CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 120 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24230 | Hig | 0.49 | 7.5 | 0.01 | Mar 18, 2024 | Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command. | ||
| CVE-2022-46070 | Hig | 0.49 | 7.5 | 0.00 | Mar 11, 2024 | GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path. | ||
| CVE-2024-24278 | Hig | 0.49 | 7.5 | 0.01 | Mar 5, 2024 | An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function. | ||
| CVE-2024-25713 | Hig | 0.49 | 8.6 | 0.02 | Feb 29, 2024 | yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.) | ||
| CVE-2022-45177 | Hig | 0.49 | 7.5 | 0.01 | Feb 21, 2024 | An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web… | ||
| CVE-2024-25415 | Hig | 0.49 | 7.2 | 0.27 | Feb 16, 2024 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | ||
| CVE-2024-21674 | Hig | 0.49 | 7.5 | 0.02 | Jan 16, 2024 | This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an… | ||
| CVE-2023-51282 | Hig | 0.49 | 7.5 | 0.01 | Jan 16, 2024 | An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter. | ||
| CVE-2023-45560 | Hig | 0.49 | 7.5 | 0.01 | Nov 14, 2023 | An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token. | ||
| CVE-2020-36767 | Hig | 0.49 | 7.5 | 0.00 | Oct 30, 2023 | tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data. | ||
| CVE-2023-38886 | Hig | 0.49 | 7.2 | 0.29 | Sep 20, 2023 | An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script. | ||
| CVE-2023-40826 | Hig | 0.49 | 7.5 | 0.01 | Aug 28, 2023 | An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter. | ||
| CVE-2023-21553 | Hig | 0.49 | 7.5 | 0.01 | Feb 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | ||
| CVE-2023-24576 | Hig | 0.49 | 7.5 | 0.01 | Feb 3, 2023 | EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used. | ||
| CVE-2022-43572 | Hig | 0.49 | 7.5 | 0.01 | Nov 4, 2022 | In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing. | ||
| CVE-2022-30194 | Hig | 0.49 | 7.5 | 0.01 | Aug 9, 2022 | Windows WebBrowser Control Remote Code Execution Vulnerability | ||
| CVE-2022-21167 | Hig | 0.49 | 7.5 | 0.01 | May 1, 2022 | All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established,… | ||
| CVE-2022-24734 | Hig | 0.49 | 7.2 | 0.78 | Mar 9, 2022 | MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change… | ||
| CVE-2021-22395 | Hig | 0.49 | 7.5 | 0.01 | Feb 25, 2022 | There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality. | ||
| CVE-2021-37097 | Hig | 0.49 | 7.5 | 0.01 | Dec 8, 2021 | There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart. |
- risk 0.49cvss 7.5epss 0.01
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.
- risk 0.49cvss 7.5epss 0.00
GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.
- risk 0.49cvss 7.5epss 0.01
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
- risk 0.49cvss 8.6epss 0.02
yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)
- risk 0.49cvss 7.5epss 0.01
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web…
- risk 0.49cvss 7.2epss 0.27
A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.
- risk 0.49cvss 7.5epss 0.02
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an…
- risk 0.49cvss 7.5epss 0.01
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
- risk 0.49cvss 7.5epss 0.01
An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.
- risk 0.49cvss 7.5epss 0.00
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
- risk 0.49cvss 7.2epss 0.29
An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.
- risk 0.49cvss 7.5epss 0.01
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
- risk 0.49cvss 7.5epss 0.01
Azure DevOps Server Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.
- risk 0.49cvss 7.5epss 0.01
In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.
- risk 0.49cvss 7.5epss 0.01
Windows WebBrowser Control Remote Code Execution Vulnerability
- risk 0.49cvss 7.5epss 0.01
All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established,…
- risk 0.49cvss 7.2epss 0.78
MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change…
- risk 0.49cvss 7.5epss 0.01
There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.
- risk 0.49cvss 7.5epss 0.01
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.