CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2023-7148
MEDIUM
ShifuML shifu 0.12.0 - Code Injection via FilterExpression in DataPurifier
CVSS 5.0
CVE-2023-46987
HIGH
SeaCMS v12.9 - Remote Code Execution via adminip.php Component
CVSS 8.8
CVE-2023-49001
CRITICAL
Indi Browser <12.11.23 - Auth Bypass
CVSS 9.8
CVE-2023-49000
CRITICAL
ArtistScope ArtisBrowser <34.1.5 - Auth Bypass
CVSS 9.8
CVE-2023-47883
CRITICAL
vladymix/tv_browser < 4.5.1 - JavaScript Code Execution via Exposed MainActivity
CVSS 9.8
CVE-2023-43955
CRITICAL
TV Bro <=2.0.0 - Code Execution via WebView External Intents
CVSS 9.8
CVE-2023-43481
CRITICAL
Shenzhen TCL Browser TV Web BrowseHere <6.65.022 - XSS
CVSS 9.8
CVE-2023-7101
HIGH
KEV
Spreadsheet::ParseExcel < 0.65 - Remote Code Execution via Number Format String Eval
CVSS 7.8
CVE-2023-51387
HIGH
Hertzbeat <1.4.1 - Command Injection
CVSS 7.2
CVE-2023-51018
CRITICAL
TOTOlink EX1800T <9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-51015
CRITICAL
TOTOLINX EX1800T <9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-51026
CRITICAL
TOTOlink EX1800T V9.1.0cu.2112_B20220316 - Command Injection
CVSS 9.8
CVE-2023-49391
HIGH
free5gc 3.3.0 - Remote Code Execution and Denial of Service via NGAP Message
CVSS 7.5
CVE-2023-7035
LOW
Automad < 1.10.9 - Stored Cross-Site Scripting via Sitename Parameter
CVSS 2.4
CVE-2023-49032
CRITICAL
LTB Self Service Password <1.5.4 - RCE
CVSS 9.8
CVE-2023-49004
CRITICAL
D-Link DIR-850L B1_FW223WWb01 en Parameter - Remote Code Execution
CVSS 9.8
CVE-2023-6691
HIGH
Cambium ePMP Force 300-25 4.7.0.1 - Remote Code Execution
CVSS 7.8
CVE-2023-32728
MEDIUM
Zabbix Agent2 5.0.0-5.0.37 - Remote Code Execution via smart.disk.get Item Key
CVSS 4.6
CVE-2023-6899
MEDIUM
rmountjoy92 DashMachine 0.5-4 - Code Injection via Config Handler value_template
CVSS 4.3
CVE-2023-6886
MEDIUM
wangmarket 6.1 - Code Injection in Role Management Page
CVSS 4.7
CVE-2023-6851
MEDIUM
KodExplorer < 4.52.01 - Remote Code Injection in ZIP Archive Handler
CVSS 6.3
CVE-2023-50723
CRITICAL
XWiki Platform 2.3-14.10.5 - Authenticated Remote Code Execution via Administration Interface
CVSS 9.9
CVE-2023-50721
CRITICAL
XWiki Platform 4.5-14.10.5 - Remote Code Execution via Search UI Extension Injection
CVSS 9.9
CVE-2023-6051
MEDIUM
GitLab CE/EE <16.4.4, <16.5.4, <16.6.2 - Info Disclosure
CVSS 5.7
CVE-2023-5512
MEDIUM
GitLab 16.3-16.4.3, 16.5-16.5.3, 16.6-16.6.1 - File Integrity Compromise via HTML-Encoded Filenames
CVSS 4.8
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium