CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,325)
page 26 of 367| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2025-27678 | Cri | 0.64 | 9.8 | 0.01 | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001. | ||
| CVE-2025-27657 | Cri | 0.64 | 9.8 | 0.02 | Mar 5, 2025 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008. | ||
| CVE-2025-27554 | Cri | 0.64 | 9.9 | 0.01 | Mar 1, 2025 | ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a… | ||
| CVE-2025-25789 | Cri | 0.64 | 9.8 | 0.01 | Feb 26, 2025 | FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php. | ||
| CVE-2025-26014 | Cri | 0.64 | 9.8 | 0.01 | Feb 21, 2025 | A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter. | ||
| CVE-2025-25675 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2025 | Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,… | ||
| CVE-2024-54756 | Cri | 0.64 | 9.8 | 0.03 | Feb 20, 2025 | A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file. | ||
| CVE-2024-57401 | Cri | 0.64 | 9.8 | 0.01 | Feb 20, 2025 | SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function. | ||
| CVE-2025-25467 | — | Cri | 0.64 | 9.8 | 0.01 | Feb 18, 2025 | Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file. | |
| CVE-2024-12366 | Cri | 0.64 | 9.8 | 0.01 | Feb 11, 2025 | PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM. | ||
| CVE-2024-57707 | Cri | 0.64 | 9.8 | 0.01 | Feb 7, 2025 | An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components. | ||
| CVE-2025-24677 | Cri | 0.64 | 9.9 | 0.01 | Feb 4, 2025 | Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.3. | ||
| CVE-2025-22204 | Cri | 0.64 | 9.8 | 0.01 | Feb 4, 2025 | Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability. | ||
| CVE-2024-57099 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2025 | ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server. | ||
| CVE-2024-49747 | Cri | 0.64 | 9.8 | 0.00 | Jan 21, 2025 | In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation. | ||
| CVE-2024-24421 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2025 | A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet. | ||
| CVE-2024-42936 | Cri | 0.64 | 9.8 | 0.01 | Jan 21, 2025 | The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message. | ||
| CVE-2025-22906 | Cri | 0.64 | 9.8 | 0.02 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN. | ||
| CVE-2025-22905 | Cri | 0.64 | 9.8 | 0.05 | Jan 16, 2025 | RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp. | ||
| CVE-2025-22968 | Cri | 0.64 | 9.8 | 0.03 | Jan 15, 2025 | An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions |
- risk 0.64cvss 9.8epss 0.01
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.
- risk 0.64cvss 9.8epss 0.02
Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.
- risk 0.64cvss 9.9epss 0.01
ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a…
- risk 0.64cvss 9.8epss 0.01
FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.
- risk 0.64cvss 9.8epss 0.01
A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.
- risk 0.64cvss 9.8epss 0.01
Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,…
- risk 0.64cvss 9.8epss 0.03
A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.
- risk 0.64cvss 9.8epss 0.01
Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.
- risk 0.64cvss 9.8epss 0.01
PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.
- risk 0.64cvss 9.8epss 0.01
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
- risk 0.64cvss 9.9epss 0.01
Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.3.
- risk 0.64cvss 9.8epss 0.01
Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.
- risk 0.64cvss 9.8epss 0.01
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.
- risk 0.64cvss 9.8epss 0.00
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.
- risk 0.64cvss 9.8epss 0.01
A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.
- risk 0.64cvss 9.8epss 0.01
The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.
- risk 0.64cvss 9.8epss 0.02
RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.
- risk 0.64cvss 9.8epss 0.05
RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.
- risk 0.64cvss 9.8epss 0.03
An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions