CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 30 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-24707 | Cri | 0.64 | 9.9 | 0.01 | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2. | ||
| CVE-2024-31390 | Cri | 0.64 | 9.9 | 0.01 | Apr 3, 2024 | : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2. | ||
| CVE-2024-31380 | Cri | 0.64 | 9.9 | 0.01 | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9. | ||
| CVE-2024-27972 | Cri | 0.64 | 9.9 | 0.02 | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24. | ||
| CVE-2024-25918 | Cri | 0.64 | 9.9 | 0.01 | Apr 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8. | ||
| CVE-2024-31011 | Cri | 0.64 | 9.8 | 0.01 | Apr 3, 2024 | Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php. | ||
| CVE-2024-31004 | Cri | 0.64 | 9.8 | 0.01 | Apr 2, 2024 | An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment. | ||
| CVE-2024-30858 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php. | ||
| CVE-2024-30868 | Cri | 0.64 | 9.8 | 0.01 | Apr 1, 2024 | netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php. | ||
| CVE-2024-31032 | Cri | 0.64 | 9.8 | 0.01 | Mar 29, 2024 | An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component. | ||
| CVE-2024-28386 | Cri | 0.64 | 9.8 | 0.01 | Mar 25, 2024 | An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component. | ||
| CVE-2024-0917 | Cri | 0.64 | 9.8 | 0.02 | Mar 7, 2024 | remote code execution in paddlepaddle/paddle 2.6.0 | ||
| CVE-2023-41503 | Cri | 0.64 | 9.8 | 0.01 | Mar 7, 2024 | Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function. | ||
| CVE-2024-22891 | Cri | 0.64 | 9.8 | 0.02 | Mar 1, 2024 | Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link. | ||
| CVE-2024-25180 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test… | ||
| CVE-2024-25291 | Cri | 0.64 | 9.8 | 0.02 | Feb 29, 2024 | Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin. | ||
| CVE-2024-24525 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL. | ||
| CVE-2023-51801 | Cri | 0.64 | 9.8 | 0.01 | Feb 29, 2024 | SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages. | ||
| CVE-2024-25350 | Cri | 0.64 | 9.8 | 0.01 | Feb 28, 2024 | SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters. | ||
| CVE-2024-22988 | Cri | 0.64 | 9.8 | 0.01 | Feb 23, 2024 | ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp. |
- risk 0.64cvss 9.9epss 0.01
Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.
- risk 0.64cvss 9.9epss 0.01
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
- risk 0.64cvss 9.9epss 0.01
Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.
- risk 0.64cvss 9.9epss 0.02
Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.
- risk 0.64cvss 9.9epss 0.01
Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.
- risk 0.64cvss 9.8epss 0.01
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.
- risk 0.64cvss 9.8epss 0.01
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
- risk 0.64cvss 9.8epss 0.01
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.
- risk 0.64cvss 9.8epss 0.01
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.
- risk 0.64cvss 9.8epss 0.01
An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.
- risk 0.64cvss 9.8epss 0.01
An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.
- risk 0.64cvss 9.8epss 0.02
remote code execution in paddlepaddle/paddle 2.6.0
- risk 0.64cvss 9.8epss 0.01
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
- risk 0.64cvss 9.8epss 0.02
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test…
- risk 0.64cvss 9.8epss 0.02
Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.
- risk 0.64cvss 9.8epss 0.01
An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
- risk 0.64cvss 9.8epss 0.01
SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.
- risk 0.64cvss 9.8epss 0.01
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.