VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 74 of 350
  • CVE-2024-37901CriJul 31, 2024
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with edit right on any page can perform arbitrary remote code execution by adding instances of `XWiki.SearchSuggestConfig` and `XWiki.SearchSuggestSourceClass` to…

  • CVE-2024-6726HigJul 29, 2024
    risk 0.57cvss 8.8epss 0.01

    Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).

  • CVE-2024-29178HigJul 18, 2024
    risk 0.57cvss 8.8epss 0.01

    On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact vulnerability. Mitigation: all users…

  • CVE-2024-29014HigJul 18, 2024
    risk 0.57cvss 8.8epss 0.02

    Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.

  • CVE-2024-39700CriJul 16, 2024
    risk 0.57cvss 9.9epss 0.01

    JupyterLab extension template is a `copier` template for JupyterLab extensions. Repositories created using this template with `test` option include `update-integration-tests.yml` workflow which has an RCE vulnerability. Extension authors hosting their code on GitHub are urged…

  • CVE-2024-39915CriJul 15, 2024
    risk 0.57cvss 9.9epss 0.01

    Thruk is a multibackend monitoring webinterface for Naemon, Nagios, Icinga and Shinken using the Livestatus API. This authenticated RCE in Thruk allows authorized users with network access to inject arbitrary commands via the URL parameter during PDF report generation. The Thruk…

  • CVE-2024-40552HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    PublicCMS v4.0.202302.e was discovered to contain a remote commande execution (RCE) vulnerability via the cmdarray parameter at /site/ScriptComponent.java.

  • CVE-2024-40546HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the component /admin/cmsWebFile/save of PublicCMS v4.0.202302.e allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2024-40522HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    There is a remote code execution vulnerability in SeaCMS 12.9. The vulnerability is caused by phomebak.php writing some variable names passed in without filtering them before writing them into the php file. An authenticated attacker can exploit this vulnerability to execute…

  • CVE-2024-40521HigJul 12, 2024
    risk 0.57cvss 8.8epss 0.01

    SeaCMS 12.9 has a remote code execution vulnerability. The vulnerability is due to the fact that although admin_template.php imposes certain restrictions on the edited file, attackers can still bypass the restrictions and write code in some way, allowing authenticated attackers…

  • CVE-2024-6365CriJul 9, 2024
    risk 0.57cvss 9.8epss 0.01

    The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended data in the languages/customTitle.php…

  • CVE-2024-39864CriJul 5, 2024
    risk 0.57cvss 9.8epss 0.02

    The CloudStack integration API service allows running its unauthenticated API server (usually on port 8096 when configured and enabled via integration.api.port global setting) for internal portal integrations and for testing purposes. By default, the integration API service port…

  • CVE-2024-33871HigJul 3, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for opvp (and oprp) devices can have an…

  • CVE-2024-39844CriJul 3, 2024
    risk 0.57cvss 9.8epss 0.04

    In ZNC before 1.9.1, remote code execution can occur in modtcl via a KICK.

  • CVE-2024-5751CriJun 27, 2024
    risk 0.57cvss 9.8epss 0.01

    BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and assigns them to `os.environ`. An attacker can…

  • CVE-2024-3562HigJun 20, 2024
    risk 0.57cvss 8.8epss 0.01

    The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the eval() function. This makes it possible…

  • CVE-2024-37821HigJun 18, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.

  • CVE-2024-38458HigJun 16, 2024
    risk 0.57cvss 8.8epss 0.01

    Xenforo before 2.2.16 allows code injection.

  • CVE-2024-32925HigJun 13, 2024
    risk 0.57cvss 8.8epss 0.00

    In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed for exploitation.

  • CVE-2024-5834HigJun 11, 2024
    risk 0.57cvss 8.8epss 0.01

    Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)