VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 120 of 350
  • CVE-2024-24230HigMar 18, 2024
    risk 0.49cvss 7.5epss 0.01

    Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRuntime().exec followed by an OS command.

  • CVE-2022-46070HigMar 11, 2024
    risk 0.49cvss 7.5epss 0.00

    GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.

  • CVE-2024-24278HigMar 5, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.

  • CVE-2024-25713HigFeb 29, 2024
    risk 0.49cvss 8.6epss 0.02

    yyjson through 0.8.0 has a double free, leading to remote code execution in some cases, because the pool_free function lacks loop checks. (pool_free is part of the pool series allocator, along with pool_malloc and pool_realloc.)

  • CVE-2022-45177HigFeb 21, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and the /login endpoint. The web…

  • CVE-2024-25415HigFeb 16, 2024
    risk 0.49cvss 7.2epss 0.27

    A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php.

  • CVE-2024-21674HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.02

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:N allows an…

  • CVE-2023-51282HigJan 16, 2024
    risk 0.49cvss 7.5epss 0.01

    An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.

  • CVE-2023-45560HigNov 14, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in Yasukawa memberscard v.13.6.1 allows attackers to send crafted notifications via leakage of the channel access token.

  • CVE-2020-36767HigOct 30, 2023
    risk 0.49cvss 7.5epss 0.00

    tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.

  • CVE-2023-38886HigSep 20, 2023
    risk 0.49cvss 7.2epss 0.29

    An issue in Dolibarr ERP CRM v.17.0.1 and before allows a remote privileged attacker to execute arbitrary code via a crafted command/script.

  • CVE-2023-40826HigAug 28, 2023
    risk 0.49cvss 7.5epss 0.01

    An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.

  • CVE-2023-21553HigFeb 14, 2023
    risk 0.49cvss 7.5epss 0.01

    Azure DevOps Server Remote Code Execution Vulnerability

  • CVE-2023-24576HigFeb 3, 2023
    risk 0.49cvss 7.5epss 0.01

    EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.

  • CVE-2022-43572HigNov 4, 2022
    risk 0.49cvss 7.5epss 0.01

    In Splunk Enterprise versions below 8.2.9, 8.1.12, and 9.0.2, sending a malformed file through the Splunk-to-Splunk (S2S) or HTTP Event Collector (HEC) protocols to an indexer results in a blockage or denial-of-service preventing further indexing.

  • CVE-2022-30194HigAug 9, 2022
    risk 0.49cvss 7.5epss 0.01

    Windows WebBrowser Control Remote Code Execution Vulnerability

  • CVE-2022-21167HigMay 1, 2022
    risk 0.49cvss 7.5epss 0.01

    All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable input after it has been established,…

  • CVE-2022-24734HigMar 9, 2022
    risk 0.49cvss 7.2epss 0.78

    MyBB is a free and open source forum software. In affected versions the Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add settings of supported type `php` with PHP code, executed on on _Change…

  • CVE-2021-22395HigFeb 25, 2022
    risk 0.49cvss 7.5epss 0.01

    There is a code injection vulnerability in smartphones. Successful exploitation of this vulnerability may affect service confidentiality.

  • CVE-2021-37097HigDec 8, 2021
    risk 0.49cvss 7.5epss 0.01

    There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.