CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 36 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-0090 | Cri | 0.64 | 9.8 | 0.01 | Mar 8, 2023 | The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.… | ||
| CVE-2021-36394 | Cri | 0.64 | 9.8 | 0.07 | Mar 6, 2023 | In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin. | ||
| CVE-2023-24776 | Cri | 0.64 | 9.8 | 0.01 | Mar 6, 2023 | Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php. | ||
| CVE-2022-45553 | Cri | 0.64 | 9.8 | 0.01 | Mar 3, 2023 | An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port. | ||
| CVE-2023-26477 | Cri | 0.64 | 10.0 | 0.75 | Mar 2, 2023 | XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional… | ||
| CVE-2023-24114 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php. | ||
| CVE-2023-24107 | Cri | 0.64 | 9.8 | 0.01 | Feb 22, 2023 | hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code. | ||
| CVE-2021-33949 | Cri | 0.64 | 9.8 | 0.01 | Feb 17, 2023 | An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function. | ||
| CVE-2023-24078 | Hig | 0.64 | 8.8 | 0.53 | Feb 17, 2023 | Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/. | ||
| CVE-2021-36424 | Cri | 0.64 | 9.8 | 0.01 | Feb 3, 2023 | An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation. | ||
| CVE-2022-48175 | Cri | 0.64 | 9.8 | 0.02 | Jan 30, 2023 | Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request. | ||
| CVE-2023-23619 | Cri | 0.64 | 9.9 | 0.01 | Jan 26, 2023 | Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not handle the functionality… | ||
| CVE-2022-25894 | Cri | 0.64 | 9.8 | 0.03 | Jan 26, 2023 | All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation. | ||
| CVE-2023-21890 | Cri | 0.64 | 9.8 | 0.01 | Jan 18, 2023 | Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to… | ||
| CVE-2023-0022 | Cri | 0.64 | 9.9 | 0.01 | Jan 10, 2023 | SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise… | ||
| CVE-2022-25893 | Cri | 0.64 | 9.8 | 0.01 | Dec 21, 2022 | The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise. | ||
| CVE-2021-39426 | Cri | 0.64 | 9.8 | 0.01 | Dec 15, 2022 | An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set. | ||
| CVE-2022-4223 | Hig | 0.64 | 8.8 | 0.80 | Dec 13, 2022 | The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin… | ||
| CVE-2022-45550 | Cri | 0.64 | 9.8 | 0.01 | Dec 7, 2022 | AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE). | ||
| CVE-2022-43333 | Cri | 0.64 | 9.8 | 0.02 | Dec 1, 2022 | Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php. |
- risk 0.64cvss 9.8epss 0.01
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.…
- risk 0.64cvss 9.8epss 0.07
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- risk 0.64cvss 9.8epss 0.01
Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
- risk 0.64cvss 10.0epss 0.75
XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional…
- risk 0.64cvss 9.8epss 0.01
typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.
- risk 0.64cvss 9.8epss 0.01
hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.
- risk 0.64cvss 9.8epss 0.01
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
- risk 0.64cvss 8.8epss 0.53
Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.
- risk 0.64cvss 9.8epss 0.01
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
- risk 0.64cvss 9.8epss 0.02
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
- risk 0.64cvss 9.9epss 0.01
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not handle the functionality…
- risk 0.64cvss 9.8epss 0.03
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
- risk 0.64cvss 9.8epss 0.01
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to…
- risk 0.64cvss 9.9epss 0.01
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…
- risk 0.64cvss 9.8epss 0.01
The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.
- risk 0.64cvss 9.8epss 0.01
An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.
- risk 0.64cvss 8.8epss 0.80
The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin…
- risk 0.64cvss 9.8epss 0.01
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
- risk 0.64cvss 9.8epss 0.02
Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.