CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 77 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2023-42833 | Hig | 0.57 | 8.8 | 0.01 | Jan 10, 2024 | A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution. | ||
| CVE-2023-51784 | Cri | 0.57 | 9.8 | 0.02 | Jan 3, 2024 | Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it.… | ||
| CVE-2023-46987 | Hig | 0.57 | 8.8 | 0.01 | Dec 28, 2023 | SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php. | ||
| CVE-2023-50723 | Cri | 0.57 | 9.9 | 0.01 | Dec 15, 2023 | XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying… | ||
| CVE-2023-43364 | Cri | 0.57 | 9.8 | 0.03 | Dec 12, 2023 | main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution. | ||
| CVE-2023-42890 | Hig | 0.57 | 8.8 | 0.03 | Dec 12, 2023 | The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution. | ||
| CVE-2023-5500 | Hig | 0.57 | 8.8 | 0.01 | Dec 11, 2023 | This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device. | ||
| CVE-2023-5762 | Hig | 0.57 | 8.8 | 0.02 | Dec 4, 2023 | The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges. | ||
| CVE-2023-48887 | Cri | 0.57 | 9.8 | 0.02 | Dec 1, 2023 | A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request. | ||
| CVE-2023-47444 | Hig | 0.57 | 8.8 | 0.02 | Nov 15, 2023 | An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server. | ||
| CVE-2023-36437 | Hig | 0.57 | 8.8 | 0.02 | Nov 14, 2023 | Azure DevOps Server Remote Code Execution Vulnerability | ||
| CVE-2023-46243 | Cri | 0.57 | 9.9 | 0.01 | Nov 7, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A… | ||
| CVE-2023-46947 | Hig | 0.57 | 8.8 | 0.01 | Nov 3, 2023 | Subrion 4.2.1 has a remote command execution vulnerability in the backend. | ||
| CVE-2023-42658 | Hig | 0.57 | 8.8 | 0.00 | Oct 31, 2023 | Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile. | ||
| CVE-2023-46816 | Hig | 0.57 | 8.8 | 0.01 | Oct 27, 2023 | An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing… | ||
| CVE-2023-37909 | Cri | 0.57 | 9.9 | 0.02 | Oct 25, 2023 | XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arbitrary script macros including Groovy… | ||
| CVE-2023-46055 | Hig | 0.57 | 8.8 | 0.01 | Oct 21, 2023 | An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint. | ||
| CVE-2023-45312 | Hig | 0.57 | 8.8 | 0.02 | Oct 10, 2023 | In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability. | ||
| CVE-2023-44846 | Hig | 0.57 | 8.8 | 0.01 | Oct 10, 2023 | An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component. | ||
| CVE-2023-45311 | Cri | 0.57 | 9.8 | 0.02 | Oct 6, 2023 | fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was… |
- risk 0.57cvss 8.8epss 0.01
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.
- risk 0.57cvss 9.8epss 0.02
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong's 1.10.0 or cherry-pick [1] to solve it.…
- risk 0.57cvss 8.8epss 0.01
SeaCMS v12.9 was discovered to contain a remote code execution (RCE) vulnerability via the component /augap/adminip.php.
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform. Starting in 2.3 and prior to versions 14.10.15, 15.5.2, and 15.7-rc-1, anyone who can edit an arbitrary wiki page in an XWiki installation can gain programming right through several cases of missing escaping in the code for displaying…
- risk 0.57cvss 9.8epss 0.03
main.py in Searchor before 2.4.2 uses eval on CLI input, which may cause unexpected code execution.
- risk 0.57cvss 8.8epss 0.03
The issue was addressed with improved memory handling. This issue is fixed in Safari 17.2, macOS Sonoma 14.2, watchOS 10.2, iOS 17.2 and iPadOS 17.2, tvOS 17.2. Processing web content may lead to arbitrary code execution.
- risk 0.57cvss 8.8epss 0.01
This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device.
- risk 0.57cvss 8.8epss 0.02
The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privileges.
- risk 0.57cvss 9.8epss 0.02
A deserialization vulnerability in Jupiter v1.3.1 allows attackers to execute arbitrary commands via sending a crafted RPC request.
- risk 0.57cvss 8.8epss 0.02
An issue discovered in OpenCart 4.0.0.0 to 4.0.2.3 allows authenticated backend users having common/security write privilege can write arbitrary untrusted data inside config.php and admin/config.php, resulting in remote code execution on the underlying server.
- risk 0.57cvss 8.8epss 0.02
Azure DevOps Server Remote Code Execution Vulnerability
- risk 0.57cvss 9.9epss 0.01
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible for a user to execute any content with the right of an existing document's content author, provided the user have edit right on it. A…
- risk 0.57cvss 8.8epss 0.01
Subrion 4.2.1 has a remote command execution vulnerability in the backend.
- risk 0.57cvss 8.8epss 0.00
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
- risk 0.57cvss 8.8epss 0.01
An issue was discovered in SugarCRM 12 before 12.0.4 and 13 before 13.0.2. A Server Site Template Injection (SSTI) vulnerability has been identified in the GecControl action. By using a crafted request, custom PHP code can be injected via the GetControl action because of missing…
- risk 0.57cvss 9.9epss 0.02
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arbitrary script macros including Groovy…
- risk 0.57cvss 8.8epss 0.01
An issue in ThingNario Photon v.1.0 allows a remote attacker to execute arbitrary code and escalate privileges via a crafted script to the ping function to the "thingnario Logger Maintenance Webpage" endpoint.
- risk 0.57cvss 8.8epss 0.02
In the mtproto_proxy (aka MTProto proxy) component through 0.7.2 for Erlang, a low-privileged remote attacker can access an improperly secured default installation without authenticating and achieve remote command execution ability.
- risk 0.57cvss 8.8epss 0.01
An issue in SeaCMS v.12.8 allows an attacker to execute arbitrary code via the admin_ notify.php component.
- risk 0.57cvss 9.8epss 0.02
fsevents before 1.2.11 depends on the https://fsevents-binaries.s3-us-west-2.amazonaws.com URL, which might allow an adversary to execute arbitrary code if any JavaScript project (that depends on fsevents) distributes code that was obtained from that URL at a time when it was…