VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 25 of 349
  • CVE-2024-55085CriDec 16, 2024
    risk 0.64cvss 9.8epss 0.01

    GetSimple CMS CE 3.3.19 suffers from arbitrary code execution in the template editing function in the background management system, which can be used by an attacker to implement RCE.

  • CVE-2022-38946CriDec 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary File Upload vulnerability in Doctor-Appointment version 1.0 in /Frontend/signup_com.php, allows attackers to execute arbitrary code.

  • CVE-2024-48453CriDec 4, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function

  • CVE-2024-53604CriNov 27, 2024
    risk 0.64cvss 9.8epss 0.01

    A SQL Injection vulnerability was found in /covid-tms/check_availability.php in PHPGurukul COVID 19 Testing Management System v1.0, which allows remote attackers to execute arbitrary code via the mobnumber POST request parameter.

  • CVE-2024-51367CriNov 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.

  • CVE-2024-48694CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.01

    File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.

  • CVE-2024-48070CriNov 19, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges

  • CVE-2024-50919CriNov 18, 2024
    risk 0.64cvss 9.8epss 0.01

    Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution

  • CVE-2024-52427CriNov 18, 2024
    risk 0.64cvss 9.9epss 0.01

    Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a through <= 2.3.11.

  • CVE-2024-44758CriNov 15, 2024
    risk 0.64cvss 9.8epss 0.01

    An arbitrary file upload vulnerability in the component /Production/UploadFile of NUS-M9 ERP Management Software v3.0.0 allows attackers to execute arbitrary code via uploading crafted files.

  • CVE-2024-50636CriNov 11, 2024
    risk 0.64cvss 9.8epss 0.01

    PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and exploit the function to achieve Remote…

  • CVE-2024-48061CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.

  • CVE-2024-48050CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.

  • CVE-2024-10035CriNov 4, 2024
    risk 0.64cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Special Elements used in a Command ('Command Injection'), Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in BG-TEK Informatics Security…

  • CVE-2024-48359CriOct 31, 2024
    risk 0.64cvss 9.8epss 0.02

    Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.

  • CVE-2024-51427CriOct 30, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to function calls.

  • CVE-2024-51424CriOct 30, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limited to function calls.

  • CVE-2024-51298CriOct 30, 2024
    risk 0.64cvss 9.8epss 0.01

    In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.

  • CVE-2024-48138CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.

  • CVE-2024-8923CriOct 29, 2024
    risk 0.64cvss 9.8epss 0.01

    ServiceNow has addressed an input validation vulnerability that was identified in the Now Platform. This vulnerability could enable an unauthenticated user to remotely execute code within the context of the Now Platform. ServiceNow deployed an update to hosted instances and…