VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 76 of 350
  • CVE-2024-28847HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.02

    OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue, `AlertUtil::validateExpression` is also called from…

  • CVE-2024-27756HigMar 15, 2024
    risk 0.57cvss 8.8epss 0.01

    GLPI through 10.0.12 allows CSV injection by an attacker who is able to create an asset with a crafted title.

  • CVE-2024-28424HigMar 14, 2024
    risk 0.57cvss 8.8epss 0.01

    zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.

  • CVE-2023-50379HigFeb 27, 2024
    risk 0.57cvss 8.8epss 0.01

    Malicious code injection in Apache Ambari in prior to 2.7.8. Users are recommended to upgrade to version 2.7.8, which fixes this issue. Impact: A Cluster Operator can manipulate the request by adding a malicious code injection and gain a root over the cluster main host.

  • CVE-2024-26483HigFeb 22, 2024
    risk 0.57cvss 8.8epss 0.01

    An arbitrary file upload vulnerability in the Profile Image module of Kirby CMS v4.1.0 allows attackers to execute arbitrary code via a crafted PDF file.

  • CVE-2023-24333HigFeb 21, 2024
    risk 0.57cvss 8.8epss 0.00

    A stack overflow vulnerability in Tenda AC21 with firmware version US_AC21V1.0re_V16.03.08.15_cn_TDC01 allows attackers to run arbitrary commands via crafted POST request to /goform/openSchedWifi.

  • CVE-2023-49109CriFeb 20, 2024
    risk 0.57cvss 9.8epss 0.02

    Exposure of Remote Code Execution in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.

  • CVE-2024-22514HigFeb 6, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.

  • CVE-2023-6996HigFeb 5, 2024
    risk 0.57cvss 8.8epss 0.01

    The Display custom fields in the frontend – Post and User Profile Fields plugin for WordPress is vulnerable to Code Injection via the plugin's vg_display_data shortcode in all versions up to, and including, 1.2.1 due to insufficient input validation and restriction on access…

  • CVE-2024-24469HigFeb 5, 2024
    risk 0.57cvss 8.8epss 0.01

    Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.

  • CVE-2024-22899HigFeb 2, 2024
    risk 0.57cvss 8.8epss 0.02

    Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.

  • CVE-2024-0755HigJan 23, 2024
    risk 0.57cvss 8.8epss 0.01

    Memory safety bugs present in Firefox 121, Firefox ESR 115.6, and Thunderbird 115.6. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary code. This vulnerability affects Firefox <…

  • CVE-2024-23750HigJan 22, 2024
    risk 0.57cvss 8.8epss 0.01

    MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.

  • CVE-2024-23731CriJan 21, 2024
    risk 0.57cvss 9.8epss 0.01

    The OpenAPI loader in Embedchain before 0.1.57 allows attackers to execute arbitrary code, related to the openapi.py yaml.load function argument.

  • CVE-2024-21673HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:H allows an…

  • CVE-2024-21672HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H allows an…

  • CVE-2023-22526HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.02

    This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execute arbitrary code which has high impact…

  • CVE-2023-43449HigJan 16, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue in HummerRisk HummerRisk v.1.10 thru 1.4.1 allows an authenticated attacker to execute arbitrary code via a crafted request to the service/LicenseService component.

  • CVE-2023-51066HigJan 13, 2024
    risk 0.57cvss 8.8epss 0.01

    An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.

  • CVE-2023-33472HigJan 13, 2024
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function.