VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,045)

page 165 of 353
  • CVE-2023-6395MedJan 16, 2024
    risk 0.37cvss 6.7epss 0.02

    The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing during the expansion and execution of…

  • CVE-2023-1178MedMay 3, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source code or installation packages are pulled…

  • CVE-2023-1708MedApr 5, 2023
    risk 0.37cvss 5.7epss 0.01

    An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be executed on victim machine.

  • CVE-2021-4178MedAug 24, 2022
    risk 0.37cvss 6.7epss 0.00

    A arbitrary code execution flaw was found in the Fabric 8 Kubernetes client affecting versions 5.0.0-beta-1 and above. Due to an improperly configured YAML parsing, this will allow a local and privileged attacker to supply malicious YAML.

  • CVE-2022-0921MedMar 11, 2022
    risk 0.37cvss 6.7epss 0.02

    Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.

  • CVE-2021-23814MedDec 17, 2021
    risk 0.37cvss 6.7epss 0.02

    This affects versions of the package unisharp/laravel-filemanager before 2.6.2. The upload() function does not sufficiently validate the file type when uploading. An attacker may be able to reproduce the following steps: 1. Install a package with a web Laravel application. 2.…

  • CVE-2011-1830MedApr 22, 2019
    risk 0.37cvss 5.7epss 0.01

    Ekiga versions before 3.3.0 attempted to load a module from /tmp/ekiga_test.so.

  • CVE-2017-1721MedApr 26, 2018
    risk 0.37cvss 5.6epss 0.01

    IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810.

  • CVE-2026-19964MedAug 17, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was found in Jij-Inc Jij-MCP-Server 0.1.0. This affects the function PythonREPL.run of the file jij_mcp/python_repr.py of the component jm_check. The manipulation of the argument code results in code injection. It is possible to launch the attack remotely. The…

  • CVE-2026-18942MedAug 10, 2026
    risk 0.36cvss 5.5epss 0.00

    A flaw was found in the Feast operator. A malicious tenant could inject arbitrary code into their feature repository. This code would be executed by an automated process with elevated privileges, allowing the tenant to steal sensitive credentials. This could lead to a direct…

  • CVE-2026-10688MedJun 2, 2026
    risk 0.36cvss 5.5epss 0.00

    A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py. This manipulation of the argument code causes code injection. The attack is…

  • CVE-2026-35197MedApr 6, 2026
    risk 0.36cvss 6.6epss 0.00

    dye is a portable and respectful color library for shell scripts. Prior to 1.1.1, certain dye template expressions would result in execution of arbitrary code. This issue was discovered and fixed by dye's author, and is not known to be exploited. This vulnerability is fixed in…

  • CVE-2024-13785MedMar 21, 2026
    risk 0.36cvss 5.6epss 0.00

    The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.2. This is due to the software allowing users to execute an action that does not properly validate a…

  • CVE-2025-12843MedDec 12, 2025
    risk 0.36cvss 5.5epss 0.00

    Code Injection using Electron Fuses in waveterm on MacOS allows TCC Bypass. This issue affects waveterm: 0.12.2.

  • CVE-2025-42947MedJul 23, 2025
    risk 0.36cvss 5.5epss 0.00

    SAP FICA ODN framework allows a high privileged user to inject value inside the local variable which can then be executed by the application. An attacker could thereby control the behaviour of the application causing high impact on integrity, low impact on availability and no…

  • CVE-2025-6101MedJun 16, 2025
    risk 0.36cvss 5.5epss 0.00

    A vulnerability classified as critical has been found in letta-ai letta up to 0.4.1. Affected is the function function_message of the file letta/letta/interface.py. The manipulation of the argument function_name/function_args leads to improper neutralization of directives in…

  • CVE-2025-47691MedMay 7, 2025
    risk 0.36cvss 5.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Ultimate Member Ultimate Member ultimate-member allows Code Injection.This issue affects Ultimate Member: from n/a through <= 2.10.3.

  • CVE-2024-50405MedMar 7, 2025
    risk 0.36cvss 5.5epss 0.00

    An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator access to modify application data. We…

  • CVE-2024-55504MedJan 21, 2025
    risk 0.36cvss 5.5epss 0.01

    An issue in RAR Extractor - Unarchiver Free and Pro v.6.4.0 allows local attackers to inject arbitrary code potentially leading to remote control and unauthorized access to sensitive user data via the exploit_combined.dylib component on MacOS.

  • CVE-2024-35315MedOct 21, 2024
    risk 0.36cvss 5.6epss 0.01

    A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper file validation. A successful exploit…