VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 20 of 349
  • CVE-2024-52786CriAug 22, 2025
    risk 0.64cvss 9.8epss 0.01

    An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.

  • CVE-2025-48169CriAug 20, 2025
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in Jordy Meow Code Engine code-engine allows Remote Code Inclusion.This issue affects Code Engine: from n/a through <= 0.3.3.

  • CVE-2025-49887CriAug 14, 2025
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in WPFactory Product XML Feed Manager for WooCommerce product-xml-feeds-for-woocommerce allows Remote Code Inclusion.This issue affects Product XML Feed Manager for WooCommerce: from n/a through <= 2.9.3.

  • CVE-2025-52385CriAug 13, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Studio 3T v.2025.1.0 and before allows a remote attacker to execute arbitrary code via a crafted payload to the child_process module

  • CVE-2025-42957CriAug 12, 2025
    risk 0.64cvss 9.9epss 0.02

    SAP S/4HANA allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability effectively functions as a…

  • CVE-2025-42950CriAug 12, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP Landscape Transformation (SLT) allows an attacker with user privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code into the system, bypassing essential authorization checks. This vulnerability…

  • CVE-2025-50692CriAug 7, 2025
    risk 0.64cvss 9.8epss 0.01

    FoxCMS <=v1.2.5 is vulnerable to Code Execution in admin/template_file/editFile.html.

  • CVE-2025-50707CriAug 5, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in thinkphp3 v.3.2.5 allows a remote attacker to execute arbitrary code via the index.php component

  • CVE-2025-50706CriAug 5, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in thinkphp v.5.1 allows a remote attacker to execute arbitrary code via the routecheck function

  • CVE-2025-51387CriAug 4, 2025
    risk 0.64cvss 9.8epss 0.01

    The GitKraken Desktop 10.8.0 and 11.1.0 is susceptible to code injection due to misconfigured Electron Fuses. Specifically, the following insecure settings were observed: RunAsNode is enabled and EnableNodeCliInspectArguments is not disabled. These configurations allow the…

  • CVE-2025-46059CriJul 29, 2025
    risk 0.64cvss 9.8epss 0.01

    langchain-ai v0.3.51 was discovered to contain an indirect prompt injection vulnerability in the GmailToolkit component. This vulnerability allows attackers to execute arbitrary code and compromise the application via a crafted email message. NOTE: this is disputed by the…

  • CVE-2025-29631CriJul 25, 2025
    risk 0.64cvss 9.8epss 0.02

    Gardyn Home Kit firmware before master.619, Home Kit Mobile Application before 2.11.0, and Home Kit Cloud API before 2.12.2026 allow command injection through vulnerable methods that do not sanitize input before passing content to the operating system for execution. The…

  • CVE-2016-15044CriJul 23, 2025
    risk 0.64cvss epss 0.01

    A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sending a specially crafted serialized PHP…

  • CVE-2018-25114CriJul 23, 2025
    risk 0.64cvss epss 0.03

    A remote code execution vulnerability exists within osCommerce Online Merchant version 2.3.4.1 due to insecure default configuration and missing authentication in the installer workflow. By default, the /install/ directory remains accessible after installation. An…

  • CVE-2025-54451CriJul 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Samsung Electronics MagicINFO 9 Server allows Code Injection.This issue affects MagicINFO 9 Server: less than 21.1080.0.

  • CVE-2025-53867CriJul 17, 2025
    risk 0.64cvss 9.8epss 0.01

    Island Lake WebBatch before 2025C allows Remote Code Execution via a crafted URL.

  • CVE-2025-5396CriJul 17, 2025
    risk 0.64cvss 9.8epss 0.01

    The Bears Backup plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.0. This is due to the bbackup_ajax_handle() function not having a capability check, nor validating user supplied input passed directly to call_user_func(). This…

  • CVE-2025-34127CriJul 16, 2025
    risk 0.64cvss epss 0.01

    A stack-based buffer overflow exists in Achat v0.150 in its default configuration. By sending a specially crafted message to the UDP port 9256, an attacker can overwrite the structured exception handler (SEH) due to insufficient bounds checking on user-supplied input leading to…

  • CVE-2025-5392CriJul 11, 2025
    risk 0.64cvss 9.8epss 0.01

    The GB Forms DB plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.0.2 via the gbfdb_talk_to_front() function. This is due to the function accepting user input and then passing that through call_user_func(). This makes it possible…

  • CVE-2025-42967CriJul 8, 2025
    risk 0.64cvss 9.9epss 0.01

    SAP S/4HANA and SAP SCM Characteristic Propagation has remote code execution vulnerability. This allows an attacker with user level privileges to create a new report with his own code potentially gaining full control of the affected SAP system causing high impact on…