CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-45390
HIGH
@blakeembrey/template <1.2.0 - Code Injection
CVSS 7.3
CVE-2024-42902
HIGH
LimeSurvey < 6.6.2 - Remote Code Execution via js_localize.php lng Parameter Injection
CVSS 8.8
CVE-2024-7345
HIGH
Progress OpenEdge < 11.7.18 - Unauthenticated Code Injection via Local ABL Client
CVSS 8.3
CVE-2024-8374
HIGH
UltiMaker Cura <5.7.2 - Code Injection
CVSS 7.8
CVE-2024-45623
CRITICAL
D-Link DAP-2310 Hardware A Firmware 1.16RC028 - RCE
CVSS 9.8
CVE-2024-41369
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-41368
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-41367
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-41366
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-41364
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-41361
CRITICAL
Sourcefabric Phoniebox - Code Injection
CVSS 9.8
CVE-2024-43922
MEDIUM
NitroPack < 1.16.7 - Unauthenticated Code Injection via Arbitrary Shortcode Execution
CVSS 4.8
CVE-2024-7720
CRITICAL
HP Security Manager - Remote Code Execution via Open-Source Library Vulnerability
CVSS 9.8
CVE-2024-7656
HIGH
Image Hotspot by DevVN <1.2.5 - Code Injection
CVSS 8.8
CVE-2024-42845
HIGH
InVesalius <3.1.99998 - Code Injection
CVSS 8.0
CVE-2024-42756
HIGH
Netgear DGN1000WW 1.1.00.45 - Remote Code Execution via Diagnostics Page
CVSS 8.8
CVE-2024-5466
HIGH
ManageEngine OpManager and OpManager MSP < 12.7 - Authenticated Remote Code Execution via Deploy Agent Option
CVSS 8.8
CVE-2024-7559
HIGH
File Manager Pro < 8.3.7 - Authenticated Arbitrary File Upload via mk_file_folder_manager AJAX Action
CVSS 8.8
CVE-2024-45201
HIGH
Llama Index <0.10.38 - Code Injection
CVSS 8.8
CVE-2024-42599
HIGH
SeaCMS 13.0 - Authenticated Remote Code Execution via admin_files.php
CVSS 8.8
CVE-2024-6386
CRITICAL
WPML < 4.6.13 - Authenticated Remote Code Execution via Twig Server-Side Template Injection
CVSS 9.9
CVE-2024-40453
CRITICAL
squirrellyjs <9.0.0 - Code Injection
CVSS 9.8
CVE-2024-42598
MEDIUM
SeaCMS 13.0 - Authenticated Remote Code Execution via admin_editplayer.php
CVSS 6.7
CVE-2024-43404
CRITICAL
Megabot < 1.5.0 - Remote Code Execution via /math Command Expression Parameter
CVSS 9.8
CVE-2024-21689
HIGH
Bamboo 9.1.0-9.2.16 - Authenticated Remote Code Execution
CVSS 8.0
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium