CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 33 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-46980 | Cri | 0.64 | 9.8 | 0.02 | Nov 3, 2023 | An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter. | ||
| CVE-2023-46958 | Cri | 0.64 | 9.8 | 0.01 | Nov 2, 2023 | An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file. | ||
| CVE-2023-40050 | Cri | 0.64 | 9.9 | 0.01 | Oct 31, 2023 | Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution. | ||
| CVE-2023-43792 | Cri | 0.64 | 9.8 | 0.01 | Oct 30, 2023 | baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available. | ||
| CVE-2021-33635 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2023 | When malicious images are pulled by isula pull, attackers can execute arbitrary code. | ||
| CVE-2023-46509 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2023 | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. | ||
| CVE-2023-46010 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | ||
| CVE-2023-30131 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2023 | An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls. | ||
| CVE-2023-41630 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2023 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component. | ||
| CVE-2023-29453 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the… | ||
| CVE-2023-43625 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application… | ||
| CVE-2023-3656 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network. | ||
| CVE-2023-44011 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | ||
| CVE-2023-5201 | Cri | 0.64 | 9.9 | 0.01 | Sep 30, 2023 | The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]… | ||
| CVE-2023-43234 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters. | ||
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2021-38243 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request. | ||
| CVE-2023-43270 | Cri | 0.64 | 9.8 | 0.01 | Sep 22, 2023 | dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate. | ||
| CVE-2023-4291 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. … | ||
| CVE-2023-4994 | Cri | 0.64 | 9.9 | 0.01 | Sep 16, 2023 | The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. |
- risk 0.64cvss 9.8epss 0.02
An issue in Best Courier Management System v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the userID parameter.
- risk 0.64cvss 9.8epss 0.01
An issue in lmxcms v.1.41 allows a remote attacker to execute arbitrary code via a crafted script to the admin.php file.
- risk 0.64cvss 9.9epss 0.01
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
- risk 0.64cvss 9.8epss 0.01
baserCMS is a website development framework. In versions 4.6.0 through 4.7.6, there is a Code Injection vulnerability in the mail form of baserCMS. As of time of publication, no known patched versions are available.
- risk 0.64cvss 9.8epss 0.01
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
- risk 0.64cvss 9.8epss 0.01
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.
- risk 0.64cvss 9.8epss 0.01
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.
- risk 0.64cvss 9.8epss 0.01
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application…
- risk 0.64cvss 9.8epss 0.01
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
- risk 0.64cvss 9.8epss 0.01
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.
- risk 0.64cvss 9.9epss 0.01
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]…
- risk 0.64cvss 9.8epss 0.01
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
- risk 0.64cvss 9.8epss 0.01
dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.
- risk 0.64cvss 9.8epss 0.01
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. …
- risk 0.64cvss 9.9epss 0.01
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.