CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-24396
MEDIUM
Stimulsoft Dashboard.JS < 2024.1.2 - Remote Code Execution via Search Bar Component
CVSS 6.1
CVE-2024-24469
HIGH
flusity-CMS 2.33 - Cross-Site Request Forgery to Code Execution via delete_post.php
CVSS 8.8
CVE-2024-25089
CRITICAL
Malwarebytes Binisoft Windows Firewall Control <6.9.9.2 - RCE
CVSS 9.8
CVE-2024-22533
CRITICAL
Before Beetl <3.15.12 - Code Injection
CVSS 9.8
CVE-2024-23746
CRITICAL
Miro Desktop 0.8.18 - Local Code Injection via Electron App Bundle Manipulation
CVSS 9.8
CVE-2024-22899
HIGH
Vinchin Backup & Recovery <7.2 - Authenticated RCE
CVSS 8.8
CVE-2024-0325
LOW
Helix Sync < 2024.1 - Local Command Injection
CVSS 3.6
CVE-2024-1117
HIGH
openBI < 1.0.8 - Remote Code Injection via Screen.php fileurl Parameter
CVSS 7.3
CVE-2024-21649
HIGH
vantage6 < 4.2.0 - Authenticated Remote Code Execution via Algorithm Environment Variables
CVSS 8.8
CVE-2024-1015
CRITICAL
SE-elektronic E-DDC3.3 Firmware 03.07.03 and higher - Remote Code Execution via Web Configuration
CVSS 9.8
CVE-2024-23742
CRITICAL
Loom < 0.196.1 - Remote Code Execution via RunAsNode and enableNodeClilnspectArguments
CVSS 9.8
CVE-2024-23741
CRITICAL
Hyper < 3.4.1 - Remote Code Execution via RunAsNode and enableNodeClilnspectArguments
CVSS 9.8
CVE-2024-0755
HIGH
Firefox < 122, Firefox ESR < 115.7, Thunderbird < 115.7 - Memory Corruption and Remote Code Execution
CVSS 8.8
CVE-2024-23208
HIGH
iPadOS < 17.3 - Remote Code Execution with Kernel Privileges
CVSS 7.8
CVE-2024-23750
HIGH
MetaGPT <= 0.6.4 - Remote Code Execution via QaEngineer Role
CVSS 8.8
CVE-2024-0521
HIGH
Paddlepaddle paddle - Code Injection
CVSS 7.8
CVE-2024-0738
MEDIUM
mldong 1.0 - Remote Code Injection in DecisionModel ExpressionEngine
CVSS 6.3
CVE-2024-21674
HIGH
Confluence Data Center and Server 7.19.0-7.19.17 - Unauthenticated Remote Code Execution
CVSS 7.5
CVE-2024-21673
HIGH
Confluence Data Center and Server 7.19.0-7.19.17 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2024-21672
HIGH
Confluence Data Center and Server 7.19.0-7.19.17 and 8.5.0-8.5.4 - Unauthenticated Remote Code Execution
CVSS 8.8
CVE-2024-0252
HIGH
ManageEngine ADSelfService Plus <= 6401 - Authenticated Remote Code Execution in Load Balancer Component
CVSS 8.8
CVE-2024-21643
HIGH
Microsoft IdentityModel Extensions < 6.34.0 - Remote Code Execution via SignedHttpRequest Protocol
CVSS 7.1
CVE-2024-21737
HIGH
SAP Application Interface Framework File Adapter 702 - Authenticated OS Command Injection
CVSS 8.4
CVE-2024-21646
CRITICAL
Azure uAMQP < 2024-01-01 - Remote Code Execution via Crafted Binary Type Data
CVSS 9.8
CVE-2024-21650
CRITICAL
XWiki < 4.10.20 - Remote code execution
CVSS 10.0
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium