VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 59 of 349
  • CVE-2025-34124HigJul 16, 2025
    risk 0.58cvss epss 0.00

    A buffer overflow vulnerability exists in Heroes of Might and Magic III Complete 4.0.0.0, HD Mod 3.808 build 9, and Demo 1.0.0.0 via malicious .h3m map files that exploit object sprite name parsing logic. The vulnerability occurs during in-game map loading when a crafted object…

  • CVE-2025-34123HigJul 16, 2025
    risk 0.58cvss epss 0.00

    A stack-based buffer overflow vulnerability exists in VideoCharge Studio 2.12.3.685 when processing a specially crafted .VSC configuration file. The issue occurs due to improper handling of user-supplied data in the XML 'Name' attribute, leading to an SEH overwrite condition. An…

  • CVE-2025-23121HigJun 19, 2025
    risk 0.58cvss 8.8epss 0.20

    A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user

  • CVE-2024-54780HigMay 14, 2025
    risk 0.58cvss 8.8epss 0.12

    Netgate pfSense CE (prior to 2.8.0 beta release) and corresponding Plus builds are vulnerable to command injection in the OpenVPN widget due to improper sanitization of user-supplied input to the OpenVPN management interface. An authenticated attacker can exploit this…

  • CVE-2025-1302CriFeb 15, 2025
    risk 0.58cvss 9.8epss 0.10

    Versions of the package jsonpath-plus before 10.3.0 are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of eval='safe' mode. **Note:** This is caused by…

  • CVE-2024-21574CriDec 12, 2024
    risk 0.58cvss 10.0epss 0.01

    The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes which is added to the server by the extension. This allows an attacker to craft a request that triggers a pip install on a user…

  • CVE-2024-42756HigAug 23, 2024
    risk 0.58cvss 8.8epss 0.14

    An issue in Netgear DGN1000WW v.1.1.00.45 allows a remote attacker to execute arbitrary code via the Diagnostics page

  • CVE-2024-5466HigAug 23, 2024
    risk 0.58cvss 8.8epss 0.07

    Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.

  • CVE-2023-45673HigJun 21, 2024
    risk 0.58cvss 8.9epss 0.01

    Joplin is a free, open source note taking and to-do application. A remote code execution (RCE) vulnerability in affected versions allows clicking on a link in a PDF in an untrusted note to execute arbitrary shell commands. Clicking links in PDFs allows for arbitrary code…

  • CVE-2024-31996CriApr 10, 2024
    risk 0.58cvss 10.0epss 0.02

    XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, allows XWiki syntax injection and thereby…

  • CVE-2023-41724HigMar 31, 2024
    risk 0.58cvss 8.8epss 0.13

    A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.

  • CVE-2024-28848HigMar 15, 2024
    risk 0.58cvss 8.8epss 0.08

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `‎CompiledRule::validateExpression` method evaluates an SpEL expression using an…

  • CVE-2024-21378HigFeb 13, 2024
    risk 0.58cvss 8.8epss 0.11

    Microsoft Outlook Remote Code Execution Vulnerability

  • CVE-2023-6846HigFeb 5, 2024
    risk 0.58cvss 8.8epss 0.16

    The File Manager Pro plugin for WordPress is vulnerable to Arbitrary File Upload in all versions up to, and including, 8.3.4 via the mk_check_filemanager_php_syntax AJAX function. This makes it possible for authenticated attackers, with subscriber access and above, to execute…

  • CVE-2024-0252HigJan 11, 2024
    risk 0.58cvss 8.8epss 0.08

    ManageEngine ADSelfService Plus versions 6401 and below are vulnerable to the remote code execution due to the improper handling in the load balancer component. Authentication is required in order to exploit this vulnerability.

  • CVE-2023-45144CriOct 16, 2023
    risk 0.58cvss 10.0epss 0.01

    com.xwiki.identity-oauth:identity-oauth-ui is a package to aid in building identity and service providers based on OAuth authorizations. When a user logs in via the OAuth method, the identityOAuth parameters sent in the GET request is vulnerable to cross site scripting (XSS) and…

  • CVE-2023-22513HigSep 19, 2023
    risk 0.58cvss 8.8epss 0.14

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to execute arbitrary code which has high…

  • CVE-2023-33466HigJun 29, 2023
    risk 0.58cvss 8.8epss 0.04

    Orthanc before 1.12.0 allows authenticated users with access to the Orthanc API to overwrite arbitrary files on the file system, and in specific deployment scenarios allows the attacker to overwrite the configuration, which can be exploited to trigger Remote Code Execution (RCE).

  • CVE-2023-34251CriJun 14, 2023
    risk 0.58cvss 9.9epss 0.02

    Grav is a flat-file content management system. Versions prior to 1.7.42 are vulnerable to server side template injection. Remote code execution is possible by embedding malicious PHP code on the administrator screen by a user with page editing privileges. Version 1.7.42 contains…

  • CVE-2023-34468HigJun 12, 2023
    risk 0.58cvss 8.8epss 0.64

    The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and…