VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (7,295)

page 36 of 365
  • CVE-2020-22612CriSep 1, 2023
    risk 0.64cvss 9.8epss 0.01

    Installer RCE on settings file write in MyBB before 1.8.22.

  • CVE-2023-31447CriAug 21, 2023
    risk 0.64cvss 9.8epss 0.01

    user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.

  • CVE-2023-32626CriAug 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Hidden functionality vulnerability in LAN-W300N/RS all versions, and LAN-W300N/PR5 all versions allows an unauthenticated attacker to log in to the product's certain management console and execute arbitrary OS commands.

  • CVE-2023-39661CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.

  • CVE-2023-38889CriAug 15, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).

  • CVE-2023-34842CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.01

    Remote Code Execution vulnerability in DedeCMS through 5.7.109 allows remote attackers to run arbitrary code via crafted POST request to /dede/tpl.php.

  • CVE-2023-34644CriJul 31, 2023
    risk 0.64cvss 9.8epss 0.02

    Remote code execution vulnerability in Ruijie Networks Product: RG-EW series home routers and repeaters EW_3.0(1)B11P204, RG-NBS and RG-S1930 series switches SWITCH_3.0(1)B11P218, RG-EG series business VPN routers EG_3.0(1)B11P216, EAP and RAP series wireless access points…

  • CVE-2023-39023CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39022CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39021CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39018CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple third parties because there are no…

  • CVE-2023-39017CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple parties because it is…

  • CVE-2023-39016CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39015CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.

  • CVE-2023-39013CriJul 28, 2023
    risk 0.64cvss 9.8epss 0.01

    Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.

  • CVE-2021-37384CriJul 17, 2023
    risk 0.64cvss 9.8epss 0.02

    RCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to send arbitrary commands to the device via web interface.

  • CVE-2023-38198CriJul 13, 2023
    risk 0.64cvss 9.8epss 0.01

    acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.

  • CVE-2023-29382CriJul 6, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.

  • CVE-2021-31635CriJun 26, 2023
    risk 0.64cvss 9.8epss 0.01

    Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.

  • CVE-2023-35150CriJun 23, 2023
    risk 0.64cvss 9.9epss 0.78

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 2.40m-2 and prior to versions 14.4.8, 14.10.4, and 15.0, any user with view rights on any document can execute code with programming rights, leading to…