CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,507 vulnerabilities with CWE-94
CVE-2024-37845 HIGH
MangoOS < 5.2.0 - Authenticated Remote Code Execution via Active Process Command
CVSS 7.2
CVE-2024-48700 HIGH
Kliqqi-CMS < 3.5.2 - Remote Code Execution via edit_page.php
CVSS 7.2
CVE-2024-48655 HIGH
Total.js CMS 1.0 - Remote Code Execution via func.js File
CVSS 8.8
CVE-2024-48581 CRITICAL
Best Courier Management System 1.0 - Remote Code Execution via Admin Class File Upload
CVSS 9.8
CVE-2024-48579 CRITICAL
Best House Rental Management System 1.0 - SQL Injection via Login Username Parameter
CVSS 9.8
CVE-2024-48204 CRITICAL
Hanzhou Haobo network management system 1.0 - RCE
CVSS 9.8
CVE-2024-47158 MEDIUM
N-LINE < 2.0.6 - Remote Code Execution
CVSS 5.4
CVE-2024-47879 HIGH
OpenRefine < 3.8.3 - Cross-Site Request Forgery via Preview Expression Command
CVSS 7.6
CVE-2024-48514 CRITICAL
php-heic-to-jpg <= 1.0.5 - Remote Code Execution via HEIC Image Filename
CVSS 9.8
CVE-2024-48964 HIGH
Snyk CLI < 1.1294.0 - Code Injection via Gradle Project Directory Handling
CVSS 7.5
CVE-2024-20485 MEDIUM
Cisco Adaptive Security Appliance Software - Authenticated Remote Code Execution via Crafted Backup File
CVSS 6.0
CVE-2024-9050 HIGH
Red Hat Enterprise Linux NetworkManager-libreswan - Local Privilege Escalation via VPN Configuration Injection
CVSS 7.8
CVE-2024-41714 HIGH
Mitel MiCollab < 9.8.1.5 & MiVoice Business < 1.0.0.27 - Authenticated Command Injection
CVSS 8.8
CVE-2024-41712 MEDIUM
Mitel MiCollab <= 9.8.1.5 - Authenticated Command Injection in Web Conferencing Component
CVSS 6.6
CVE-2024-35315 MEDIUM
Mitel Micollab < 9.7.1.110 - Code Injection
CVSS 5.6
CVE-2024-35314 CRITICAL
Mitel MiCollab <= 9.7.1.110 & MiVoice Business Virtual Instance 1.0.0.25 - Unauthenticated Command Injection
CVSS 9.8
CVE-2024-10131 HIGH
ragflow 0.11.0 - Remote Code Execution via add_llm Function
CVSS 8.8
CVE-2024-9593 HIGH
Time Clock and Time Clock Pro <= 1.2.2 - Unauthenticated Remote Code Execution via etimeclockwp_load_function_callback
CVSS 8.3
CVE-2024-9264 CRITICAL
Grafana 11.0.0-11.0.5 - Authenticated Command Injection via DuckDB SQL Expressions
CVSS 9.9
CVE-2024-27766 MEDIUM
MariaDB 11.1 - Remote Code Execution via lib_mysqludf_sys.so Function
CVSS 5.7
CVE-2024-10073 MEDIUM
flairNLP flair 0.14.0 - Code Injection
CVSS 5.0
CVE-2024-45766 HIGH
Dell OpenManage Enterprise < 4.2.0 - Authenticated Remote Code Execution
CVSS 8.0
CVE-2024-48744 MEDIUM
PHPGurukul Teachers Record Management System 2.1 - Reflected Cross-Site Scripting via Search Input Parameter
CVSS 6.1
CVE-2024-49254 CRITICAL
ajax-extend <= 1.0 - Remote Code Execution
CVSS 10.0
CVE-2024-49271 CRITICAL
Unlimited Elements For Elementor < 1.5.121 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.1
Details
Vulnerabilities 6,507
Exploit Likelihood Medium