VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 123 of 350
  • CVE-2024-8271HigSep 14, 2024
    risk 0.48cvss 7.3epss 0.01

    The The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.4.2.1. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2024-8478HigSep 10, 2024
    risk 0.48cvss 7.3epss 0.01

    The The Affiliate Super Assistent plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.5.3. This is due to the software allowing users to supply arbitrary shortcodes in comments when the 'Parse comments' option is enabled.…

  • CVE-2024-21513HigJul 15, 2024
    risk 0.48cvss 8.5epss 0.02

    Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from the database, the code will attempt to call 'eval' on all values. An attacker can exploit this vulnerability and execute arbitrary…

  • CVE-2024-37149HigJul 10, 2024
    risk 0.48cvss 7.2epss 0.21

    GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loader to execute this malicious script.…

  • CVE-2024-32030HigJun 19, 2024
    risk 0.48cvss 8.1epss 0.34

    Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. As a separate feature, it also provides the ability to monitor the performance of Kafka brokers by…

  • CVE-2024-1117HigJan 31, 2024
    risk 0.48cvss 7.3epss 0.01

    A vulnerability was found in openBI up to 1.0.8. It has been declared as critical. Affected by this vulnerability is the function index of the file /application/index/controller/Screen.php. The manipulation of the argument fileurl leads to code injection. The attack can be…

  • CVE-2023-6548MedKEVJan 17, 2024
    risk 0.48cvss 5.5epss 0.03

    Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execution on Management Interface.

  • CVE-2023-48699HigNov 21, 2023
    risk 0.48cvss 8.4epss 0.01

    fastbots is a library for fast bot and scraper development using selenium and the Page Object Model (POM) design. Prior to version 0.1.5, an attacker could modify the locators.ini locator file with python code that without proper validation it's executed and it could lead to…

  • CVE-2023-36014HigNov 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2023-46865HigOct 30, 2023
    risk 0.48cvss 7.2epss 0.20

    /api/v1/company/upload-logo in CompanyController.php in crater through 6.0.6 allows a superadmin to execute arbitrary PHP code by placing this code into an image/png IDAT chunk of a Company Logo image.

  • CVE-2023-26155HigOct 14, 2023
    risk 0.48cvss 7.3epss 0.02

    All versions of the package node-qpdf are vulnerable to Command Injection such that the package-exported method encrypt() fails to sanitize its parameter input, which later flows into a sensitive command execution API. As a result, attackers may inject malicious commands once…

  • CVE-2023-36592HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36591HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36589HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36575HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36574HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36573HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36572HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36571HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability

  • CVE-2023-36570HigOct 10, 2023
    risk 0.48cvss 7.3epss 0.01

    Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability