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.

  • CVE-2024-40487HigAug 12, 2024
    risk 0.49cvss 7.6epss 0.01

    A Stored Cross Site Scripting (XSS) vulnerability was found in "/view_type.php" of Kashipara Live Membership System v1.0, which allows remote attackers to execute arbitrary code via membershipType parameter.

  • CVE-2023-31315HigAug 12, 2024
    risk 0.49cvss 7.5epss 0.01

    Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.

  • CVE-2024-6206HigJun 25, 2024
    risk 0.49cvss 7.5epss 0.00

    A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying container leading to complete takeover of the…

  • CVE-2024-38319HigJun 22, 2024
    risk 0.49cvss 7.5epss 0.00

    IBM Security SOAR 51.0.2.0 could allow an authenticated user to execute malicious code loaded from a specially crafted script. IBM X-Force ID: 294830.

  • CVE-2024-36581HigJun 17, 2024
    risk 0.49cvss 7.6epss 0.01

    A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.

  • CVE-2024-32358HigApr 25, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.

  • CVE-2024-29399HigApr 11, 2024
    risk 0.49cvss 7.6epss 0.01

    An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.

  • CVE-2024-27705HigApr 3, 2024
    risk 0.49cvss 7.6epss 0.01

    Cross Site Scripting vulnerability in Leantime v3.0.6 allows attackers to execute arbitrary code via upload of crafted PDF file to the files/browse endpoint.

  • CVE-2024-2097HigMar 27, 2024
    risk 0.49cvss 7.5epss 0.00

    An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed in the case of SCM Tools.

  • CVE-2024-0400HigMar 27, 2024
    risk 0.49cvss 7.5epss 0.01

    SCM Software is a client and server application. An Authenticated System manager client can execute LINQ query in the SCM server, for customized filtering. An Authenticated malicious client can send a specially crafted code to skip the validation and execute arbitrary code (RCE)…

  • CVE-2024-28396HigMar 20, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in MyPrestaModules ordersexport v.6.0.2 and before allows a remote attacker to execute arbitrary code via the download.php component.