VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 145 of 353
  • CVE-2025-0664MedJul 21, 2025
    risk 0.44cvss epss 0.00

    A locally authenticated, privileged user can craft a malicious OpenSSL configuration file, potentially leading the agent to load an arbitrary local library. This may impair endpoint defenses and allow the attacker to achieve code execution with SYSTEM-level privileges.

  • CVE-2025-30013MedApr 8, 2025
    risk 0.44cvss 6.7epss 0.01

    SAP ERP BW Business Content is vulnerable to OS Command Injection through certain function modules. These function modules, when executed with elevated privileges, improperly handle user input, allowing attacker to inject arbitrary OS commands. This vulnerability allows the…

  • CVE-2024-41643MedMar 26, 2025
    risk 0.44cvss 6.8epss 0.00

    An issue in Arris NVG443B 9.3.0h3d36 allows a physically proximate attacker to execute arbitrary code via the cshell login component.

  • CVE-2024-52925MedFeb 26, 2025
    risk 0.44cvss 6.8epss 0.00

    In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted USB drives.

  • CVE-2024-7425MedFeb 7, 2025
    risk 0.44cvss 6.8epss 0.00

    The WP ALL Export Pro plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to improper user input validation and sanitization in all versions up to, and including, 1.9.1. This makes it possible for authenticated…

  • CVE-2024-56448MedJan 8, 2025
    risk 0.44cvss 6.7epss 0.00

    Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.

  • CVE-2024-56334HigDec 20, 2024
    risk 0.44cvss 7.8epss 0.01

    systeminformation is a System and OS information library for node.js. In affected versions SSIDs are not sanitized when before they are passed as a parameter to cmd.exe in the `getWindowsIEEE8021x` function. This means that malicious content in the SSID can be executed as OS…

  • CVE-2024-30964HigDec 5, 2024
    risk 0.44cvss 7.8epss 0.00

    Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_navigator

  • CVE-2024-42598MedAug 20, 2024
    risk 0.44cvss 6.7epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_editplayer.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2023-33206MedAug 8, 2024
    risk 0.44cvss 6.8epss 0.00

    Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of…

  • CVE-2024-36078MedMay 19, 2024
    risk 0.44cvss 6.7epss 0.00

    In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with the environment and permissions of the…

  • CVE-2024-25624MedApr 25, 2024
    risk 0.44cvss 6.8epss 0.01

    Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation…

  • CVE-2023-51797MedApr 19, 2024
    risk 0.44cvss 6.7epss 0.00

    Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame

  • CVE-2023-47542MedApr 9, 2024
    risk 0.44cvss 6.7epss 0.00

    A improper neutralization of special elements used in a template engine [CWE-1336] in FortiManager versions 7.4.1 and below, versions 7.2.4 and below, and 7.0.10 and below allows attacker to execute unauthorized code or commands via specially crafted templates.

  • CVE-2023-51820MedFeb 2, 2024
    risk 0.44cvss 6.8epss 0.00

    An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.

  • CVE-2022-42045MedJul 13, 2023
    risk 0.44cvss 6.7epss 0.01

    Certain Zemana products are vulnerable to Arbitrary code injection. This affects Watchdog Anti-Malware 4.1.422 and Zemana AntiMalware 3.2.28.

  • CVE-2023-37199MedJul 12, 2023
    risk 0.44cvss 6.8epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.

  • CVE-2023-37198MedJul 12, 2023
    risk 0.44cvss 6.8epss 0.01

    A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.

  • CVE-2023-26060MedApr 24, 2023
    risk 0.44cvss 6.8epss 0.01

    An issue was discovered in Nokia NetAct before 22 FP2211. On the Working Set Manager page, users can create a Working Set with a name that has a client-side template injection payload. Input validation is missing during creation of the working set. For an external attacker, it…

  • CVE-2022-43486MedDec 19, 2022
    risk 0.44cvss 6.8epss 0.00

    Hidden functionality vulnerability in Buffalo network devices allows a network-adjacent attacker with an administrative privilege to enable the debug functionalities and execute an arbitrary command on the affected devices.