VYPR

CWE-94

Improper Control of Generation of Code ('Code Injection')

BaseDraftLikelihood: Medium

Description

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

Hierarchy (View 1000)

Related attack patterns (CAPEC)

CAPEC-242 · CAPEC-35 · CAPEC-77

CVEs mapped to this weakness (6,984)

page 97 of 350
  • CVE-2023-37424HigAug 22, 2023
    risk 0.53cvss 8.1epss 0.01

    A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's control are met. Successful…

  • CVE-2023-34330HigJul 18, 2023
    risk 0.53cvss 8.2epss 0.01

    AMI SPx contains a vulnerability in the BMC where a user may inject code which could be executed via a Dynamic Redfish Extension interface. A successful exploit of this vulnerability may lead to a loss of confidentiality, integrity, and availability.

  • CVE-2023-23477HigFeb 3, 2023
    risk 0.53cvss 8.1epss 0.02

    IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.

  • CVE-2023-21886HigJan 18, 2023
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple…

  • CVE-2022-39424HigOct 18, 2022
    risk 0.53cvss 8.1epss 0.01

    Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.40. Difficult to exploit vulnerability allows unauthenticated attacker with network access via VRDP to compromise Oracle VM…

  • CVE-2022-25921HigAug 29, 2022
    risk 0.53cvss 8.1epss 0.01

    All versions of package morgan-json are vulnerable to Arbitrary Code Execution due to missing sanitization of input passed to the Function constructor.

  • CVE-2022-35767HigAug 9, 2022
    risk 0.53cvss 8.1epss 0.02

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-35766HigAug 9, 2022
    risk 0.53cvss 8.1epss 0.02

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-34714HigAug 9, 2022
    risk 0.53cvss 8.1epss 0.02

    Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability

  • CVE-2022-0819HigMar 2, 2022
    risk 0.53cvss 8.8epss 0.41

    Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.

  • CVE-2021-32834HigSep 9, 2021
    risk 0.53cvss 8.2epss 0.01

    Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the configured Groovy sandbox. This…

  • CVE-2021-29461HigApr 20, 2021
    risk 0.53cvss 8.1epss 0.02

    Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to 0.0.3 could be exploited to read internal files from the system and write files into the system resulting in remote code…

  • CVE-2021-27928HigMar 19, 2021
    risk 0.53cvss 7.2epss 0.38

    A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untrusted search path leads to eval injection,…

  • CVE-2020-15167HigSep 2, 2020
    risk 0.53cvss 8.2epss 0.00

    In Miller (command line utility) using the configuration file support introduced in version 5.9.0, it is possible for an attacker to cause Miller to run arbitrary code by placing a malicious `.mlrrc` file in the working directory. See linked GitHub Security Advisory for complete…

  • CVE-2020-7710HigAug 21, 2020
    risk 0.53cvss 8.1epss 0.01

    This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.

  • CVE-2019-16255HigNov 26, 2019
    risk 0.53cvss 8.1epss 0.04

    Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an arbitrary Ruby method.

  • CVE-2019-15388HigNov 14, 2019
    risk 0.53cvss 8.1epss 0.01

    The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, versionName=7.1.13). This app contains an…

  • CVE-2019-2390HigAug 30, 2019
    risk 0.53cvss 8.2epss 0.01

    An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This issue MongoDB Server v4.0 versions…

  • CVE-2019-9140HigAug 1, 2019
    risk 0.53cvss 8.1epss 0.01

    When processing Deeplink scheme, Happypoint mobile app 6.3.19 and earlier versions doesn't check Deeplink URL correctly. This could lead to javascript code execution, url redirection, sensitive information disclosure. An attacker can exploit this issue by enticing an…

  • CVE-2018-17170HigJun 28, 2019
    risk 0.53cvss 8.1epss 0.03

    Grouptime Teamwire Desktop Client 1.5.1 prior to 1.9.0 on Windows allows code injection via a template, leading to remote code execution. All backend versions prior to prod-2018-11-13-15-00-42 are affected.