CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-37849
CRITICAL
itsourcecode Billing System 1.0 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2024-1577
CRITICAL
MegaBIP <= 5.11.2 - Unauthenticated Remote Code Execution via PHP File Upload
CVSS 9.8
CVE-2024-5834
HIGH
Google Chrome < 126.0.6478.54 - Remote Code Execution via Dawn Implementation
CVSS 8.8
CVE-2024-34405
CRITICAL
McAfee Security: Antivirus VPN <8.3.0 - Open Redirect
CVSS 9.1
CVE-2024-27857
HIGH
Apple iOS, macOS, tvOS, and visionOS - Remote Code Execution via Out-of-Bounds Access
CVSS 7.8
CVE-2024-37014
CRITICAL
Langflow < 0.6.19 - Remote Code Execution via Custom Component Endpoint
CVSS 9.8
CVE-2024-34761
HIGH
WPENGINE INC Advanced Custom Fields PRO <6.2.10 - Code Injection
CVSS 8.5
CVE-2024-36531
MEDIUM
nukeviet and nukeviet-egov < 4.5.05 and < 1.2.02 - Remote Code Execution via Admin Extensions Upload
CVSS 5.7
CVE-2024-3408
CRITICAL
D-Tale RCE
CVSS 9.8
CVE-2024-4889
HIGH
litellm < 1.44.16 - Code Injection via UI_LOGO_PATH and SAVE_CONFIG_TO_DB Environment Variables
CVSS 7.2
CVE-2024-4194
MEDIUM
The Album & Image Gallery plus Lightbox <2.0 - RCE
CVSS 6.5
CVE-2024-37273
CRITICAL
Jan v0.4.12 - Arbitrary File Upload via /v1/app/appendFileSync Interface
CVSS 9.8
CVE-2024-25600
CRITICAL
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
CVE-2024-37061
HIGH
MLflow >= 1.11.0 - Remote Code Execution via Malicious MLproject
CVSS 8.8
CVE-2024-36568
CRITICAL
Sourcecodester Gas Agency Management System v1.0 - SQL Injection
CVSS 9.8
CVE-2024-36120
HIGH
javascript-deobfuscator <1.1.0 - RCE
CVSS 8.1
CVE-2024-5565
HIGH
Vanna - Remote Code Execution via Prompt Injection
CVSS 8.1
CVE-2024-23692
CRITICAL
KEV
Rejetto HTTP File Server - Template injection
CVSS 9.8
CVE-2024-3924
MEDIUM
huggingface/text-generation-inference <= 2.0.0 - Remote Code Execution via GitHub Actions Workflow
CVSS 4.4
CVE-2024-35226
HIGH
Smarty 3.0.0-4.5.2 and 5.0.0-5.1.0 - PHP Code Injection via Extends Tag Filename
CVSS 7.3
CVE-2024-35581
MEDIUM
Sourcecodester Laboratory Management System 1.0 - Stored Cross-Site Scripting via Borrower Name Input
CVSS 6.1
CVE-2024-23601
CRITICAL
AutomationDirect P3-550E 1.2.10.9 - Arbitrary Code Execution via Crafted scan_lib.bin
CVSS 9.8
CVE-2024-28886
HIGH
UTAU < 0.4.19 - OS Command Injection via Crafted UST File
CVSS 8.4
CVE-2024-5407
CRITICAL
RhinOS 3.0-1190 - Remote Code Execution via Search Parameter
CVSS 10.0
CVE-2024-35339
CRITICAL
Tenda FH1206 V1.2.0.8(8155) - OS Command Injection via mac Parameter
CVSS 9.8
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium