VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 73 of 350
  • CVE-2024-21534CriOct 11, 2024
    risk 0.57cvss 9.8epss 0.09

    All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note:** There were several attempts to fix…

  • CVE-2024-46489HigSep 25, 2024
    risk 0.57cvss 8.8epss 0.01

    A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.

  • CVE-2024-37779HigSep 23, 2024
    risk 0.57cvss 8.8epss 0.01

    WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.

  • CVE-2024-43469HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.02

    Azure CycleCloud Remote Code Execution Vulnerability

  • CVE-2024-43388HigSep 10, 2024
    risk 0.57cvss 8.8epss 0.01

    A low privileged remote attacker with write permissions can reconfigure the SNMP service due to improper input validation.

  • CVE-2024-42902HigSep 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in the js_localize.php function of LimeSurvey v6.6.2 and before allows attackers to execute arbitrary code via injecting a crafted payload into the lng parameter of the js_localize.php function

  • CVE-2023-26324HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2023-26322HigAug 28, 2024
    risk 0.57cvss 8.8epss 0.01

    A code execution vulnerability exists in the XiaomiGetApps application product. This vulnerability is caused by the verification logic being bypassed, and an attacker can exploit this vulnerability to execute malicious code.

  • CVE-2024-45258CriAug 25, 2024
    risk 0.57cvss 9.8epss 0.01

    The req package before 3.43.4 for Go may send an unintended request when a malformed URL is provided, because cleanHost in http.go intentionally uses a "garbage in, garbage out" design.

  • CVE-2024-7559HigAug 23, 2024
    risk 0.57cvss 8.8epss 0.01

    The File Manager Pro plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation and capability checks in the mk_file_folder_manager AJAX action in all versions up to, and including, 8.3.7. This makes it possible for authenticated attackers,…

  • CVE-2024-42599HigAug 22, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 13.0 has a remote code execution vulnerability. The reason for this vulnerability is that although admin_files.php imposes restrictions on edited files, attackers can still bypass these restrictions and write code, allowing authenticated attackers to exploit the…

  • CVE-2024-40453CriAug 21, 2024
    risk 0.57cvss 9.8epss 0.01

    squirrellyjs squirrelly v9.0.0 and fixed in v.9.0.1 was discovered to contain a code injection vulnerability via the component options.varName.

  • CVE-2024-43202CriAug 20, 2024
    risk 0.57cvss 9.8epss 0.02

    Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.2. We recommend users to upgrade Apache DolphinScheduler to version 3.2.2, which fixes the issue.

  • CVE-2024-42739HigAug 13, 2024
    risk 0.57cvss 8.8epss 0.02

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setAccessDeviceCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

  • CVE-2024-42745HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.02

    In TOTOLINK X5000r v9.1.0cu.2350_b20230313, the file /cgi-bin/cstecgi.cgi contains an OS command injection vulnerability in setUPnPCfg. Authenticated Attackers can send malicious packet to execute arbitrary commands.

  • CVE-2024-5651HigAug 12, 2024
    risk 0.57cvss 8.8epss 0.01

    A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, for example, a user with developer…

  • CVE-2024-6891HigAug 8, 2024
    risk 0.57cvss 8.8epss 0.01

    Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.

  • CVE-2024-7520HigAug 6, 2024
    risk 0.57cvss 8.8epss 0.01

    A type confusion bug in WebAssembly could be leveraged by an attacker to potentially achieve code execution. This vulnerability affects Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1.

  • CVE-2024-34344HigAug 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScript on the server side, which allows them…

  • CVE-2024-36268CriAug 2, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.13.0 or cherry-pick [1] to solve…