VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,979)

page 70 of 349
  • CVE-2024-37777HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.

  • CVE-2025-34159HigAug 27, 2025
    risk 0.57cvss 8.8epss 0.01

    Coolify versions prior to v4.0.0-beta.420.6 are vulnerable to a remote code execution vulnerability in the application deployment workflow. The platform allows authenticated users, with low-level member privileges, to inject arbitrary Docker Compose directives during project…

  • CVE-2025-51991HigAug 20, 2025
    risk 0.57cvss 8.8epss 0.04

    XWiki through version 17.3.0 is vulnerable to Server-Side Template Injection (SSTI) in the Administration interface, specifically within the HTTP Meta Info field of the Global Preferences Presentation section. An authenticated administrator can inject crafted Apache Velocity…

  • CVE-2025-53890CriJul 15, 2025
    risk 0.57cvss 9.8epss 0.01

    pyload is an open-source Download Manager written in pure Python. An unsafe JavaScript evaluation vulnerability in pyLoad’s CAPTCHA processing code allows unauthenticated remote attackers to execute arbitrary code in the client browser and potentially the backend server.…

  • CVE-2025-53836CriJul 15, 2025
    risk 0.57cvss 9.9epss 0.01

    XWiki Rendering is a generic rendering system that converts textual input in a given syntax (wiki syntax, HTML, etc) into another syntax (XHTML, etc). Starting in version 4.2-milestone-1 and prior to versions 13.10.11, 14.4.7, and 14.10, the default macro content parser doesn't…

  • CVE-2025-49521HigJun 30, 2025
    risk 0.57cvss 8.8epss 0.00

    A flaw was found in the EDA component of the Ansible Automation Platform, where user-supplied Git branch or refspec values are evaluated as Jinja2 templates. This vulnerability allows authenticated users to inject expressions that execute commands or access sensitive files on…

  • CVE-2025-46725CriMay 20, 2025
    risk 0.57cvss 9.8epss 0.01

    Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `LanceDocChatAgent` uses pandas eval() through `compute_from_docs()`. As a result, an attacker may be able to make the agent run malicious commands through…

  • CVE-2025-46724CriMay 20, 2025
    risk 0.57cvss 9.8epss 0.01

    Langroid is a Python framework to build large language model (LLM)-powered applications. Prior to version 0.53.15, `TableChatAgent` uses `pandas eval()`. If fed by untrusted user input, like the case of a public-facing LLM application, it may be vulnerable to code injection.…

  • CVE-2024-24780CriMay 14, 2025
    risk 0.57cvss 9.8epss 0.01

    Remote Code Execution with untrusted URI of UDF vulnerability in Apache IoTDB. The attacker who has privilege to create UDF can register malicious function from untrusted URI. This issue affects Apache IoTDB: from 1.0.0 before 1.3.4. Users are recommended to upgrade to…

  • CVE-2025-28203HigMay 9, 2025
    risk 0.57cvss 8.8epss 0.01

    Victure RX1800 EN_V1.0.0_r12_110933 was discovered to contain a command injection vulnerability.

  • CVE-2024-13808HigApr 26, 2025
    risk 0.57cvss 8.8epss 0.01

    The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custom PHP widget. This is due to their only being client side controls when determining who can access the widget. This makes it…

  • CVE-2024-53303HigApr 16, 2025
    risk 0.57cvss 8.8epss 0.01

    A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via a crafted POST request.

  • CVE-2025-29281HigApr 15, 2025
    risk 0.57cvss 8.8epss 0.01

    In PerfreeBlog version 4.0.11, regular users can exploit the arbitrary file upload vulnerability in the attach component to upload arbitrary files and execute code within them.

  • CVE-2024-45199HigApr 3, 2025
    risk 0.57cvss 8.8epss 0.01

    insightsoftware Hive JDBC through 2.6.13 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to…

  • CVE-2024-45198HigApr 3, 2025
    risk 0.57cvss 8.8epss 0.01

    insightsoftware Spark JDBC 2.6.21 has a remote code execution vulnerability. Attackers can inject malicious parameters into the JDBC URL, triggering JNDI injection during the process when the JDBC Driver uses this URL to connect to the database. This can further lead to remote…

  • CVE-2025-2787HigMar 26, 2025
    risk 0.57cvss 8.8epss 0.00

    KNIME Business Hub is affected by the Ingress-nginx CVE-2025-1974 ( a.k.a IngressNightmare ) vulnerability which affects the ingress-nginx component. In the worst case a complete takeover of the Kubernetes cluster is possible. Since the affected component is only reachable from…

  • CVE-2025-29807HigMar 21, 2025
    risk 0.57cvss 8.7epss 0.01

    Deserialization of untrusted data in Microsoft Dataverse allows an authorized attacker to execute code over a network.

  • CVE-2025-0185HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.01

    A vulnerability in the Dify Tools' Vanna module of the langgenius/dify repository allows for a Pandas Query Injection in the latest version. The vulnerability occurs in the function `vn.get_training_plan_generic(df_information_schema)`, which does not properly sanitize user…

  • CVE-2024-9439HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.01

    SuperAGI is vulnerable to remote code execution in the latest version. The `agent template update` API allows attackers to control certain parameters, which are then fed to the eval function without any sanitization or checks in place. This vulnerability can lead to full system…

  • CVE-2024-12215HigMar 20, 2025
    risk 0.57cvss 8.8epss 0.01

    In kedro-org/kedro version 0.19.8, the `pull_package()` API function allows users to download and extract micro packages from the Internet. However, the function `project_wheel_metadata()` within the code path can execute the `setup.py` file inside the tar file, leading to…