CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,044)
page 133 of 353| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-30912 | Hig | 0.47 | 7.2 | 0.01 | Oct 25, 2023 | A remote code execution issue exists in HPE OneView. | ||
| CVE-2023-36789 | Hig | 0.47 | 7.2 | 0.02 | Oct 10, 2023 | Skype for Business Remote Code Execution Vulnerability | ||
| CVE-2023-44847 | Hig | 0.47 | 7.2 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component. | ||
| CVE-2023-37427 | Hig | 0.47 | 7.2 | 0.01 | Aug 22, 2023 | A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary… | ||
| CVE-2023-36992 | Hig | 0.47 | 7.2 | 0.01 | Jul 7, 2023 | PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code. | ||
| CVE-2020-20918 | Hig | 0.47 | 7.2 | 0.01 | Jun 20, 2023 | An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page. | ||
| CVE-2023-32540 | Hig | 0.47 | 7.2 | 0.01 | Jun 6, 2023 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead… | ||
| CVE-2023-29963 | Hig | 0.47 | 7.2 | 0.02 | May 5, 2023 | S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php. | ||
| CVE-2022-36963 | Hig | 0.47 | 7.2 | 0.08 | Apr 21, 2023 | The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands. | ||
| CVE-2023-25550 | Hig | 0.47 | 7.2 | 0.01 | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center… | ||
| CVE-2023-25549 | Hig | 0.47 | 7.2 | 0.01 | Apr 18, 2023 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior) | ||
| CVE-2023-30638 | Hig | 0.47 | 7.2 | 0.01 | Apr 14, 2023 | Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands. | ||
| CVE-2023-24835 | Hig | 0.47 | 7.2 | 0.01 | Mar 27, 2023 | Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or… | ||
| CVE-2023-0575 | Hig | 0.47 | 7.2 | 0.01 | Feb 9, 2023 | External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege… | ||
| CVE-2022-48093 | Hig | 0.47 | 7.2 | 0.01 | Feb 1, 2023 | Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php. | ||
| CVE-2022-48116 | Hig | 0.47 | 7.2 | 0.01 | Jan 27, 2023 | AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php. | ||
| CVE-2022-44533 | Hig | 0.47 | 7.2 | 0.01 | Dec 12, 2022 | A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system… | ||
| CVE-2022-43542 | Hig | 0.47 | 7.2 | 0.01 | Dec 12, 2022 | Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system… | ||
| CVE-2022-43541 | Hig | 0.47 | 7.2 | 0.02 | Dec 12, 2022 | Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system… | ||
| CVE-2022-43660 | Hig | 0.47 | 7.2 | 0.01 | Dec 7, 2022 | Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are… |
- risk 0.47cvss 7.2epss 0.01
A remote code execution issue exists in HPE OneView.
- risk 0.47cvss 7.2epss 0.02
Skype for Business Remote Code Execution Vulnerability
- risk 0.47cvss 7.2epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ Weixin.php component.
- risk 0.47cvss 7.2epss 0.01
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows an attacker to execute arbitrary…
- risk 0.47cvss 7.2epss 0.01
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
- risk 0.47cvss 7.2epss 0.01
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
- risk 0.47cvss 7.2epss 0.01
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead…
- risk 0.47cvss 7.2epss 0.02
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
- risk 0.47cvss 7.2epss 0.08
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
- risk 0.47cvss 7.2epss 0.01
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows remote code execution via the “hostname” parameter when maliciously crafted hostname syntax is entered. Affected products: StruxureWare Data Center…
- risk 0.47cvss 7.2epss 0.01
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that allows for remote code execution when using a parameter of the DCE network settings endpoint. Affected products: StruxureWare Data Center Expert (V7.9.2 and prior)
- risk 0.47cvss 7.2epss 0.01
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.
- risk 0.47cvss 7.2epss 0.01
Softnext Technologies Corp.’s SPAM SQR has a vulnerability of Code Injection within its specific function. An authenticated remote attacker with administrator privilege can exploit this vulnerability to execute arbitrary system command to perform arbitrary system operation or…
- risk 0.47cvss 7.2epss 0.01
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules) allows API Manipulation, Privilege…
- risk 0.47cvss 7.2epss 0.01
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
- risk 0.47cvss 7.2epss 0.01
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
- risk 0.47cvss 7.2epss 0.01
A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…
- risk 0.47cvss 7.2epss 0.01
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…
- risk 0.47cvss 7.2epss 0.02
Vulnerabilities in the Aruba EdgeConnect Enterprise command line interface allow remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as root on the underlying operating system…
- risk 0.47cvss 7.2epss 0.01
Improper neutralization of Server-Side Includes (SSW) within a web page in Movable Type series allows a remote authenticated attacker with Privilege of 'Manage of Content Types' may execute an arbitrary Perl script and/or an arbitrary OS command. Affected products/versions are…