VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 36 of 349
  • CVE-2023-0090CriMar 8, 2023
    risk 0.64cvss 9.8epss 0.01

    The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such access is a non-standard configuration.…

  • CVE-2021-36394CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.07

    In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.

  • CVE-2023-24776CriMar 6, 2023
    risk 0.64cvss 9.8epss 0.01

    Funadmin v3.2.0 was discovered to contain a remote code execution (RCE) vulnerability via the component \controller\Addon.php.

  • CVE-2022-45553CriMar 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.

  • CVE-2023-26477CriMar 2, 2023
    risk 0.64cvss 10.0epss 0.75

    XWiki Platform is a generic wiki platform. Starting in versions 6.3-rc-1 and 6.2.4, it's possible to inject arbitrary wiki syntax including Groovy, Python and Velocity script macros via the `newThemeName` request parameter (URL parameter), in combination with additional…

  • CVE-2023-24114CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    typecho 1.1/17.10.30 was discovered to contain a remote code execution (RCE) vulnerability via install.php.

  • CVE-2023-24107CriFeb 22, 2023
    risk 0.64cvss 9.8epss 0.01

    hour_of_code_python_2015 commit 520929797b9ca43bb818b2e8f963fb2025459fa3 was discovered to contain a code execution backdoor via the request package (requirements.txt). This vulnerability allows attackers to access sensitive user information and execute arbitrary code.

  • CVE-2021-33949CriFeb 17, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.

  • CVE-2023-24078HigFeb 17, 2023
    risk 0.64cvss 8.8epss 0.53

    Real Time Logic FuguHub v8.1 and earlier was discovered to contain a remote code execution (RCE) vulnerability via the component /FuguHub/cmsdocs/.

  • CVE-2021-36424CriFeb 3, 2023
    risk 0.64cvss 9.8epss 0.01

    An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.

  • CVE-2022-48175CriJan 30, 2023
    risk 0.64cvss 9.8epss 0.02

    Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.

  • CVE-2023-23619CriJan 26, 2023
    risk 0.64cvss 9.9epss 0.01

    Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/or does not handle the functionality…

  • CVE-2022-25894CriJan 26, 2023
    risk 0.64cvss 9.8epss 0.03

    All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.

  • CVE-2023-21890CriJan 18, 2023
    risk 0.64cvss 9.8epss 0.01

    Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via UDP to…

  • CVE-2023-0022CriJan 10, 2023
    risk 0.64cvss 9.9epss 0.01

    SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform operations that may completely compromise…

  • CVE-2022-25893CriDec 21, 2022
    risk 0.64cvss 9.8epss 0.01

    The package vm2 before 3.9.10 are vulnerable to Arbitrary Code Execution due to the usage of prototype lookup for the WeakMap.prototype.set method. Exploiting this vulnerability leads to access to a host object and a sandbox compromise.

  • CVE-2021-39426CriDec 15, 2022
    risk 0.64cvss 9.8epss 0.01

    An issue was discovered in /Upload/admin/admin_notify.php in Seacms 11.4 allows attackers to execute arbitrary php code via the notify1 parameter when the action parameter equals set.

  • CVE-2022-4223HigDec 13, 2022
    risk 0.64cvss 8.8epss 0.80

    The pgAdmin server includes an HTTP API that is intended to be used to validate the path a user selects to external PostgreSQL utilities such as pg_dump and pg_restore. The utility is executed by the server to determine what PostgreSQL version it is from. Versions of pgAdmin…

  • CVE-2022-45550CriDec 7, 2022
    risk 0.64cvss 9.8epss 0.01

    AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).

  • CVE-2022-43333CriDec 1, 2022
    risk 0.64cvss 9.8epss 0.02

    Telenia Software s.r.l TVox before v22.0.17 was discovered to contain a remote code execution (RCE) vulnerability in the component action_export_control.php.