VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,044)

page 142 of 353
  • CVE-2023-20209MedAug 16, 2023
    risk 0.45cvss 6.5epss 0.41

    A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform a command injection attack that could…

  • CVE-2023-4142HigAug 4, 2023
    risk 0.45cvss 8.0epss 0.02

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access…

  • CVE-2023-4141HigAug 4, 2023
    risk 0.45cvss 8.0epss 0.02

    The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the administrator previously grants access…

  • CVE-2023-35926HigJun 22, 2023
    risk 0.45cvss 8.0epss 0.02

    Backstage is an open platform for building developer portals. The Backstage scaffolder-backend plugin uses a templating library that requires sandbox, as it by design allows for code injection. The library used for this sandbox so far has been `vm2`, but in light of several past…

  • CVE-2023-2928MedMay 27, 2023
    risk 0.45cvss 6.3epss 0.51

    A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls leads to code injection. The attack can…

  • CVE-2023-26107MedMar 6, 2023
    risk 0.45cvss 6.9epss 0.00

    All versions of the package sketchsvg are vulnerable to Arbitrary Code Injection when invoking shell.exec without sanitization nor parametrization while concatenating the current directory as part of the command string.

  • CVE-2022-47318HigJan 17, 2023
    risk 0.45cvss 8.0epss 0.01

    ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-46648.

  • CVE-2022-46648HigJan 17, 2023
    risk 0.45cvss 8.0epss 0.01

    ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from CVE-2022-47318.

  • CVE-2022-29821MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible

  • CVE-2022-29819MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible

  • CVE-2022-29815MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible

  • CVE-2022-29814MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible

  • CVE-2022-29813MedApr 28, 2022
    risk 0.45cvss 6.9epss 0.00

    In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible

  • CVE-2020-15142HigAug 14, 2020
    risk 0.45cvss 8.0epss 0.02

    In openapi-python-client before version 0.5.3, clients generated with a maliciously crafted OpenAPI Document can generate arbitrary Python code. Subsequent execution of this malicious client is arbitrary code execution.

  • CVE-2019-3759MedSep 11, 2019
    risk 0.45cvss 6.4epss 0.03

    The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability to run custom Groovy scripts to gain…

  • CVE-2019-11201HigJul 29, 2019
    risk 0.45cvss 8.0epss 0.02

    Dolibarr ERP/CRM 9.0.1 provides a module named website that provides for creation of public websites with a WYSIWYG editor. It was identified that the editor also allowed inclusion of dynamic code, which can lead to code execution on the host machine. An attacker has to check a…

  • CVE-2026-68508HigAug 21, 2026
    risk 0.44cvss 7.8epss 0.00

    Hydra is a framework for elegantly configuring complex applications. Prior to 1.3.4, hydra.utils.instantiate() resolves and calls Python objects selected by configuration through _resolve_target() in hydra/_internal/instantiate/_instantiate2.py, allowing attacker-controlled…

  • CVE-2026-18287HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.00

    Aeon load_time_series_segmentation_benchmark Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the target…

  • CVE-2026-18286HigAug 20, 2026
    risk 0.44cvss 7.8epss 0.00

    Aeon load_human_activity_segmentation_datasets Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of aeon. User interaction is required to exploit this vulnerability in that the…

  • CVE-2026-43961HigAug 19, 2026
    risk 0.44cvss 7.8epss 0.00

    A flaw was found in Vim's netrw plugin. A crafted filename containing quote characters and expression fragments can break out of the quoted context during mark/unmark operations, allowing arbitrary Vimscript execution. This can be leveraged to run shell commands with the…