CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 35 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-38198 | Cri | 0.64 | 9.8 | 0.01 | Jul 13, 2023 | acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023. | ||
| CVE-2023-29382 | Cri | 0.64 | 9.8 | 0.01 | Jul 6, 2023 | An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component. | ||
| CVE-2021-31635 | Cri | 0.64 | 9.8 | 0.01 | Jun 26, 2023 | Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function. | ||
| CVE-2023-35150 | Cri | 0.64 | 9.9 | 0.78 | Jun 23, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to… | ||
| CVE-2023-35034 | Cri | 0.64 | 9.8 | 0.01 | Jun 12, 2023 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033. | ||
| CVE-2023-29404 | Cri | 0.64 | 9.8 | 0.02 | Jun 8, 2023 | The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.… | ||
| CVE-2023-29402 | Cri | 0.64 | 9.8 | 0.02 | Jun 8, 2023 | The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules… | ||
| CVE-2023-25953 | Cri | 0.64 | 9.8 | 0.01 | May 23, 2023 | Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is… | ||
| CVE-2023-29861 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device. | ||
| CVE-2023-29862 | Cri | 0.64 | 9.8 | 0.02 | May 15, 2023 | An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters. | ||
| CVE-2022-47129 | Cri | 0.64 | 9.8 | 0.01 | May 11, 2023 | PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability. | ||
| CVE-2023-30349 | Cri | 0.64 | 9.8 | 0.02 | Apr 27, 2023 | JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function. | ||
| CVE-2023-30404 | Cri | 0.64 | 9.8 | 0.02 | Apr 26, 2023 | Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request. | ||
| CVE-2020-29007 | Cri | 0.64 | 9.8 | 0.02 | Apr 15, 2023 | The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary… | ||
| CVE-2023-27650 | Cri | 0.64 | 9.8 | 0.02 | Apr 10, 2023 | An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter. | ||
| CVE-2023-24538 | Cri | 0.64 | 9.8 | 0.02 | Apr 6, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the… | ||
| CVE-2023-25261 | Cri | 0.64 | 9.8 | 0.02 | Mar 27, 2023 | Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an… | ||
| CVE-2023-24795 | Cri | 0.64 | 9.8 | 0.01 | Mar 16, 2023 | Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483. | ||
| CVE-2023-25344 | Cri | 0.64 | 9.8 | 0.01 | Mar 15, 2023 | An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function. | ||
| CVE-2023-22889 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users. |
- risk 0.64cvss 9.8epss 0.01
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
- risk 0.64cvss 9.8epss 0.01
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.
- risk 0.64cvss 9.8epss 0.01
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
- risk 0.64cvss 9.9epss 0.78
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to…
- risk 0.64cvss 9.8epss 0.01
Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033.
- risk 0.64cvss 9.8epss 0.02
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, specified via a "#cgo LDFLAGS" directive.…
- risk 0.64cvss 9.8epss 0.02
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newline characters in their names. Modules…
- risk 0.64cvss 9.8epss 0.01
Code injection vulnerability in Drive Explorer for macOS versions 3.5.4 and earlier allows an attacker who can login to the client where the affected product is installed to inject arbitrary code while processing the product execution. Since a full disk access privilege is…
- risk 0.64cvss 9.8epss 0.02
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
- risk 0.64cvss 9.8epss 0.02
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
- risk 0.64cvss 9.8epss 0.01
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
- risk 0.64cvss 9.8epss 0.02
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
- risk 0.64cvss 9.8epss 0.02
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
- risk 0.64cvss 9.8epss 0.02
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticated anonymous users) to execute arbitrary…
- risk 0.64cvss 9.8epss 0.02
An issue found in APUS Group Launcher v.3.10.73 and v.3.10.88 allows a remote attacker to execute arbitrary code via the FONT_FILE parameter.
- risk 0.64cvss 9.8epss 0.02
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…
- risk 0.64cvss 9.8epss 0.02
Certain Stimulsoft GmbH products are affected by: Remote Code Execution. This affects Stimulsoft Designer (Desktop) 2023.1.4 and Stimulsoft Designer (Web) 2023.1.3 and Stimulsoft Viewer (Web) 2023.1.3. Access to the local file system is not prohibited in any way. Therefore, an…
- risk 0.64cvss 9.8epss 0.01
Command execution vulnerability was discovered in JHR-N916R router firmware version<=21.11.1.1483.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in swig-templates thru 2.0.4 and swig thru 1.4.2, allows attackers to execute arbitrary code via crafted Object.prototype anonymous function.
- risk 0.64cvss 9.8epss 0.01
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.