VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 78 of 350
  • CVE-2023-41450HigSep 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.

  • CVE-2023-40221HigSep 18, 2023
    risk 0.57cvss 8.8epss 0.01

    The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section (MAIL SERVER) where the information is…

  • CVE-2022-41763HigSep 5, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in NOKIA AMS 9.7.05. Remote Code Execution exists via the debugger of the ipAddress variable. A remote user, authenticated to the AMS server, could inject code in the PING function. The privileges of the command executed depend on the user that runs the…

  • CVE-2023-39631CriSep 1, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.

  • CVE-2023-39059HigAug 28, 2023
    risk 0.57cvss 8.8epss 0.01

    An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.

  • CVE-2023-40177CriAug 23, 2023
    risk 0.57cvss 9.9epss 0.01

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus effectively performing rights escalation.…

  • CVE-2023-36281CriAug 22, 2023
    risk 0.57cvss 9.8epss 0.03

    An issue in langchain v.0.0.171 allows a remote attacker to execute arbitrary code via a JSON file to load_prompt. This is related to __subclasses__ or a template.

  • CVE-2023-39660CriAug 21, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.

  • CVE-2023-39445HigAug 18, 2023
    risk 0.57cvss 8.8epss 0.01

    Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.

  • CVE-2023-37914CriAug 17, 2023
    risk 0.57cvss 9.9epss 0.02

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote code execution including unrestricted read…

  • CVE-2023-39662CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in llama_index v.0.7.13 and before allows a remote attacker to execute arbitrary code via the `exec` parameter in PandasQueryEngine function.

  • CVE-2023-38896CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.02

    An issue in Harrison Chase langchain v.0.0.194 and before allows a remote attacker to execute arbitrary code via the from_math_prompt and from_colored_object_prompt functions.

  • CVE-2023-38860CriAug 15, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.

  • CVE-2023-36095CriAug 5, 2023
    risk 0.57cvss 9.8epss 0.01

    An issue in Harrison Chase langchain v.0.0.194 allows an attacker to execute arbitrary code via the python exec calls in the PALChain, affected functions include from_math_prompt and from_colored_object_prompt.

  • CVE-2023-38943HigAug 5, 2023
    risk 0.57cvss 8.8epss 0.02

    ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.

  • CVE-2023-39020CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.

  • CVE-2023-39010CriJul 28, 2023
    risk 0.57cvss 9.8epss 0.01

    BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.

  • CVE-2023-22506HigJul 19, 2023
    risk 0.57cvss 8.8epss 0.02

    This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center.   This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.5, allows an authenticated attacker…

  • CVE-2023-37466CriJul 14, 2023
    risk 0.57cvss 9.8epss 0.04

    vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanitization can be bypassed with the…

  • CVE-2023-35333HigJul 11, 2023
    risk 0.57cvss 8.8epss 0.01

    MediaWiki PandocUpload Extension Remote Code Execution Vulnerability