VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,295)

page 29 of 365
  • CVE-2024-45507CriSep 4, 2024
    risk 0.64cvss 9.8epss 0.93

    Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.16. Users are recommended to upgrade to version 18.12.16, which fixes the issue.

  • CVE-2024-45623CriSep 2, 2024
    risk 0.64cvss 9.8epss 0.01

    D-Link DAP-2310 Hardware A Firmware 1.16RC028 allows remote attackers to execute arbitrary code via a stack-based buffer overflow in the ATP binary that handles PHP HTTP GET requests for the Apache HTTP Server (httpd). NOTE: This vulnerability only affects products that are no…

  • CVE-2024-41369CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWifi.php

  • CVE-2024-41368CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\inc.setWlanIpMail.php

  • CVE-2024-41367CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\api\playlist\appendFileToPlaylist.php

  • CVE-2024-41366CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\userScripts.php

  • CVE-2024-41364CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\trackEdit.php

  • CVE-2024-41361CriAug 29, 2024
    risk 0.64cvss 9.8epss 0.01

    RPi-Jukebox-RFID v2.7.0 was discovered to contain a remote code execution (RCE) vulnerability via htdocs\manageFilesFolders.php

  • CVE-2024-7720CriAug 27, 2024
    risk 0.64cvss 9.8epss 0.01

    HP Security Manager is potentially vulnerable to Remote Code Execution as a result of code vulnerability within the product's solution open-source libraries.

  • CVE-2024-42634CriAug 16, 2024
    risk 0.64cvss 9.8epss 0.02

    A Command Injection vulnerability exists in formWriteFacMac of the httpd binary in Tenda AC9 v15.03.06.42. As a result, attacker can execute OS commands with root privileges.

  • CVE-2024-41623CriAug 13, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in D3D Security D3D IP Camera (D8801) v.V9.1.17.1.4-20180428 allows a local attacker to execute arbitrary code via a crafted payload

  • CVE-2024-22116CriAug 12, 2024
    risk 0.64cvss 9.9epss 0.02

    An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the Ping script, thereby compromising…

  • CVE-2024-42393CriAug 6, 2024
    risk 0.64cvss 9.8epss 0.01

    There are vulnerabilities in the Soft AP Daemon Service which could allow a threat actor to execute an unauthenticated RCE attack. Successful exploitation could allow an attacker to execute arbitrary commands on the underlying operating system leading to complete system…

  • CVE-2024-41468CriJul 25, 2024
    risk 0.64cvss 9.8epss 0.05

    Tenda FH1201 v1.2.0.14 was discovered to contain a command injection vulnerability via the cmdinput parameter at /goform/exeCommand

  • CVE-2024-21552CriJul 22, 2024
    risk 0.64cvss 9.8epss 0.01

    All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI application server.

  • CVE-2024-39962CriJul 19, 2024
    risk 0.64cvss 9.8epss 0.02

    D-Link DIR-823X AX3000 Dual-Band Gigabit Wireless Router v21_D240126 was discovered to contain a remote code execution (RCE) vulnerability in the ntp_zone_val parameter at /goform/set_ntp. This vulnerability is exploited via a crafted HTTP request.

  • CVE-2024-25077CriJul 10, 2024
    risk 0.64cvss 9.8epss 0.00

    An issue was discovered on Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 devices. The Nonce used for on-the-fly decryption of flash images is stored in an unsigned header, allowing its value to be modified without invalidating the signature used for secureboot image…

  • CVE-2024-39071CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    Fujian Kelixun <=7.6.6.4391 is vulnerable to SQL Injection in send_event.php.

  • CVE-2024-6602CriJul 9, 2024
    risk 0.64cvss 9.8epss 0.01

    A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.

  • CVE-2024-38346CriJul 5, 2024
    risk 0.64cvss 9.8epss 0.03

    The CloudStack cluster service runs on unauthenticated port (default 9090) that can be misused to run arbitrary commands on targeted hypervisors and CloudStack management server hosts. Some of these commands were found to have command injection vulnerabilities that can result in…