VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 21 of 349
  • CVE-2025-45479CriJul 7, 2025
    risk 0.64cvss 9.8epss 0.01

    Insufficient security mechanisms for created containers in educoder challenges v1.0 allow attackers to execute arbitrary code via injecting crafted content into a container.

  • CVE-2025-34089CriJul 3, 2025
    risk 0.64cvss epss 0.01

    An unauthenticated remote code execution vulnerability exists in Remote for Mac, a macOS remote control utility developed by Aexol Studio, in versions up to and including 2025.7. When the application is configured with authentication disabled (i.e., the "Allow unknown devices"…

  • CVE-2025-34061CriJul 3, 2025
    risk 0.64cvss epss 0.01

    A backdoor in PHPStudy versions 2016 through 2018 allows unauthenticated remote attackers to execute arbitrary PHP code on affected installations. The backdoor listens for base64-encoded PHP payloads in the Accept-Charset HTTP header of incoming requests, decodes and executes…

  • CVE-2025-34074CriJul 2, 2025
    risk 0.64cvss epss 0.01

    An authenticated remote code execution vulnerability exists in Lucee’s administrative interface due to insecure design in the scheduled task functionality. An administrator with access to /lucee/admin/web.cfm can configure a scheduled job to retrieve a remote .cfm file from an…

  • CVE-2025-37099CriJul 1, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote code execution vulnerability exists in HPE Insight Remote Support (IRS) prior to v7.15.0.646.

  • CVE-2024-37743CriJun 24, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.

  • CVE-2023-47030CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code and obtain sensitive information via a GET request to a UserService SOAP API endpoint to validate if a user exists.

  • CVE-2023-47032CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    Password Vulnerability in NCR Terminal Handler v.1.5.1 allows a remote attacker to execute arbitrary code via a crafted script to the UserService SOAP API function.

  • CVE-2023-48978CriJun 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in NCR ITM Web terminal v.4.4.0 and v.4.4.4 allows a remote attacker to execute arbitrary code via a crafted script to the IP camera URL component.

  • CVE-2025-5309CriJun 16, 2025
    risk 0.64cvss 9.8epss 0.01

    The chat feature within Remote Support (RS) and Privileged Remote Access (PRA) is vulnerable to a Server-Side Template Injection vulnerability which can lead to remote code execution.

  • CVE-2025-28386CriJun 13, 2025
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability in the Plugin Management component of OpenC3 COSMOS v6.0.0 allows attackers to execute arbitrary code via uploading a crafted .txt file.

  • CVE-2025-48140CriJun 9, 2025
    risk 0.64cvss 9.9epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in metalpriceapi MetalpriceAPI metalpriceapi allows Code Injection.This issue affects MetalpriceAPI: from n/a through <= 1.1.4.

  • CVE-2025-49013CriJun 9, 2025
    risk 0.64cvss 9.9epss 0.01

    WilderForge is a Wildermyth coremodding API. A critical vulnerability has been identified in multiple projects across the WilderForge organization. The issue arises from unsafe usage of `${{ github.event.review.body }}` and other user controlled variables directly inside shell…

  • CVE-2025-32106CriJun 3, 2025
    risk 0.64cvss 9.8epss 0.01

    In Audiocodes Mediapack MP-11x through 6.60A.369.002, a crafted POST request request may result in an unauthenticated remote user's ability to execute unauthorized code.

  • CVE-2024-51360CriMay 23, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file

  • CVE-2025-44881CriMay 20, 2025
    risk 0.64cvss 9.8epss 0.02

    A command injection vulnerability in the component /cgi-bin/qos.cgi of Wavlink WL-WN579A3 v1.0 allows attackers to execute arbitrary commands via a crafted input.

  • CVE-2025-32363CriMay 14, 2025
    risk 0.64cvss 9.8epss 0.01

    mediDOK before 2.5.18.43 allows remote attackers to achieve remote code execution on a target system via deserialization of untrusted data.

  • CVE-2025-45857CriMay 13, 2025
    risk 0.64cvss 9.8epss 0.01

    EDIMAX CV7428NS v1.20 was discovered to contain a remote code execution (RCE) vulnerability via the command parameter in the mp function.

  • CVE-2025-46191CriMay 9, 2025
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and…

  • CVE-2025-26845CriMay 8, 2025
    risk 0.64cvss 9.8epss 0.00

    An Eval Injection issue was discovered in Znuny through 7.1.3. A user with write access to the configuration file can use this to execute a command executed by the user running the backup.pl script.