VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 91 of 350
  • CVE-2025-27998HigMay 21, 2025
    risk 0.55cvss 8.4epss 0.00

    An issue in Valvesoftware Steam Client Steam Client 1738026274 allows attackers to escalate privileges via a crafted executable or DLL.

  • CVE-2025-46579HigApr 27, 2025
    risk 0.55cvss 8.4epss 0.00

    There is a DDE injection vulnerability in the GoldenDB database product. Attackers can inject DDE expressions through the interface, and when users download and open the affected file, the DDE commands can be executed.

  • CVE-2025-23186HigApr 8, 2025
    risk 0.55cvss 8.5epss 0.00

    In certain conditions, SAP NetWeaver Application Server ABAP allows an authenticated attacker to craft a Remote Function Call (RFC) request to restricted destinations, which can be used to expose credentials for a remote service. These credentials can then be further exploited…

  • CVE-2024-21760HigMar 18, 2025
    risk 0.55cvss 8.4epss 0.01

    An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated attacker to execute arbitrary code on the…

  • CVE-2024-56051HigDec 18, 2024
    risk 0.55cvss 8.5epss 0.00

    Improper Control of Generation of Code ('Code Injection') vulnerability in VibeThemes WPLMS wplms_plugin allows Code Injection.This issue affects WPLMS: from n/a through < 1.9.9.5.

  • CVE-2024-52899HigNov 26, 2024
    risk 0.55cvss 8.5epss 0.01

    IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.

  • CVE-2024-9593HigOct 18, 2024
    risk 0.55cvss 8.3epss 0.12

    The Time Clock plugin and Time Clock Pro plugin for WordPress are vulnerable to Remote Code Execution in versions up to, and including, 1.2.2 (for Time Clock) and 1.1.4 (for Time Clock Pro) via the 'etimeclockwp_load_function_callback' function. This allows unauthenticated…

  • CVE-2024-45271HigOct 15, 2024
    risk 0.55cvss 8.4epss 0.00

    An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation.

  • CVE-2024-39715HigSep 7, 2024
    risk 0.55cvss 8.5epss 0.01

    A code injection vulnerability that allows a low-privileged user with REST API access granted to remotely upload arbitrary files to the VSPC server using REST API, leading to remote code execution on VSPC server.

  • CVE-2024-38651HigSep 7, 2024
    risk 0.55cvss 8.5epss 0.01

    A code injection vulnerability can allow a low-privileged user to overwrite files on that VSPC server, which can lead to remote code execution on VSPC server.

  • CVE-2024-41961CriAug 1, 2024
    risk 0.55cvss 9.6epss 0.01

    Elektra is an opinionated Openstack Dashboard for Operators and Consumers of Openstack Services. A code injection vulnerability was found in the live search functionality of the Ruby on Rails based Elektra web application. An authenticated user can craft a search term containing…

  • CVE-2024-37855HigJun 25, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.

  • CVE-2024-34761HigJun 10, 2024
    risk 0.55cvss 8.5epss 0.00

    Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fields PRO: from n/a before 6.2.10.

  • CVE-2024-28886HigMay 28, 2024
    risk 0.55cvss 8.4epss 0.01

    OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.

  • CVE-2024-33228HigMay 22, 2024
    risk 0.55cvss 8.4epss 0.00

    An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.

  • CVE-2024-27191HigApr 3, 2024
    risk 0.55cvss 8.5epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in inpersttion Slivery Extender slivery-extender allows Remote Code Inclusion.This issue affects Slivery Extender: from n/a through <= 1.0.2.

  • CVE-2024-23727HigMar 28, 2024
    risk 0.55cvss 8.4epss 0.01

    The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity component.

  • CVE-2024-21737HigJan 9, 2024
    risk 0.55cvss 8.4epss 0.01

    In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the application. This leads to considerable…

  • CVE-2023-22677HigDec 29, 2023
    risk 0.55cvss 8.5epss 0.01

    Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1.8.

  • CVE-2023-46242CriNov 7, 2023
    risk 0.55cvss 9.6epss 0.00

    XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In affected versions it's possible to execute a content with the right of any user via a crafted URL. A user must have `programming` privileges in order to exploit this…