CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-0196
MEDIUM
magic-api < 2.0.1 - Remote Code Execution via /resource/file/api/save Endpoint
CVSS 6.3
CVE-2024-0195
MEDIUM
spider-flow 0.4.3 - Remote Code Execution via FunctionService.saveFunction
CVSS 6.3
CVE-2023-54345
HIGH
Frappe Framework ERPNext 13.4.0 Remote Code Execution
CVSS 8.8
CVE-2023-31044
LOW
Nokia Impact <Mobile 23_FP1 - Code Injection
CVSS 2.0
CVE-2023-53940
HIGH
Codigo Markdown Editor 1.0.1 - Code Injection
CVSS 7.8
CVE-2023-53888
HIGH
Zomplog 3.9 - Remote Code Execution
CVSS 8.8
CVE-2023-53883
HIGH
Webedition CMS <2.9.8.8 - Authenticated RCE
CVSS 7.2
CVE-2023-47030
CRITICAL
NCR Terminal Handler 1.5.1 - Remote Code Execution via UserService SOAP API Endpoint
CVSS 9.8
CVE-2023-47032
CRITICAL
NCR Terminal Handler 1.5.1 - Remote Code Execution via UserService SOAP API
CVSS 9.8
CVE-2023-48978
CRITICAL
NCR ITM Web Terminal 4.4.0 and 4.4.4 - Remote Code Execution via IP Camera URL Component
CVSS 9.8
CVE-2023-7303
LOW
q2apro q2apro-on-site-notifications <1.4.6 - XSS
CVSS 3.5
CVE-2023-42404
MEDIUM
OneVision Workspace < WS23.1 SR1 - Remote Code Execution via Java EL Injection
CVSS 4.9
CVE-2023-43958
CRITICAL
Hospital Management System <4.0 - RCE
CVSS 9.8
CVE-2023-42875
HIGH
Safari < 17.0 - Remote Code Execution via Web Content Processing
CVSS 7.3
CVE-2023-51331
MEDIUM
PHPJabbers Cleaning Business Software v1.0 - Code Injection
CVSS 6.5
CVE-2023-51324
MEDIUM
PHPJabbers Shared Asset Booking System v1.0 - Code Injection
CVSS 6.5
CVE-2023-51320
MEDIUM
PHPJabbers Night Club Booking Software v1.0 - Code Injection
CVSS 5.3
CVE-2023-51317
MEDIUM
PHPJabbers Restaurant Booking System <3.0 - XSS
CVSS 6.5
CVE-2023-51313
HIGH
PHPJabbers Restaurant Booking System v3.0 - Code Injection
CVSS 8.8
CVE-2023-28354
CRITICAL
Opsview Monitor Agent 6.8 - Unauthenticated Remote Code Execution via NRPE Plugin Command Injection
CVSS 9.8
CVE-2023-6604
MEDIUM
FFmpeg 2.0-6.0 - Denial of Service via XBIN Demuxer
CVSS 5.3
CVE-2023-6601
MEDIUM
FFmpeg HLS Demuxer - Unsafe Extension Check Bypass
CVSS 4.7
CVE-2023-34990
CRITICAL
Fortinet FortiWLM 8.5.0-8.5.4 and 8.6.0-8.6.5 - Relative Path Traversal and Code Execution via Web Requests
CVSS 9.8
CVE-2023-43091
CRITICAL
GNOME Maps 43.0-43.6 - Code Injection via service.json Configuration File
CVSS 9.8
CVE-2023-39593
MEDIUM
MariaDB - Authenticated Command Injection via sys_exec Function
CVSS 5.6
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium