VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 31 of 349
  • CVE-2024-22988CriFeb 23, 2024
    risk 0.64cvss 9.8epss 0.01

    ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.

  • CVE-2024-25249CriFeb 21, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in He3 App for macOS version 2.0.17, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

  • CVE-2023-52381CriFeb 18, 2024
    risk 0.64cvss 9.8epss 0.00

    Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.

  • CVE-2024-25502CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.01

    Directory Traversal vulnerability in flusity CMS v.2.4 allows a remote attacker to execute arbitrary code and obtain sensitive information via the download_backup.php component.

  • CVE-2022-23088CriFeb 15, 2024
    risk 0.64cvss 9.8epss 0.04

    The 802.11 beacon handling routine failed to validate the length of an IEEE 802.11s Mesh ID before copying it to a heap-allocated buffer. While a FreeBSD Wi-Fi client is in scanning mode (i.e., not associated with a SSID) a malicious beacon frame may overwrite kernel memory,…

  • CVE-2024-21351HigKEVFeb 13, 2024
    risk 0.64cvss 7.6epss 0.30

    Windows SmartScreen Security Feature Bypass Vulnerability

  • CVE-2024-24091CriFeb 8, 2024
    risk 0.64cvss 9.8epss 0.01

    Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.

  • CVE-2024-25089CriFeb 4, 2024
    risk 0.64cvss 9.8epss 0.02

    Malwarebytes Binisoft Windows Firewall Control before 6.9.9.2 allows remote attackers to execute arbitrary code via gRPC named pipes.

  • CVE-2023-50488CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    An issue in Blurams Lumi Security Camera (A31C) v23.0406.435.4120 allows attackers to execute arbitrary code.

  • CVE-2024-22533CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filtering is not strict, the blacklist can be…

  • CVE-2024-23746CriFeb 2, 2024
    risk 0.64cvss 9.8epss 0.01

    Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, an asar modification, and a rename back…

  • CVE-2024-1015CriJan 29, 2024
    risk 0.64cvss 9.8epss 0.02

    Remote command execution vulnerability in SE-elektronic GmbH E-DDC3.3 affecting versions 03.07.03 and higher. An attacker could send different commands from the operating system to the system via the web configuration functionality of the device.

  • CVE-2024-23742CriJan 28, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a victim's machine.

  • CVE-2024-23741CriJan 28, 2024
    risk 0.64cvss 9.8epss 0.02

    An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.

  • CVE-2024-23752CriJan 22, 2024
    risk 0.64cvss 9.8epss 0.01

    GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides an English language specification of…

  • CVE-2023-46226CriJan 15, 2024
    risk 0.64cvss 9.8epss 0.02

    Remote Code Execution vulnerability in Apache IoTDB.This issue affects Apache IoTDB: from 1.0.0 through 1.2.2. Users are recommended to upgrade to version 1.3.0, which fixes the issue.

  • CVE-2023-41544CriDec 30, 2023
    risk 0.64cvss 9.8epss 0.03

    SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.

  • CVE-2023-49830CriDec 29, 2023
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Brainstorm Force Astra Pro.This issue affects Astra Pro: from n/a through 4.3.1.

  • CVE-2023-47840CriDec 29, 2023
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Qode Interactive Qode Essential Addons.This issue affects Qode Essential Addons: from n/a through 1.5.2.

  • CVE-2023-46623CriDec 29, 2023
    risk 0.64cvss 9.9epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in TienCOP WP EXtra.This issue affects WP EXtra: from n/a through 6.2.