VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 82 of 350
  • CVE-2021-39114HigApr 5, 2022
    risk 0.57cvss 8.8epss 0.02

    Affected versions of Atlassian Confluence Server and Data Center allow users with a valid account on a Confluence Data Center instance to execute arbitrary Java code or run arbitrary system commands by injecting an OGNL payload. The affected versions are before version 6.13.23,…

  • CVE-2022-23812CriMar 16, 2022
    risk 0.57cvss 9.8epss 0.04

    This affects the package node-ipc from 10.1.1 and before 10.1.3. This package contains malicious code, that targets users with IP located in Russia or Belarus, and overwrites their files with a heart emoji. **Note**: from versions 11.0.0 onwards, instead of having malicious code…

  • CVE-2021-44618CriMar 11, 2022
    risk 0.57cvss 9.8epss 0.01

    A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.

  • CVE-2022-22985HigMar 10, 2022
    risk 0.57cvss 8.8epss 0.01

    The absence of filters when loading some sections in the web application of the vulnerable device allows attackers to inject malicious code that will be interpreted when a legitimate user accesses the specific web section where the information is displayed. Injection can be done…

  • CVE-2022-0895CriMar 10, 2022
    risk 0.57cvss 9.8epss 0.02

    Static Code Injection in GitHub repository microweber/microweber prior to 1.3.

  • CVE-2022-0845CriMar 5, 2022
    risk 0.57cvss 9.8epss 0.01

    Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.

  • CVE-2022-25018HigMar 1, 2022
    risk 0.57cvss 8.8epss 0.03

    Pluxml v5.8.7 was discovered to allow attackers to execute arbitrary code via crafted PHP code inserted into static pages.

  • CVE-2022-23340CriFeb 8, 2022
    risk 0.57cvss 9.8epss 0.02

    Joplin 2.6.10 allows remote attackers to execute system commands through malicious code in user search results.

  • CVE-2021-46114HigJan 26, 2022
    risk 0.57cvss 8.8epss 0.01

    jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.

  • CVE-2021-43269HigJan 20, 2022
    risk 0.57cvss 8.8epss 0.01

    In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1; CrashPlan Cloud; and CrashPlan for…

  • CVE-2021-45806HigJan 13, 2022
    risk 0.57cvss 8.8epss 0.01

    jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.

  • CVE-2021-42309HigDec 15, 2021
    risk 0.57cvss 8.8epss 0.03

    Microsoft SharePoint Server Remote Code Execution Vulnerability

  • CVE-2021-23639CriDec 10, 2021
    risk 0.57cvss 9.8epss 0.05

    The package md-to-pdf before 5.0.0 are vulnerable to Remote Code Execution (RCE) due to utilizing the library gray-matter to parse front matter content, without disabling the JS engine.

  • CVE-2021-29679HigOct 15, 2021
    risk 0.57cvss 8.8epss 0.02

    IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 199915.

  • CVE-2021-24546HigOct 11, 2021
    risk 0.57cvss 8.8epss 0.02

    The Gutenberg Block Editor Toolkit – EditorsKit WordPress plugin before 1.31.6 does not sanitise and validate the Conditional Logic of the Custom Visibility settings, allowing users with a role as low contributor to execute Arbitrary PHP code

  • CVE-2020-21650HigOct 6, 2021
    risk 0.57cvss 8.8epss 0.03

    Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.

  • CVE-2020-20124HigSep 28, 2021
    risk 0.57cvss 8.8epss 0.03

    Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.

  • CVE-2021-22952HigSep 23, 2021
    risk 0.57cvss 8.8epss 0.01

    A vulnerability found in UniFi Talk application V1.12.3 and earlier permits a malicious actor who has already gained access to a network to subsequently control Talk device(s) assigned to said network if they are not yet adopted. This vulnerability is fixed in UniFi Talk…

  • CVE-2020-22120HigAug 18, 2021
    risk 0.57cvss 8.8epss 0.02

    A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.

  • CVE-2021-37694HigAug 11, 2021
    risk 0.57cvss 8.7epss 0.01

    @asyncapi/java-spring-cloud-stream-template generates a Spring Cloud Stream (SCSt) microservice. In versions prior to 0.7.0 arbitrary code injection was possible when an attacker controls the AsyncAPI document. An example is provided in GHSA-xj6r-2jpm-qvxp. There are no…