VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 23 of 349
  • CVE-2025-30911CriApr 1, 2025
    risk 0.64cvss 9.9epss 0.02

    Improper Control of Generation of Code ('Code Injection') vulnerability in Rometheme RTMKit rometheme-for-elementor allows Command Injection.This issue affects RTMKit: from n/a through <= 1.5.4.

  • CVE-2024-54807CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    In Netgear WNR854T 1.5.2 (North America), the UPNP service is vulnerable to command injection in the function addmap_exec which parses the NewInternalClient parameter of the AddPortMapping SOAPAction into a system call without sanitation. An attacker can send a specially crafted…

  • CVE-2024-54806CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.01

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Arbitrary command execution in cmd.cgi which allows for the execution of system commands via the web interface.

  • CVE-2024-54805CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter get_email. After which, they can visit the send_log.cgi endpoint which uses the parameter in a system call to…

  • CVE-2024-54804CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter wan_hostname and forcing a reboot. This will result in command injection.

  • CVE-2024-54803CriMar 31, 2025
    risk 0.64cvss 9.8epss 0.02

    Netgear WNR854T 1.5.2 (North America) is vulnerable to Command Injection. An attacker can send a specially crafted request to post.cgi, updating the nvram parameter pppoe_peer_mac and forcing a reboot. This will result in command injection.

  • CVE-2025-26003CriMar 26, 2025
    risk 0.64cvss 9.8epss 0.01

    Telesquare TLR-2005KSH 1.1.4 is affected by an unauthorized command execution vulnerability when requesting the admin.cgi parameter with setAutorest.

  • CVE-2025-28893CriMar 26, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Govind Visual Text Editor visual-text-editor allows Remote Code Inclusion.This issue affects Visual Text Editor: from n/a through <= 1.2.1.

  • CVE-2024-55028CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    A template injection vulnerability in the Dashboard of NASA Fprime v3.4.3 allows attackers to execute arbitrary code via uploading a crafted Vue file.

  • CVE-2024-48818CriMar 25, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.

  • CVE-2024-57061CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.

  • CVE-2025-29401CriMar 19, 2025
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /views/plugin.php of emlog pro v2.5.7 allows attackers to execute arbitrary code via uploading a crafted PHP file.

  • CVE-2024-42733CriMar 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in Docmosis Tornado v.2.9.7 and before allows a remote attacker to execute arbitrary code via a crafted script to the UNC path input

  • CVE-2025-27678CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.

  • CVE-2025-27657CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

  • CVE-2025-27554CriMar 1, 2025
    risk 0.64cvss 9.9epss 0.01

    ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a…

  • CVE-2025-25789CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

  • CVE-2025-26014CriFeb 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.

  • CVE-2025-25675CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,…

  • CVE-2024-54756CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.