VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,325)

page 26 of 367
  • CVE-2025-27678CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.01

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Client Remote Code Execution V-2023-001.

  • CVE-2025-27657CriMar 5, 2025
    risk 0.64cvss 9.8epss 0.02

    Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Remote Code Execution V-2023-008.

  • CVE-2025-27554CriMar 1, 2025
    risk 0.64cvss 9.9epss 0.01

    ToDesktop before 2024-10-03, as used by Cursor before 2024-10-03 and other applications, allows remote attackers to execute arbitrary commands on the build server (e.g., read secrets from the desktopify config.prod.json file), and consequently deploy updates to any app, via a…

  • CVE-2025-25789CriFeb 26, 2025
    risk 0.64cvss 9.8epss 0.01

    FoxCMS v1.2.5 was discovered to contain a remote code execution (RCE) vulnerability via the index() method at \controller\Sitemap.php.

  • CVE-2025-26014CriFeb 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A Remote Code Execution (RCE) vulnerability in Loggrove v.1.0 allows a remote attacker to execute arbitrary code via the path parameter.

  • CVE-2025-25675CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    Tenda AC10 V1.0 V15.03.06.23 has a command injection vulnerablility located in the formexeCommand function. The str variable receives the cmdinput parameter from a POST request and is later assigned to the cmd_buf variable, which is directly used in the doSystemCmd function,…

  • CVE-2024-54756CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.03

    A remote code execution (RCE) vulnerability in the ZScript function of ZDoom Team GZDoom v4.13.1 allows attackers to execute arbitrary code via supplying a crafted PK3 file containing a malicious ZScript source file.

  • CVE-2024-57401CriFeb 20, 2025
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.

  • CVE-2025-25467CriFeb 18, 2025
    risk 0.64cvss 9.8epss 0.01

    Insufficient tracking and releasing of allocated used memory in libx264 git master allows attackers to execute arbitrary code via creating a crafted AAC file.

  • CVE-2024-12366CriFeb 11, 2025
    risk 0.64cvss 9.8epss 0.01

    PandasAI uses an interactive prompt function that is vulnerable to prompt injection and run arbitrary Python code that can lead to Remote Code Execution (RCE) instead of the intended explanation of the natural language processing by the LLM.

  • CVE-2024-57707CriFeb 7, 2025
    risk 0.64cvss 9.8epss 0.01

    An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.

  • CVE-2025-24677CriFeb 4, 2025
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in wpspin Post/Page Copying Tool postpage-import-export-with-custom-fields-taxonomies allows Remote Code Inclusion.This issue affects Post/Page Copying Tool: from n/a through <= 2.0.3.

  • CVE-2025-22204CriFeb 4, 2025
    risk 0.64cvss 9.8epss 0.01

    Improper control of generation of code in the sourcerer extension for Joomla in versions before 11.0.0 lead to a remote code execution vulnerability.

  • CVE-2024-57099CriFeb 3, 2025
    risk 0.64cvss 9.8epss 0.01

    ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take control of the server.

  • CVE-2024-49747CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.00

    In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-24421CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.

  • CVE-2024-42936CriJan 21, 2025
    risk 0.64cvss 9.8epss 0.01

    The mqlink.elf is service component in Ruijie RG-EW300N with firmware ReyeeOS 1.300.1422 is vulnerable to Remote Code Execution via a modified MQTT broker message.

  • CVE-2025-22906CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.02

    RE11S v1.11 was discovered to contain a command injection vulnerability via the L2TPUserName parameter at /goform/setWAN.

  • CVE-2025-22905CriJan 16, 2025
    risk 0.64cvss 9.8epss 0.05

    RE11S v1.11 was discovered to contain a command injection vulnerability via the command parameter at /goform/mp.

  • CVE-2025-22968CriJan 15, 2025
    risk 0.64cvss 9.8epss 0.03

    An issue in D-Link DWR-M972V 1.05SSG allows a remote attacker to execute arbitrary code via SSH using root account without restrictions