CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-6655
HIGH
Red Hat Enterprise Linux 8 - Code Injection via GTK Library Loading
CVSS 7.0
CVE-2024-39915
CRITICAL
Thruk < 3.16 - Authenticated Remote Code Execution via PDF Report URL Parameter
CVSS 9.9
CVE-2024-36456
CRITICAL
Broadcom Symantec PAM 3.4.6 and 4.1.0-4.1.7 - Unauthenticated Remote Command Execution
CVE-2024-21513
HIGH
langchain-experimental 0.0.15-<0.0.21 - Remote Code Execution via VectorSQLDatabaseChain Eval
CVSS 8.5
CVE-2024-6345
HIGH
setuptools < 70.0.0 - Remote Code Execution via Package Index Download Functions
CVSS 8.8
CVE-2024-40552
HIGH
PublicCMS < 4.0.202302.e - Remote Code Execution via cmdarray Parameter
CVSS 8.8
CVE-2024-40546
HIGH
PublicCMS < 4.0.202302.e - Arbitrary File Upload via /admin/cmsWebFile/save
CVSS 8.8
CVE-2024-40522
HIGH
SeaCMS 12.9 - Authenticated Remote Code Execution via phomebak.php Variable Injection
CVSS 8.8
CVE-2024-40521
HIGH
SeaCMS 12.9 - Authenticated Remote Code Execution via admin_template.php
CVSS 8.8
CVE-2024-37405
MEDIUM
Rocket.Chat - Unauthenticated NoSQL Injection in Livechat Login and History Endpoints
CVSS 6.5
CVE-2024-37149
HIGH
GLPI 0.85-10.0.15 - Authenticated Remote Code Execution via Plugin Loader Hijack
CVSS 7.2
CVE-2024-25077
CRITICAL
Renesas SmartBond DA14691, DA14695, DA14697, and DA14699 - Arbitrary Code Execution via Nonce Manipulation
CVSS 9.8
CVE-2024-37770
CRITICAL
14Finger v1.1 - Remote Code Execution via Fingerprint Function
CVSS 9.1
CVE-2024-21832
LOW
PingFederate 11.0.0-11.0.8, 11.1.0-11.1.8, 11.2.0-11.2.7, 11.3.0-11.3.3 - JSON Injection via REST API POST Request
CVSS 3.5
CVE-2024-39071
CRITICAL
Fujian Kelixun <=7.6.6.4391 - SQL Injection
CVSS 9.8
CVE-2024-40735
MEDIUM
NetBox 4.0.3 - Stored Cross-Site Scripting via Power Outlet Name Parameter
CVSS 6.1
CVE-2024-40726
MEDIUM
NetBox 4.0.3 - Stored Cross-Site Scripting via Power Port Name Parameter
CVSS 6.1
CVE-2024-6602
CRITICAL
Firefox < 128 and ESR < 115.13 - Memory Corruption via Allocator-Deallocator Mismatch
CVSS 9.8
CVE-2024-37934
MEDIUM
Ninja Forms < 3.8.4 - Code Injection via Arbitrary Shortcode Execution
CVSS 5.4
CVE-2024-6365
CRITICAL
Product Table by WBW < 2.0.1 - Unauthenticated Remote Code Execution via saveCustomTitle Function
CVSS 9.8
CVE-2024-22020
MEDIUM
Node.js < 18.20.4, 20.0-20.15.1, 22.0-22.4.1 - Remote Code Execution via Data URL Network Import Bypass
CVSS 6.5
CVE-2024-39864
CRITICAL
Apache CloudStack 4.0.0-4.18.2.0 - Unauthenticated Remote Code Execution via Integration API Service
CVSS 9.8
CVE-2024-38346
CRITICAL
Apache CloudStack 4.0.0-4.18.2.0 - Unauthenticated Remote Code Execution via Cluster Service Port
CVSS 9.8
CVE-2024-39932
CRITICAL
Gogs < 0.13.0 - Argument Injection via Change Preview
CVSS 9.9
CVE-2024-39165
CRITICAL
Asial JpGraph Professional <4.2.6-pro - RCE
CVSS 9.8
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium