VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 30 of 349
  • CVE-2024-24707CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Cwicly Builder, SL. Cwicly allows Code Injection.This issue affects Cwicly: from n/a through 1.4.0.2.

  • CVE-2024-31390CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    : Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.

  • CVE-2024-31380CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.

  • CVE-2024-27972CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.02

    Improper Control of Generation of Code ('Code Injection') vulnerability in Jack Arturo WP Fusion Lite wp-fusion-lite.This issue affects WP Fusion Lite: from n/a through <= 3.41.24.

  • CVE-2024-25918CriApr 3, 2024
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in InstaWP InstaWP Connect instawp-connect.This issue affects InstaWP Connect: from n/a through <= 0.1.0.8.

  • CVE-2024-31011CriApr 3, 2024
    risk 0.64cvss 9.8epss 0.01

    Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.

  • CVE-2024-31004CriApr 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.

  • CVE-2024-30858CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.

  • CVE-2024-30868CriApr 1, 2024
    risk 0.64cvss 9.8epss 0.01

    netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.

  • CVE-2024-31032CriMar 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.

  • CVE-2024-28386CriMar 25, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Home-Made.io fastmagsync v.1.7.51 and before allows a remote attacker to execute arbitrary code via the getPhpBin() component.

  • CVE-2024-0917CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.02

    remote code execution in paddlepaddle/paddle 2.6.0

  • CVE-2023-41503CriMar 7, 2024
    risk 0.64cvss 9.8epss 0.01

    Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.

  • CVE-2024-22891CriMar 1, 2024
    risk 0.64cvss 9.8epss 0.02

    Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.

  • CVE-2024-25180CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in pdfmake 0.2.9 allows remote attackers to run arbitrary code via crafted POST request to the /pdf endpoint. NOTE: this is disputed because the behavior of the /pdf endpoint is intentional. The /pdf endpoint is only available after installing a test…

  • CVE-2024-25291CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.02

    Deskfiler v1.2.3 allows attackers to execute arbitrary code via uploading a crafted plugin.

  • CVE-2024-24525CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in EpointWebBuilder 5.1.0-sp1, 5.2.1-sp1, 5.4.1 and 5.4.2 allows a remote attacker to execute arbitrary code via the infoid parameter of the URL.

  • CVE-2023-51801CriFeb 29, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.

  • CVE-2024-25350CriFeb 28, 2024
    risk 0.64cvss 9.8epss 0.01

    SQL Injection vulnerability in /zms/admin/edit-ticket.php in PHPGurukul Zoo Management System 1.0 via tickettype and tprice parameters.

  • CVE-2024-22988CriFeb 23, 2024
    risk 0.64cvss 9.8epss 0.01

    ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.