CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-43202
CRITICAL
Apache DolphinScheduler <3.2.2 - RCE
CVSS 9.8
CVE-2024-7899
MEDIUM
InnoCMS 0.3.1 - Remote Code Injection in Backend Page Edit
CVSS 4.7
CVE-2024-42634
CRITICAL
Tenda AC9 <15.03.06.42 - Command Injection
CVSS 9.8
CVE-2024-42739
HIGH
TOTOLINK X5000r v9.1.0cu.2350_b20230313 - Command Injection
CVSS 8.8
CVE-2024-41623
CRITICAL
D3D Security D8801 Firmware V9.1.17.1.4-20180428 - Code Injection via Crafted Payload
CVSS 9.8
CVE-2024-37287
CRITICAL
Kibana 7.7.0-7.17.23 - Authenticated Remote Code Execution via Prototype Pollution in ML and Alerting Connector Features
CVSS 9.1
CVE-2024-43128
MEDIUM
WC Product Table <3.5.1 - Code Injection
CVSS 6.5
CVE-2024-7094
CRITICAL
JS Help Desk & Support Plugin <2.8.7 - RCE
CVSS 9.8
CVE-2024-42745
HIGH
TOTOLINK X5000r v9.1.0cu.2350_b20230313 - Command Injection
CVSS 8.8
CVE-2024-41651
HIGH
PrestaShop < 8.1.7 - Server-Side Request Forgery via Module Upgrade Functionality
CVSS 8.1
CVE-2024-5651
HIGH
Fence Agents Remediation 0.4 for RHEL 8 - Remote Code Execution via SSH/TELNET Path Arguments
CVSS 8.8
CVE-2024-40487
HIGH
Kashipara Live Membership System <1.0 - XSS
CVSS 7.6
CVE-2024-22123
LOW
Zabbix 5.0.0-5.0.41 - Arbitrary File Write via SMS Media GSM Modem File Setting
CVSS 2.7
CVE-2024-22116
CRITICAL
Zabbix 6.4.9-6.4.14 - Authenticated Remote Code Execution via Ping Script Parameter Injection
CVSS 9.9
CVE-2024-37382
HIGH
Ab Initio Metadata Hub and Authorization Gateway < 4.3.1.1 - Remote Code Execution via Import Host Feature
CVSS 7.2
CVE-2024-42356
HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-42355
HIGH
Shopware <6.6.5.1-6.5.8.13 - Code Injection
CVSS 8.3
CVE-2024-3958
MEDIUM
GitLab < 17.0.6, 17.1 < 17.1.4, 17.2 < 17.2.2 - Code Injection via Repository Display Discrepancy
CVSS 5.3
CVE-2024-6891
HIGH
journyx - Authenticated Python Code Injection during Login
CVSS 8.8
CVE-2024-42393
CRITICAL
Soft AP Daemon Service - Unauthenticated RCE
CVSS 9.8
CVE-2024-7520
HIGH
Firefox < 129, Firefox ESR < 128.1, and Thunderbird < 128.1 - Remote Code Execution via WebAssembly Type Confusion
CVSS 8.8
CVE-2024-34344
HIGH
Nuxt 3.4.0-3.12.4 - Remote Code Execution via Test Component Path Parameter
CVSS 8.8
CVE-2024-22169
HIGH
WD Discovery <5.0.589 - Code Injection
CVE-2024-41127
HIGH
monkeytype < 24.30.0 - Poisoned Pipeline Execution via GitHub Workflow Artifact Injection
CVSS 8.3
CVE-2024-36268
CRITICAL
Apache InLong <1.12.0 - Code Injection
CVSS 9.8
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium