CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,507 vulnerabilities with CWE-94
CVE-2023-7148 MEDIUM
ShifuML shifu 0.12.0 - Code Injection via FilterExpression in DataPurifier
CVSS 5.0
CVE-2023-46987 HIGH
SeaCMS v12.9 - Remote Code Execution via adminip.php Component
CVSS 8.8
CVE-2023-49001 CRITICAL
Indi Browser <12.11.23 - Auth Bypass
CVSS 9.8
CVE-2023-49000 CRITICAL
ArtistScope ArtisBrowser <34.1.5 - Auth Bypass
CVSS 9.8
CVE-2023-47883 CRITICAL
vladymix/tv_browser < 4.5.1 - JavaScript Code Execution via Exposed MainActivity
CVSS 9.8
CVE-2023-43955 CRITICAL
TV Bro <=2.0.0 - Code Execution via WebView External Intents
CVSS 9.8
CVE-2023-43481 CRITICAL
Shenzhen TCL Browser TV Web BrowseHere <6.65.022 - XSS
CVSS 9.8
CVE-2023-7101 HIGH KEV
Spreadsheet::ParseExcel < 0.65 - Remote Code Execution via Number Format String Eval
CVSS 7.8
CVE-2023-51387 HIGH
Hertzbeat <1.4.1 - Command Injection
CVSS 7.2
CVE-2023-51018 CRITICAL
TOTOlink EX1800T <9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-51015 CRITICAL
TOTOLINX EX1800T <9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-51026 CRITICAL
TOTOlink EX1800T V9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-49391 HIGH
free5gc 3.3.0 - Remote Code Execution and Denial of Service via NGAP Message
CVSS 7.5
CVE-2023-7035 LOW
Automad < 1.10.9 - Stored Cross-Site Scripting via Sitename Parameter
CVSS 2.4
CVE-2023-49032 CRITICAL
LTB Self Service Password <1.5.4 - RCE
CVSS 9.8
CVE-2023-49004 CRITICAL
D-Link DIR-850L B1_FW223WWb01 en Parameter - Remote Code Execution
CVSS 9.8
CVE-2023-6691 HIGH
Cambium ePMP Force 300-25 4.7.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-32728 MEDIUM
Zabbix Agent2 5.0.0-5.0.37 - Remote Code Execution via smart.disk.get Item Key
CVSS 4.6
CVE-2023-6899 MEDIUM
rmountjoy92 DashMachine 0.5-4 - Code Injection via Config Handler value_template
CVSS 4.3
CVE-2023-6886 MEDIUM
wangmarket 6.1 - Code Injection in Role Management Page
CVSS 4.7
CVE-2023-6851 MEDIUM
KodExplorer < 4.52.01 - Remote Code Injection in ZIP Archive Handler
CVSS 6.3
CVE-2023-50723 CRITICAL
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
CVE-2023-50721 CRITICAL
XWiki Platform 4.5-14.10.5 - Remote Code Execution via Search UI Extension Injection
CVSS 9.9
CVE-2023-6051 MEDIUM
GitLab CE/EE <16.4.4, <16.5.4, <16.6.2 - Info Disclosure
CVSS 5.7
CVE-2023-5512 MEDIUM
GitLab 16.3-16.4.3, 16.5-16.5.3, 16.6-16.6.1 - File Integrity Compromise via HTML-Encoded Filenames
CVSS 4.8
Details
Vulnerabilities 6,507
Exploit Likelihood Medium