VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 147 of 353
  • CVE-2026-28801MedMar 6, 2026
    risk 0.43cvss 6.6epss 0.00

    Natro Macro is an open-source Bee Swarm Simulator macro written in AutoHotkey. Prior to version 1.1.0, any ahk code contained inside of a pattern or path file is executed by the macro. Since users commonly share path/pattern files, an attacker could share a file containing…

  • CVE-2026-25153HigJan 30, 2026
    risk 0.43cvss 7.7epss 0.01

    Backstage is an open framework for building developer portals, and @backstage/plugin-techdocs-node provides common node.js functionalities for TechDocs. In versions of @backstage/plugin-techdocs-node prior to 1.13.11 and 1.14.1, when TechDocs is configured with `runIn: local`, a…

  • CVE-2025-60114MedSep 26, 2025
    risk 0.43cvss 6.6epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in YayCommerce YayCurrency yaycurrency allows Code Injection.This issue affects YayCurrency: from n/a through <= 3.3.1.

  • CVE-2025-27218MedFeb 20, 2025
    risk 0.43cvss 5.3epss 0.65

    Sitecore Experience Manager (XM) and Experience Platform (XP) 10.4 before KB1002844 allow remote code execution through insecure deserialization.

  • CVE-2024-41712MedOct 21, 2024
    risk 0.43cvss 6.6epss 0.01

    A vulnerability in the Web Conferencing Component of Mitel MiCollab through 9.8.1.5 could allow an authenticated attacker to conduct a command injection attack, due to insufficient validation of user input. A successful exploit could allow an attacker to execute arbitrary…

  • CVE-2023-31493MedOct 15, 2024
    risk 0.43cvss 6.6epss 0.00

    RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote system.

  • CVE-2024-41997MedOct 14, 2024
    risk 0.43cvss 6.6epss 0.01

    An issue was discovered in version of Warp Terminal prior to 2024.07.18 (v0.2024.07.16.08.02). A command injection vulnerability exists in the Docker integration functionality. An attacker can create a specially crafted hyperlink using the `warp://action/docker/open_subshell`…

  • CVE-2024-45933MedOct 7, 2024
    risk 0.43cvss 6.6epss 0.00

    OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.

  • CVE-2024-31396MedMay 22, 2024
    risk 0.43cvss 6.6epss 0.00

    Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can log in to the product may execute an…

  • CVE-2024-3788MedMay 14, 2024
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

  • CVE-2024-3787MedMay 14, 2024
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

  • CVE-2024-3786MedApr 15, 2024
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

  • CVE-2024-3785MedApr 15, 2024
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

  • CVE-2024-3784MedApr 15, 2024
    risk 0.43cvss 6.6epss 0.01

    Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.

  • CVE-2024-22724MedMar 21, 2024
    risk 0.43cvss 6.6epss 0.00

    An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.

  • CVE-2024-25359MedMar 21, 2024
    risk 0.43cvss 6.6epss 0.00

    An issue in zuoxingdong lagom v.0.1.2 allows a local attacker to execute arbitrary code via the pickle_load function of the serialize.py file.

  • CVE-2024-0195MedJan 2, 2024
    risk 0.43cvss 6.3epss 0.19

    A vulnerability, which was classified as critical, was found in spider-flow 0.4.3. Affected is the function FunctionService.saveFunction of the file src/main/java/org/spiderflow/controller/FunctionController.java. The manipulation leads to code injection. It is possible to…

  • CVE-2021-22150MedNov 22, 2023
    risk 0.43cvss 6.6epss 0.01

    It was discovered that a user with Fleet admin permissions could upload a malicious package. Due to using an older version of the js-yaml library, this package would be loaded in an insecure manner, allowing an attacker to execute commands on the Kibana server.

  • CVE-2023-36022MedNov 3, 2023
    risk 0.43cvss 6.6epss 0.01

    Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

  • CVE-2022-29171MedMay 6, 2022
    risk 0.43cvss 6.6epss 0.01

    Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site admins to specify a `callsignCommand`,…