CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,979)
page 38 of 349| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2022-25767 | Cri | 0.64 | 9.8 | 0.03 | May 1, 2022 | All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets. | ||
| CVE-2021-39383 | Cri | 0.64 | 9.8 | 0.03 | Mar 20, 2022 | DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java. | ||
| CVE-2022-25578 | Cri | 0.64 | 9.8 | 0.02 | Mar 18, 2022 | taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file. | ||
| CVE-2020-25197 | Cri | 0.64 | 9.8 | 0.03 | Mar 18, 2022 | A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system. | ||
| CVE-2020-15591 | Cri | 0.64 | 9.8 | 0.04 | Mar 17, 2022 | fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution). | ||
| CVE-2022-25498 | Cri | 0.64 | 9.8 | 0.03 | Mar 15, 2022 | CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php. | ||
| CVE-2022-22909 | Hig | 0.64 | 8.8 | 0.45 | Mar 3, 2022 | HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module. | ||
| CVE-2022-24442 | Cri | 0.64 | 9.8 | 0.04 | Feb 25, 2022 | JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates. | ||
| CVE-2022-24664 | Cri | 0.64 | 9.9 | 0.02 | Feb 16, 2022 | PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts. | ||
| CVE-2021-46362 | Cri | 0.64 | 9.8 | 0.05 | Feb 11, 2022 | A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter. | ||
| CVE-2021-44521 | Cri | 0.64 | 9.1 | 0.55 | Feb 11, 2022 | When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would… | ||
| CVE-2021-44978 | Cri | 0.64 | 9.8 | 0.02 | Feb 4, 2022 | iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution. | ||
| CVE-2021-45029 | Cri | 0.64 | 9.8 | 0.06 | Jan 25, 2022 | Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1. | ||
| CVE-2021-44734 | Cri | 0.64 | 9.8 | 0.06 | Jan 20, 2022 | Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device. | ||
| CVE-2021-39979 | Cri | 0.64 | 9.8 | 0.01 | Jan 3, 2022 | HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity. | ||
| CVE-2020-20601 | Cri | 0.64 | 9.8 | 0.08 | Dec 22, 2021 | An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet. | ||
| CVE-2021-44231 | Cri | 0.64 | 9.8 | 0.01 | Dec 14, 2021 | Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | ||
| CVE-2021-33816 | Cri | 0.64 | 9.8 | 0.04 | Nov 10, 2021 | The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked. | ||
| CVE-2021-43466 | Cri | 0.64 | 9.8 | 0.04 | Nov 9, 2021 | In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution. | ||
| CVE-2021-38450 | Cri | 0.64 | 9.9 | 0.01 | Oct 27, 2021 | The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software. |
- risk 0.64cvss 9.8epss 0.03
All versions of package com.bstek.ureport:ureport2-console are vulnerable to Remote Code Execution by connecting to a malicious database server, causing arbitrary file read and deserialization of local gadgets.
- risk 0.64cvss 9.8epss 0.03
DWSurvey v3.2.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /sysuser/SysPropertyAction.java.
- risk 0.64cvss 9.8epss 0.02
taocms v3.0.2 allows attackers to execute code injection via arbitrarily editing the .htaccess file.
- risk 0.64cvss 9.8epss 0.03
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the system.
- risk 0.64cvss 9.8epss 0.04
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
- risk 0.64cvss 9.8epss 0.03
CuppaCMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the saveConfigData function in /classes/ajax/Functions.php.
- risk 0.64cvss 8.8epss 0.45
HotelDruid v3.0.3 was discovered to contain a remote code execution (RCE) vulnerability which is exploited via an attacker inserting a crafted payload into the name field under the Create New Room module.
- risk 0.64cvss 9.8epss 0.04
JetBrains YouTrack before 2021.4.40426 was vulnerable to SSTI (Server-Side Template Injection) via FreeMarker templates.
- risk 0.64cvss 9.9epss 0.02
PHP Everywhere <= 2.0.3 included functionality that allowed execution of PHP Code Snippets via WordPress metaboxes, which could be used by any user able to edit posts.
- risk 0.64cvss 9.8epss 0.05
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
- risk 0.64cvss 9.1epss 0.55
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitrary code on the host. The attacker would…
- risk 0.64cvss 9.8epss 0.02
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
- risk 0.64cvss 9.8epss 0.06
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- risk 0.64cvss 9.8epss 0.06
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
- risk 0.64cvss 9.8epss 0.01
HHEE system has a Code Injection vulnerability.Successful exploitation of this vulnerability may affect HHEE system integrity.
- risk 0.64cvss 9.8epss 0.08
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
- risk 0.64cvss 9.8epss 0.01
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- risk 0.64cvss 9.8epss 0.04
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
- risk 0.64cvss 9.8epss 0.04
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
- risk 0.64cvss 9.9epss 0.01
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.