CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-37845
HIGH
MangoOS < 5.2.0 - Authenticated Remote Code Execution via Active Process Command
CVSS 7.2
CVE-2024-48700
HIGH
Kliqqi-CMS < 3.5.2 - Remote Code Execution via edit_page.php
CVSS 7.2
CVE-2024-48655
HIGH
Total.js CMS 1.0 - Remote Code Execution via func.js File
CVSS 8.8
CVE-2024-48581
CRITICAL
Best Courier Management System 1.0 - Remote Code Execution via Admin Class File Upload
CVSS 9.8
CVE-2024-48579
CRITICAL
Best House Rental Management System 1.0 - SQL Injection via Login Username Parameter
CVSS 9.8
CVE-2024-48204
CRITICAL
Hanzhou Haobo network management system 1.0 - RCE
CVSS 9.8
CVE-2024-47158
MEDIUM
N-LINE < 2.0.6 - Remote Code Execution
CVSS 5.4
CVE-2024-47879
HIGH
OpenRefine < 3.8.3 - Cross-Site Request Forgery via Preview Expression Command
CVSS 7.6
CVE-2024-48514
CRITICAL
php-heic-to-jpg <= 1.0.5 - Remote Code Execution via HEIC Image Filename
CVSS 9.8
CVE-2024-48964
HIGH
Snyk CLI < 1.1294.0 - Code Injection via Gradle Project Directory Handling
CVSS 7.5
CVE-2024-20485
MEDIUM
Cisco Adaptive Security Appliance Software - Authenticated Remote Code Execution via Crafted Backup File
CVSS 6.0
CVE-2024-9050
HIGH
Red Hat Enterprise Linux NetworkManager-libreswan - Local Privilege Escalation via VPN Configuration Injection
CVSS 7.8
CVE-2024-41714
HIGH
Mitel MiCollab < 9.8.1.5 & MiVoice Business < 1.0.0.27 - Authenticated Command Injection
CVSS 8.8
CVE-2024-41712
MEDIUM
Mitel MiCollab <= 9.8.1.5 - Authenticated Command Injection in Web Conferencing Component
CVSS 6.6
CVE-2024-35315
MEDIUM
Mitel Micollab < 9.7.1.110 - Code Injection
CVSS 5.6
CVE-2024-35314
CRITICAL
Mitel MiCollab <= 9.7.1.110 & MiVoice Business Virtual Instance 1.0.0.25 - Unauthenticated Command Injection
CVSS 9.8
CVE-2024-10131
HIGH
ragflow 0.11.0 - Remote Code Execution via add_llm Function
CVSS 8.8
CVE-2024-9593
HIGH
Time Clock and Time Clock Pro <= 1.2.2 - Unauthenticated Remote Code Execution via etimeclockwp_load_function_callback
CVSS 8.3
CVE-2024-9264
CRITICAL
Grafana 11.0.0-11.0.5 - Authenticated Command Injection via DuckDB SQL Expressions
CVSS 9.9
CVE-2024-27766
MEDIUM
MariaDB 11.1 - Remote Code Execution via lib_mysqludf_sys.so Function
CVSS 5.7
CVE-2024-10073
MEDIUM
flairNLP flair 0.14.0 - Code Injection
CVSS 5.0
CVE-2024-45766
HIGH
Dell OpenManage Enterprise < 4.2.0 - Authenticated Remote Code Execution
CVSS 8.0
CVE-2024-48744
MEDIUM
PHPGurukul Teachers Record Management System 2.1 - Reflected Cross-Site Scripting via Search Input Parameter
CVSS 6.1
CVE-2024-49254
CRITICAL
ajax-extend <= 1.0 - Remote Code Execution
CVSS 10.0
CVE-2024-49271
CRITICAL
Unlimited Elements For Elementor < 1.5.121 - Remote Code Execution via Untrusted Data Deserialization
CVSS 9.1
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium