CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 73 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2024-21534 | Cri | 0.57 | 9.8 | 0.09 | Oct 11, 2024 | All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix… | ||
| CVE-2024-46489 | Hig | 0.57 | 8.8 | 0.01 | Sep 25, 2024 | A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL. | ||
| CVE-2024-37779 | Hig | 0.57 | 8.8 | 0.01 | Sep 23, 2024 | WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality. | ||
| CVE-2024-43469 | Hig | 0.57 | 8.8 | 0.02 | Sep 10, 2024 | Azure CycleCloud Remote Code Execution Vulnerability | ||
| CVE-2024-43388 | Hig | 0.57 | 8.8 | 0.01 | Sep 10, 2024 | A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation. | ||
| CVE-2024-42902 | Hig | 0.57 | 8.8 | 0.01 | Sep 3, 2024 | An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function | ||
| CVE-2023-26324 | Hig | 0.57 | 8.8 | 0.01 | Aug 28, 2024 | A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code. | ||
| CVE-2023-26322 | Hig | 0.57 | 8.8 | 0.01 | Aug 28, 2024 | A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code. | ||
| CVE-2024-45258 | Cri | 0.57 | 9.8 | 0.01 | Aug 25, 2024 | The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design. | ||
| CVE-2024-7559 | Hig | 0.57 | 8.8 | 0.01 | Aug 23, 2024 | The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers,… | ||
| CVE-2024-42599 | Hig | 0.57 | 8.8 | 0.01 | Aug 22, 2024 | SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the… | ||
| CVE-2024-40453 | Cri | 0.57 | 9.8 | 0.01 | Aug 21, 2024 | squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName. | ||
| CVE-2024-43202 | Cri | 0.57 | 9.8 | 0.02 | Aug 20, 2024 | Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue. | ||
| CVE-2024-42739 | Hig | 0.57 | 8.8 | 0.02 | Aug 13, 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | ||
| CVE-2024-42745 | Hig | 0.57 | 8.8 | 0.02 | Aug 12, 2024 | In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands. | ||
| CVE-2024-5651 | Hig | 0.57 | 8.8 | 0.01 | Aug 12, 2024 | A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer… | ||
| CVE-2024-6891 | Hig | 0.57 | 8.8 | 0.01 | Aug 8, 2024 | Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow. | ||
| CVE-2024-7520 | Hig | 0.57 | 8.8 | 0.01 | Aug 6, 2024 | A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1. | ||
| CVE-2024-34344 | Hig | 0.57 | 8.8 | 0.01 | Aug 5, 2024 | Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them… | ||
| CVE-2024-36268 | Cri | 0.57 | 9.8 | 0.01 | Aug 2, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve… |
- risk 0.57cvss 9.8epss 0.09
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix…
- risk 0.57cvss 8.8epss 0.01
A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.
- risk 0.57cvss 8.8epss 0.01
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
- risk 0.57cvss 8.8epss 0.02
Azure CycleCloud Remote Code Execution Vulnerability
- risk 0.57cvss 8.8epss 0.01
A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.
- risk 0.57cvss 8.8epss 0.01
An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function
- risk 0.57cvss 8.8epss 0.01
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
- risk 0.57cvss 8.8epss 0.01
A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.
- risk 0.57cvss 9.8epss 0.01
The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.
- risk 0.57cvss 8.8epss 0.01
The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers,…
- risk 0.57cvss 8.8epss 0.01
SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…
- risk 0.57cvss 9.8epss 0.01
squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.
- risk 0.57cvss 9.8epss 0.02
Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.
- risk 0.57cvss 8.8epss 0.02
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
- risk 0.57cvss 8.8epss 0.02
In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.
- risk 0.57cvss 8.8epss 0.01
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer…
- risk 0.57cvss 8.8epss 0.01
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
- risk 0.57cvss 8.8epss 0.01
A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.
- risk 0.57cvss 8.8epss 0.01
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them…
- risk 0.57cvss 9.8epss 0.01
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve…