CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,507 vulnerabilities with CWE-94
CVE-2024-37849 CRITICAL
itsourcecode Billing System 1.0 - SQL Injection via Username Parameter
CVSS 9.8
CVE-2024-1577 CRITICAL
MegaBIP <= 5.11.2 - Unauthenticated Remote Code Execution via PHP File Upload
CVSS 9.8
CVE-2024-5834 HIGH
Google Chrome < 126.0.6478.54 - Remote Code Execution via Dawn Implementation
CVSS 8.8
CVE-2024-34405 CRITICAL
McAfee Security: Antivirus VPN <8.3.0 - Open Redirect
CVSS 9.1
CVE-2024-27857 HIGH
Apple iOS, macOS, tvOS, and visionOS - Remote Code Execution via Out-of-Bounds Access
CVSS 7.8
CVE-2024-37014 CRITICAL
Langflow < 0.6.19 - Remote Code Execution via Custom Component Endpoint
CVSS 9.8
CVE-2024-34761 HIGH
WPENGINE INC Advanced Custom Fields PRO <6.2.10 - Code Injection
CVSS 8.5
CVE-2024-36531 MEDIUM
nukeviet and nukeviet-egov < 4.5.05 and < 1.2.02 - Remote Code Execution via Admin Extensions Upload
CVSS 5.7
CVE-2024-3408 CRITICAL
D-Tale RCE
CVSS 9.8
CVE-2024-4889 HIGH
litellm < 1.44.16 - Code Injection via UI_LOGO_PATH and SAVE_CONFIG_TO_DB Environment Variables
CVSS 7.2
CVE-2024-4194 MEDIUM
The Album & Image Gallery plus Lightbox <2.0 - RCE
CVSS 6.5
CVE-2024-37273 CRITICAL
Jan v0.4.12 - Arbitrary File Upload via /v1/app/appendFileSync Interface
CVSS 9.8
CVE-2024-25600 CRITICAL
Unauthenticated Remote Code Execution - Bricks <= 1.9.6
CVSS 10.0
CVE-2024-37061 HIGH
MLflow >= 1.11.0 - Remote Code Execution via Malicious MLproject
CVSS 8.8
CVE-2024-36568 CRITICAL
Sourcecodester Gas Agency Management System v1.0 - SQL Injection
CVSS 9.8
CVE-2024-36120 HIGH
javascript-deobfuscator <1.1.0 - RCE
CVSS 8.1
CVE-2024-5565 HIGH
Vanna - Remote Code Execution via Prompt Injection
CVSS 8.1
CVE-2024-23692 CRITICAL KEV
Rejetto HTTP File Server - Template injection
CVSS 9.8
CVE-2024-3924 MEDIUM
huggingface/text-generation-inference <= 2.0.0 - Remote Code Execution via GitHub Actions Workflow
CVSS 4.4
CVE-2024-35226 HIGH
Smarty 3.0.0-4.5.2 and 5.0.0-5.1.0 - PHP Code Injection via Extends Tag Filename
CVSS 7.3
CVE-2024-35581 MEDIUM
Sourcecodester Laboratory Management System 1.0 - Stored Cross-Site Scripting via Borrower Name Input
CVSS 6.1
CVE-2024-23601 CRITICAL
AutomationDirect P3-550E 1.2.10.9 - Arbitrary Code Execution via Crafted scan_lib.bin
CVSS 9.8
CVE-2024-28886 HIGH
UTAU < 0.4.19 - OS Command Injection via Crafted UST File
CVSS 8.4
CVE-2024-5407 CRITICAL
RhinOS 3.0-1190 - Remote Code Execution via Search Parameter
CVSS 10.0
CVE-2024-35339 CRITICAL
Tenda FH1206 V1.2.0.8(8155) - OS Command Injection via mac Parameter
CVSS 9.8
Details
Vulnerabilities 6,507
Exploit Likelihood Medium