VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 24 of 349
  • CVE-2024-57401CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.

  • CVE-2025-25467CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

  • CVE-2024-12366CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.

  • CVE-2024-57707CriFeb 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

  • CVE-2025-24677CriFeb 4, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.3.

  • CVE-2025-22204CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

  • CVE-2024-57099CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

  • CVE-2024-49747CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.00

    In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-24421CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2024-42936CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

  • CVE-2025-22906CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

  • CVE-2025-22905CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.05

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

  • CVE-2025-22968CriJan 15, 2025
    risk 0.64cvss 9.8epss 0.03

    An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions

  • CVE-2023-28354CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control characters and pass them to command-line…

  • CVE-2024-54724CriJan 9, 2025
    risk 0.64cvss 9.8epss 0.01

    PHPYun before 7.0.2 is vulnerable to code execution through backdoor-restricted arbitrary file writing and file inclusion.

  • CVE-2024-11635CriJan 8, 2025
    risk 0.64cvss 9.8epss 0.01

    The WordPress File Upload plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.24.12 via the 'wfu_ABSPATH' cookie parameter. This makes it possible for unauthenticated attackers to execute code on the server.

  • CVE-2024-50660CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality

  • CVE-2024-50658CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file

  • CVE-2024-12252CriJan 7, 2025
    risk 0.64cvss 9.8epss 0.03

    The SEO LAT Auto Post plugin for WordPress is vulnerable to file overwrite due to a missing capability check on the remote_update AJAX action in all versions up to, and including, 2.2.1. This makes it possible for unauthenticated attackers to overwrite the…

  • CVE-2024-55529CriJan 6, 2025
    risk 0.64cvss 9.8epss 0.01

    Z-BlogPHP 1.7.3 is vulnerable to arbitrary code execution via \zb_users\theme\shell\template.