CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 27 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-6596 | Cri | 0.64 | 9.8 | 0.01 | Sep 10, 2024 | An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context. | ||
| CVE-2024-44411 | Cri | 0.64 | 9.8 | 0.04 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function. | ||
| CVE-2024-44410 | Cri | 0.64 | 9.8 | 0.03 | Sep 9, 2024 | D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function. | ||
| CVE-2024-39714 | Cri | 0.64 | 9.9 | 0.01 | Sep 7, 2024 | A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server. | ||
| CVE-2024-45507 | Cri | 0.64 | 9.8 | 0.93 | Sep 4, 2024 | Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue. | ||
| CVE-2024-45623 | Cri | 0.64 | 9.8 | 0.01 | Sep 2, 2024 | D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no… | ||
| CVE-2024-41369 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php | ||
| CVE-2024-41368 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php | ||
| CVE-2024-41367 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php | ||
| CVE-2024-41366 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php | ||
| CVE-2024-41364 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php | ||
| CVE-2024-41361 | Cri | 0.64 | 9.8 | 0.01 | Aug 29, 2024 | RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php | ||
| CVE-2024-7720 | Cri | 0.64 | 9.8 | 0.01 | Aug 27, 2024 | HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries. | ||
| CVE-2024-42634 | Cri | 0.64 | 9.8 | 0.02 | Aug 16, 2024 | A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges. | ||
| CVE-2024-41623 | Cri | 0.64 | 9.8 | 0.01 | Aug 13, 2024 | An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload | ||
| CVE-2024-22116 | Cri | 0.64 | 9.9 | 0.02 | Aug 12, 2024 | An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising… | ||
| CVE-2024-42393 | Cri | 0.64 | 9.8 | 0.01 | Aug 6, 2024 | There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system… | ||
| CVE-2024-41468 | Cri | 0.64 | 9.8 | 0.05 | Jul 25, 2024 | Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand | ||
| CVE-2024-21552 | Cri | 0.64 | 9.8 | 0.01 | Jul 22, 2024 | All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server. | ||
| CVE-2024-39962 | Cri | 0.64 | 9.8 | 0.02 | Jul 19, 2024 | D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request. |
- risk 0.64cvss 9.8epss 0.01
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- risk 0.64cvss 9.8epss 0.04
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the msp_info_htm function.
- risk 0.64cvss 9.8epss 0.03
D-Link DI-8300 v16.07.26A1 is vulnerable to command injection via the upgrade_filter_asp function.
- risk 0.64cvss 9.9epss 0.01
A code injection vulnerability that permits a low-privileged user to upload arbitrary files to the server, leading to remote code execution on VSPC server.
- risk 0.64cvss 9.8epss 0.93
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.
- risk 0.64cvss 9.8epss 0.01
D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no…
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php
- risk 0.64cvss 9.8epss 0.01
RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php
- risk 0.64cvss 9.8epss 0.01
HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.
- risk 0.64cvss 9.8epss 0.02
A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.
- risk 0.64cvss 9.8epss 0.01
An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload
- risk 0.64cvss 9.9epss 0.02
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising…
- risk 0.64cvss 9.8epss 0.01
There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…
- risk 0.64cvss 9.8epss 0.05
Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand
- risk 0.64cvss 9.8epss 0.01
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.
- risk 0.64cvss 9.8epss 0.02
D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.