VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 96 of 350
  • CVE-2024-46964HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.

  • CVE-2024-46963HigNov 11, 2024
    risk 0.53cvss 8.1epss 0.00

    The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity component.

  • CVE-2024-46961HigNov 7, 2024
    risk 0.53cvss 8.1epss 0.00

    The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity component.

  • CVE-2024-42041HigOct 30, 2024
    risk 0.53cvss 8.1epss 0.00

    The com.videodownload.browser.videodownloader (aka AppTool-Browser-Video All Video Downloader) application 20-30.05.24 for Android allows an attacker to execute arbitrary JavaScript code via the acr.browser.lightning.DefaultBrowserActivity component.

  • CVE-2024-43393HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP FW_RULESETS.FROM_IP…

  • CVE-2024-43392HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_INCOMING.FROM_IP FW_INCOMING.IN_IP FW_OUTGOING.FROM_IP FW_OUTGOING.IN_IP environment variable…

  • CVE-2024-43391HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet filter, packet forwarding, network access control or NAT through the FW_PORTFORWARDING.SRC_IP environment variable which can lead to a DoS.

  • CVE-2024-43390HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the firewall services, including packet forwarding or NAT through the FW_NAT.IN_IP environment variable which can lead to a DoS.

  • CVE-2024-43389HigSep 10, 2024
    risk 0.53cvss 8.1epss 0.01

    A low privileged remote attacker can perform configuration changes of the ospf service through OSPF_INTERFACE.SIMPLE_KEY, OSPF_INTERFACE.DIGEST_KEY environment variables which can lead to a DoS.

  • CVE-2024-41651HigAug 12, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue in Prestashop v.8.1.7 and before allows a remote attacker to execute arbitrary code via the module upgrade functionality. NOTE: this is disputed by multiple parties, who report that exploitation requires that an attacker be able to hijack network requests made by an…

  • CVE-2024-6507HigJul 4, 2024
    risk 0.53cvss 8.1epss 0.01

    Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API

  • CVE-2024-36598HigJun 14, 2024
    risk 0.53cvss 8.1epss 0.01

    An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.

  • CVE-2024-0867HigMay 24, 2024
    risk 0.53cvss 8.1epss 0.01

    The Email Log plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 2.4.8 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain…

  • CVE-2024-20359MedKEVApr 24, 2024
    risk 0.53cvss 6.0epss 0.19

    A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to…

  • CVE-2023-44857HigApr 12, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue in Cobham SAILOR VSAT Ku v.164B019, allows a remote attacker to execute arbitrary code via a crafted script to the sub_21D24 function in the acu_web component.

  • CVE-2024-31005HigApr 2, 2024
    risk 0.53cvss 8.1epss 0.01

    An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment

  • CVE-2024-0866HigMar 26, 2024
    risk 0.53cvss 8.1epss 0.01

    The Check & Log Email plugin for WordPress is vulnerable to Unauthenticated Hook Injection in all versions up to, and including, 1.0.9 via the check_nonce function. This makes it possible for unauthenticated attackers to execute actions with hooks in WordPress under certain…

  • CVE-2023-47257HigFeb 1, 2024
    risk 0.53cvss 8.1epss 0.01

    ConnectWise ScreenConnect through 23.8.4 allows man-in-the-middle attackers to achieve remote code execution via crafted messages.

  • CVE-2023-43301HigDec 7, 2023
    risk 0.53cvss 8.2epss 0.01

    An issue in DARTS SHOP MAXIM mini-app on Line v13.6.1 allows attackers to send crafted malicious notifications via leakage of the channel access token.

  • CVE-2023-20063HigNov 1, 2023
    risk 0.53cvss 8.2epss 0.00

    A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated, local attacker to execute arbitrary…