VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 81 of 350
  • CVE-2022-41264HigDec 13, 2022
    risk 0.57cvss 8.8epss 0.01

    Due to the unrestricted scope of the RFC function module, SAP BASIS - versions 731, 740, 750, 751, 752, 753, 754, 755, 756, 757, 789, 790, 791, allows an authenticated non-administrator attacker to access a system class and execute any of its public methods with parameters…

  • CVE-2022-3713HigDec 1, 2022
    risk 0.57cvss 8.8epss 0.01

    A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.

  • CVE-2022-44262CriDec 1, 2022
    risk 0.57cvss 9.8epss 0.01

    ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).

  • CVE-2022-44136CriNov 30, 2022
    risk 0.57cvss 9.8epss 0.01

    Zenario CMS 9.3.57186 is vulnerable to Remote Code Excution (RCE).

  • CVE-2022-45908CriNov 26, 2022
    risk 0.57cvss 9.8epss 0.01

    In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.

  • CVE-2022-45907CriNov 26, 2022
    risk 0.57cvss 9.8epss 0.01

    In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.

  • CVE-2022-40127HigNov 14, 2022
    risk 0.57cvss 8.8epss 0.86

    A vulnerability in Example Dags of Apache Airflow allows an attacker with UI access who can trigger DAGs, to execute arbitrary commands via manually provided run_id parameter. This issue affects Apache Airflow Apache Airflow versions prior to 2.4.0.

  • CVE-2022-44794HigNov 7, 2022
    risk 0.57cvss 8.8epss 0.01

    An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate input parameters. As a result, arbitrary…

  • CVE-2022-39365CriOct 27, 2022
    risk 0.57cvss 9.8epss 0.02

    Pimcore is an open source data and experience management platform. Prior to version 10.5.9, the user controlled twig templates rendering in `Pimcore/Mail` & `ClassDefinition\Layout\Text` is vulnerable to server-side template injection, which could lead to remote code execution.…

  • CVE-2022-42902HigOct 13, 2022
    risk 0.57cvss 8.8epss 0.01

    In Linaro Automated Validation Architecture (LAVA) before 2022.10, there is dynamic code execution in lava_server/lavatable.py. Due to improper input sanitization, an anonymous user can force the lava-server-gunicorn service to execute user-provided code on the server.

  • CVE-2022-40469HigOct 12, 2022
    risk 0.57cvss 8.8epss 0.02

    iKuai OS v3.6.7 was discovered to contain an authenticated remote code execution (RCE) vulnerability.

  • CVE-2022-40486HigSep 28, 2022
    risk 0.57cvss 8.8epss 0.02

    TP Link Archer AX10 V1 Firmware Version 1.3.1 Build 20220401 Rel. 57450(5553) was discovered to allow authenticated attackers to execute arbitrary code via a crafted backup file.

  • CVE-2022-26112CriSep 23, 2022
    risk 0.57cvss 9.8epss 0.01

    In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function support by default from Pinot release 0.11.0.…

  • CVE-2022-28640HigSep 20, 2022
    risk 0.57cvss 8.8epss 0.01

    A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard Enterprise has provided updated…

  • CVE-2022-35777HigAug 9, 2022
    risk 0.57cvss 8.8epss 0.02

    Visual Studio Remote Code Execution Vulnerability

  • CVE-2021-22646HigJul 28, 2022
    risk 0.57cvss 8.8epss 0.01

    The “ipk” package containing the configuration created by TWinSoft can be uploaded, extracted, and executed in Ovarro TBox, allowing malicious code execution.

  • CVE-2021-40553HigJun 28, 2022
    risk 0.57cvss 8.8epss 0.02

    piwigo 11.5.0 is affected by a remote code execution (RCE) vulnerability in the LocalFiles Editor.

  • CVE-2021-41402HigJun 16, 2022
    risk 0.57cvss 8.8epss 0.01

    flatCore-CMS v2.0.8 has a code execution vulnerability, which could let a remote malicious user execute arbitrary PHP code.

  • CVE-2022-21831CriMay 26, 2022
    risk 0.57cvss 9.8epss 0.03

    A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.

  • CVE-2021-40219HigApr 11, 2022
    risk 0.57cvss 8.8epss 0.03

    Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution.