VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 19 of 349
  • CVE-2025-67164CriDec 17, 2025
    risk 0.64cvss 9.9epss 0.01

    An authenticated arbitrary file upload vulnerability in the /storage/poc.php component of Pagekit CMS v1.0.18 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2025-46295CriDec 16, 2025
    risk 0.64cvss 9.8epss 0.01

    Apache Commons Text versions prior to 1.10.0 included interpolation features that could be abused when applications passed untrusted input into the text-substitution API. Because some interpolators could trigger actions like executing commands or accessing external resources, an…

  • CVE-2025-65854CriDec 12, 2025
    risk 0.64cvss 9.8epss 0.00

    Insecure permissions in the scheduled tasks feature of MineAdmin v3.x allows attackers to execute arbitrary commands and execute a full account takeover.

  • CVE-2025-65294CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Aqara Hub devices including Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027, and Hub M3 4.3.6_0025 contain an undocumented remote access mechanism enabling unrestricted remote command execution.

  • CVE-2025-65602CriDec 10, 2025
    risk 0.64cvss 9.8epss 0.01

    A template injection vulnerability in the /vip/v1/file/save component of ChanCMS v3.3.4 allows attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-14324CriDec 9, 2025
    risk 0.64cvss 9.8epss 0.01

    JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 146, Firefox ESR 115.31, Firefox ESR 140.6, Thunderbird 146, and Thunderbird 140.6.

  • CVE-2025-65099CriNov 19, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. Prior to version 1.0.39, when running on a machine with Yarn 3.0 or above, Claude Code could have been tricked to execute code contained in a project via yarn plugins before the user accepted the startup trust dialog. Exploiting this would…

  • CVE-2025-12813CriNov 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The Holiday class post calendar plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 7.1 via the 'contents' parameter. This is due to a lack of sanitization of user-supplied data when creating a cache file. This makes it possible for…

  • CVE-2025-42887CriNov 11, 2025
    risk 0.64cvss 9.9epss 0.01

    Due to missing input sanitation, SAP Solution Manager allows an authenticated attacker to insert malicious code when calling a remote-enabled function module. This could provide the attacker with full control of the system hence leading to high impact on confidentiality,…

  • CVE-2025-32222CriNov 6, 2025
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Widgetlogic.org Widget Logic widget-logic allows Code Injection.This issue affects Widget Logic: from n/a through <= 6.0.5.

  • CVE-2025-34277CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.02

    Nagios Log Server versions prior to 2024R1.3.1 contain a code injection vulnerability where malformed dashboard ID values are not properly validated before being forwarded to an internal API. An attacker able to supply crafted dashboard ID values can cause the system to…

  • CVE-2025-50739CriOct 30, 2025
    risk 0.64cvss 9.8epss 0.01

    iib0011 omni-tools v0.4.0 is vulnerable to remote code execution via unsafe JSON deserialization.

  • CVE-2025-46581CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.01

    ZTE's ZXCDN product is affected by a Struts remote code execution (RCE) vulnerability. An unauthenticated attacker can remotely execute commands with non-root privileges.

  • CVE-2025-59041CriSep 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. At startup, Claude Code executed a command templated in with `git config user.email`. Prior to version 1.0.105, a maliciously configured user email in git could be used to trigger arbitrary code execution before a user accepted the…

  • CVE-2025-58764CriSep 10, 2025
    risk 0.64cvss 9.8epss 0.01

    Claude Code is an agentic coding tool. Due to an error in command parsing, versions prior to 1.0.105 were vulnerable to a bypass of the Claude Code confirmation prompt to trigger execution of an untrusted command. Reliably exploiting this requires the ability to add untrusted…

  • CVE-2025-42922CriSep 9, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP NetWeaver AS Java allows an attacker authenticated as a non-administrative user to use a flaw in an available service to upload an arbitrary file. This file when executed can lead to a full compromise of confidentiality, integrity and availability of the system.

  • CVE-2025-58745CriSep 8, 2025
    risk 0.64cvss 9.9epss 0.01

    WeGIA is a Web manager for charitable institutions. The fix for CVE-2025-22133 was not enough to remediate the arbitrary file upload vulnerability. The WeGIA only check MIME types for Excel files at endpoint `/html/socio/sistema/controller/controla_xlsx.php`, which can be…

  • CVE-2025-57141CriSep 8, 2025
    risk 0.64cvss 9.8epss 0.01

    rsbi-os 4.7 is vulnerable to Remote Code Execution (RCE) in sqlite-jdbc.

  • CVE-2025-58159CriAug 29, 2025
    risk 0.64cvss 9.9epss 0.01

    WeGIA is a Web manager for charitable institutions. Prior to version 3.4.11, a remote code execution vulnerability was identified, caused by improper validation of uploaded files. The application allows an attacker to upload files with arbitrary filenames, including those with a…

  • CVE-2025-52122CriAug 27, 2025
    risk 0.64cvss 9.8epss 0.01

    Freeform 5.0.0 to before 5.10.16, a plugin for CraftCMS, contains an Server-side template injection (SSTI) vulnerability, resulting in arbitrary code injection for all users that have access to editing a form (submission title).