CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (7,295)
page 35 of 365| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-33635 | Cri | 0.64 | 9.8 | 0.01 | Oct 29, 2023 | When malicious images are pulled by isula pull, attackers can execute arbitrary code. | ||
| CVE-2023-46509 | Cri | 0.64 | 9.8 | 0.01 | Oct 27, 2023 | An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component. | ||
| CVE-2023-46010 | Cri | 0.64 | 9.8 | 0.01 | Oct 25, 2023 | An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component. | ||
| CVE-2023-30131 | Cri | 0.64 | 9.8 | 0.01 | Oct 19, 2023 | An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls. | ||
| CVE-2023-41630 | Cri | 0.64 | 9.8 | 0.01 | Oct 17, 2023 | eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component. | ||
| CVE-2023-29453 | Cri | 0.64 | 9.8 | 0.01 | Oct 12, 2023 | Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the… | ||
| CVE-2023-43625 | Cri | 0.64 | 9.8 | 0.01 | Oct 10, 2023 | A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application… | ||
| CVE-2023-3656 | Cri | 0.64 | 9.8 | 0.01 | Oct 3, 2023 | cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network. | ||
| CVE-2023-44011 | Cri | 0.64 | 9.8 | 0.01 | Oct 2, 2023 | An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component. | ||
| CVE-2023-5201 | Cri | 0.64 | 9.9 | 0.01 | Sep 30, 2023 | The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]… | ||
| CVE-2023-43234 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters. | ||
| CVE-2023-43222 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file. | ||
| CVE-2021-38243 | Cri | 0.64 | 9.8 | 0.01 | Sep 27, 2023 | xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request. | ||
| CVE-2023-43270 | Cri | 0.64 | 9.8 | 0.01 | Sep 22, 2023 | dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate. | ||
| CVE-2023-4291 | Cri | 0.64 | 9.8 | 0.01 | Sep 21, 2023 | Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. … | ||
| CVE-2023-4994 | Cri | 0.64 | 9.9 | 0.01 | Sep 16, 2023 | The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. | ||
| CVE-2023-42471 | Cri | 0.64 | 9.8 | 0.03 | Sep 11, 2023 | The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to… | ||
| CVE-2023-42470 | Cri | 0.64 | 9.8 | 0.02 | Sep 11, 2023 | The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and… | ||
| CVE-2023-39320 | Cri | 0.64 | 9.8 | 0.02 | Sep 8, 2023 | The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as… | ||
| CVE-2023-39681 | Cri | 0.64 | 9.8 | 0.02 | Sep 5, 2023 | Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload. |
- risk 0.64cvss 9.8epss 0.01
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
An issue in Contec SolarView Compact v.6.0 and before allows an attacker to execute arbitrary code via the texteditor.php component.
- risk 0.64cvss 9.8epss 0.01
An issue in SeaCMS v.12.9 allows an attacker to execute arbitrary commands via the admin_safe.php component.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.
- risk 0.64cvss 9.8epss 0.01
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.
- risk 0.64cvss 9.8epss 0.01
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript template literal, the contents of the…
- risk 0.64cvss 9.8epss 0.01
A vulnerability has been identified in Simcenter Amesim (All versions < V2021.1). The affected application contains a SOAP endpoint that could allow an unauthenticated remote attacker to perform DLL injection and execute arbitrary code in the context of the affected application…
- risk 0.64cvss 9.8epss 0.01
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP endpoint exposed to the network.
- risk 0.64cvss 9.8epss 0.01
An issue in mojoPortal v.2.7.0.0 allows a remote attacker to execute arbitrary code via a crafted script to the layout.master skin file at the Skin management component.
- risk 0.64cvss 9.9epss 0.01
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server. This requires the [php]…
- risk 0.64cvss 9.8epss 0.01
DedeBIZ v6.2.11 was discovered to contain multiple remote code execution (RCE) vulnerabilities at /admin/file_manage_control.php via the $activepath and $filename parameters.
- risk 0.64cvss 9.8epss 0.01
SeaCMS v12.8 has an arbitrary code writing vulnerability in the /jxz7g2/admin_ping.php file.
- risk 0.64cvss 9.8epss 0.01
xunruicms up to v4.5.1 was discovered to contain a remote code execution (RCE) vulnerability in /index.php. This vulnerability allows attackers to execute arbitrary code via a crafted GET request.
- risk 0.64cvss 9.8epss 0.01
dst-admin v1.5.0 was discovered to contain a remote command execution (RCE) vulnerability via the userId parameter at /home/playerOperate.
- risk 0.64cvss 9.8epss 0.01
Frauscher Sensortechnik GmbH FDS101 for FAdC/FAdCi v1.4.24 and all previous versions are vulnerable to a remote code execution (RCE) vulnerability via manipulated parameters of the web interface without authentication. This could lead to a full compromise of the FDS101 device. …
- risk 0.64cvss 9.9epss 0.01
The Allow PHP in Posts and Pages plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.0.4 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on the server.
- risk 0.64cvss 9.8epss 0.03
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. This activity uses a WebView component to…
- risk 0.64cvss 9.8epss 0.02
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execution is enabled in the WebView, and…
- risk 0.64cvss 9.8epss 0.02
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "go" command from the module proxy, as…
- risk 0.64cvss 9.8epss 0.02
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.