VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,047)

page 176 of 353
  • CVE-2021-4315MedJan 28, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/experiment.py. The manipulation of the argument mode leads to improper neutralization of special elements used in a template…

  • CVE-2015-10009MedJan 2, 2023
    risk 0.29cvss 5.5epss 0.01

    A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/controllers/code_caller_controller.php. The manipulation of the argument q with the input %5C%27%29;phpinfo%28%29;/* leads to code…

  • CVE-2022-33721MedAug 5, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.

  • CVE-2022-27837MedApr 11, 2022
    risk 0.29cvss 4.4epss 0.01

    A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.

  • CVE-2022-23434MedFeb 11, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in Bixby Vision prior to versions 3.7.60.8 in Android S(12), 3.7.50.6 in Andorid R(11) and below allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2022-23426MedFeb 11, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in DeX Home and DeX for PC prior to SMR Feb-2022 Release 1 allows attackers to access files with system privilege.

  • CVE-2022-22286MedJan 10, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2022-22285MedJan 10, 2022
    risk 0.29cvss 4.4epss 0.00

    A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.

  • CVE-2022-22270MedJan 10, 2022
    risk 0.29cvss 4.4epss 0.00

    An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.

  • CVE-2021-25411MedJun 11, 2021
    risk 0.29cvss 4.4epss 0.00

    Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.

  • CVE-2017-1336MedDec 7, 2017
    risk 0.29cvss 4.4epss 0.01

    IBM Infosphere BigInsights 4.2.0 could allow an attacker to inject code that could allow access to restricted data and files. IBM X-Force ID: 126244.

  • CVE-2005-1876MedJun 9, 2005
    risk 0.29cvss 4.5epss 0.01

    Direct code injection vulnerability in CuteNews 1.3.6 and earlier allows remote attackers with administrative privileges to execute arbitrary PHP code via certain inputs that are injected into a template (.tpl) file.

  • CVE-2026-78060MedAug 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in SourceCodester Stock Management System 1.0. This issue affects some unknown processing of the file /php_action/getOrderReport.php. Performing a manipulation of the argument clientName/clientContact results in cross site scripting. It is possible to…

  • CVE-2026-78059MedAug 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability has been found in SourceCodester Stock Management System 1.0. This vulnerability affects unknown code of the file /php_action/printOrder.php. Such manipulation of the argument clientName/clientContact leads to cross site scripting. The attack may be performed…

  • CVE-2026-78055MedAug 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A security vulnerability has been detected in SourceCodester Class and Exam Timetabling System 1.0. Affected by this vulnerability is an unknown functionality of the file /BSIT2.php. The manipulation of the argument course leads to cross site scripting. Remote exploitation of…

  • CVE-2026-78054MedAug 23, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /BSIS1.php. Executing a manipulation of the argument course can lead to cross site scripting. The attack may be launched remotely. The exploit has…

  • CVE-2026-75078MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown part of the file /BSHRM1.php. Performing a manipulation of the argument course results in cross site scripting. Remote exploitation of the attack is possible. The…

  • CVE-2026-75077MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /BSCE2.php. Such manipulation of the argument course leads to cross site scripting. The attack may be launched remotely. The…

  • CVE-2026-19998MedAug 17, 2026
    risk 0.28cvss 4.3epss 0.00

    A weakness has been identified in code-projects Online Shopping System 1.0. Impacted is an unknown function of the file offersmail.php. Executing a manipulation of the argument email can lead to cross site scripting. The attack may be performed from remote. The exploit has been…

  • CVE-2026-19378MedAug 10, 2026
    risk 0.28cvss 4.3epss 0.00

    A vulnerability was found in code-projects Task Management System 1.0. This issue affects some unknown processing of the file /user/CommentSave.php. The manipulation of the argument comment/task_id/mineId/recId/myName/myImage results in cross site scripting. It is possible to…