CWE-94
Improper Control of Generation of Code ('Code Injection')
Description
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
Hierarchy (View 1000)
Related attack patterns (CAPEC)
CAPEC-242 · CAPEC-35 · CAPEC-77
CVEs mapped to this weakness (6,984)
page 82 of 350| CVE | Vendor / Product | Sev | Risk | CVSS | EPSS | KEV | Published | Description |
|---|---|---|---|---|---|---|---|---|
| CVE-2021-39114 | Hig | 0.57 | 8.8 | 0.02 | Apr 5, 2022 | Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23,… | ||
| CVE-2022-23812 | Cri | 0.57 | 9.8 | 0.04 | Mar 16, 2022 | This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code… | ||
| CVE-2021-44618 | Cri | 0.57 | 9.8 | 0.01 | Mar 11, 2022 | A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header. | ||
| CVE-2022-22985 | Hig | 0.57 | 8.8 | 0.01 | Mar 10, 2022 | The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the specific web section where the information is displayed. Injection can be done… | ||
| CVE-2022-0895 | Cri | 0.57 | 9.8 | 0.02 | Mar 10, 2022 | Static Code Injection in GitHub repository microweber/microweber prior to 1.3. | ||
| CVE-2022-0845 | Cri | 0.57 | 9.8 | 0.01 | Mar 5, 2022 | Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0. | ||
| CVE-2022-25018 | Hig | 0.57 | 8.8 | 0.03 | Mar 1, 2022 | Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages. | ||
| CVE-2022-23340 | Cri | 0.57 | 9.8 | 0.02 | Feb 8, 2022 | Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results. | ||
| CVE-2021-46114 | Hig | 0.57 | 8.8 | 0.01 | Jan 26, 2022 | jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code. | ||
| CVE-2021-43269 | Hig | 0.57 | 8.8 | 0.01 | Jan 20, 2022 | In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for… | ||
| CVE-2021-45806 | Hig | 0.57 | 8.8 | 0.01 | Jan 13, 2022 | jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code. | ||
| CVE-2021-42309 | Hig | 0.57 | 8.8 | 0.03 | Dec 15, 2021 | Microsoft SharePoint Server Remote Code Execution Vulnerability | ||
| CVE-2021-23639 | Cri | 0.57 | 9.8 | 0.05 | Dec 10, 2021 | The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine. | ||
| CVE-2021-29679 | Hig | 0.57 | 8.8 | 0.02 | Oct 15, 2021 | IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915. | ||
| CVE-2021-24546 | Hig | 0.57 | 8.8 | 0.02 | Oct 11, 2021 | The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code | ||
| CVE-2020-21650 | Hig | 0.57 | 8.8 | 0.03 | Oct 6, 2021 | Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method. | ||
| CVE-2020-20124 | Hig | 0.57 | 8.8 | 0.03 | Sep 28, 2021 | Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php. | ||
| CVE-2021-22952 | Hig | 0.57 | 8.8 | 0.01 | Sep 23, 2021 | A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk… | ||
| CVE-2020-22120 | Hig | 0.57 | 8.8 | 0.02 | Aug 18, 2021 | A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code. | ||
| CVE-2021-37694 | Hig | 0.57 | 8.7 | 0.01 | Aug 11, 2021 | @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no… |
- risk 0.57cvss 8.8epss 0.02
Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23,…
- risk 0.57cvss 9.8epss 0.04
This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code…
- risk 0.57cvss 9.8epss 0.01
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
- risk 0.57cvss 8.8epss 0.01
The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the specific web section where the information is displayed. Injection can be done…
- risk 0.57cvss 9.8epss 0.02
Static Code Injection in GitHub repository microweber/microweber prior to 1.3.
- risk 0.57cvss 9.8epss 0.01
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
- risk 0.57cvss 8.8epss 0.03
Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.
- risk 0.57cvss 9.8epss 0.02
Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.
- risk 0.57cvss 8.8epss 0.01
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
- risk 0.57cvss 8.8epss 0.01
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for…
- risk 0.57cvss 8.8epss 0.01
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
- risk 0.57cvss 8.8epss 0.03
Microsoft SharePoint Server Remote Code Execution Vulnerability
- risk 0.57cvss 9.8epss 0.05
The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.
- risk 0.57cvss 8.8epss 0.02
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.
- risk 0.57cvss 8.8epss 0.02
The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code
- risk 0.57cvss 8.8epss 0.03
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.
- risk 0.57cvss 8.8epss 0.03
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
- risk 0.57cvss 8.8epss 0.01
A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk…
- risk 0.57cvss 8.8epss 0.02
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
- risk 0.57cvss 8.7epss 0.01
@asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no…