VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 75 of 350
  • CVE-2024-37061HigJun 4, 2024
    risk 0.57cvss 8.8epss 0.01

    Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.

  • CVE-2024-4662HigMay 23, 2024
    risk 0.57cvss 8.8epss 0.01

    The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This makes it possible for lower privileged…

  • CVE-2024-24294CriMay 20, 2024
    risk 0.57cvss 9.8epss 0.01

    A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.

  • CVE-2024-32680HigMay 17, 2024
    risk 0.57cvss 8.8epss 0.01

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Malicious Files, Code Inclusion.This issue…

  • CVE-2024-32352HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.

  • CVE-2024-32350HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.02

    TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.

  • CVE-2024-4605HigMay 14, 2024
    risk 0.57cvss 8.8epss 0.01

    The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes it possible for lower privileged users,…

  • CVE-2024-30973HigMay 6, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/formAcc.

  • CVE-2024-34461CriMay 4, 2024
    risk 0.57cvss 9.8epss 0.01

    Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.

  • CVE-2024-33430HigMay 1, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.

  • CVE-2024-21511CriApr 23, 2024
    risk 0.57cvss 9.8epss 0.01

    Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.

  • CVE-2024-3660CriApr 16, 2024
    risk 0.57cvss 9.8epss 0.02

    A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the application.

  • CVE-2024-21508CriApr 11, 2024
    risk 0.57cvss 9.8epss 0.03

    Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.

  • CVE-2024-26362HigApr 10, 2024
    risk 0.57cvss 8.8epss 0.01

    HTML injection vulnerability in Enpass Password Manager Desktop Client 6.9.2 for Windows and Linux allows attackers to run arbitrary HTML code via creation of crafted note.

  • CVE-2024-3098CriApr 10, 2024
    risk 0.57cvss 9.8epss 0.01

    A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient validation of input, which can be…

  • CVE-2024-31864CriApr 9, 2024
    risk 0.57cvss 9.8epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppelin: before 0.11.1. Users are…

  • CVE-2024-30565HigApr 4, 2024
    risk 0.57cvss 8.8epss 0.02

    An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.

  • CVE-2024-29477HigApr 3, 2024
    risk 0.57cvss 8.8epss 0.01

    Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.

  • CVE-2024-31003HigApr 2, 2024
    risk 0.57cvss 8.8epss 0.01

    Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.

  • CVE-2024-23755HigMar 23, 2024
    risk 0.57cvss 8.8epss 0.01

    ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.