CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,510 vulnerabilities with CWE-94
CVE-2023-45144 CRITICAL
XWiki OAuth Identity < 1.6 - Remote Code Execution via OAuth Login Parameter Injection
CVSS 10.0
CVE-2023-29453 CRITICAL
Zabbix Agent2 5.0.0-5.0.34 - JavaScript Injection via Backtick Delimiter Mishandling
CVSS 9.8
CVE-2023-43661 HIGH
Cachet < 2.4 - Remote Code Execution via Template Injection
CVSS 8.8
CVE-2023-36789 HIGH
Skype for Business Server - Remote Code Execution
CVSS 7.2
CVE-2023-36718 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in Virtual Trusted Platform Module
CVSS 7.8
CVE-2023-36702 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution via DirectMusic
CVSS 7.8
CVE-2023-36592 HIGH
Windows 10/11 and Windows Server - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36591 HIGH
Windows 10, 11, Server 2008-2019 - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36589 HIGH
Windows 10/11 and Windows Server - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36575 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36574 HIGH
Microsoft Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in Message Queuing
CVSS 7.3
CVE-2023-36573 HIGH
Microsoft Windows MSMQ - Remote Code Execution
CVSS 7.3
CVE-2023-36572 HIGH
Windows 10 1507-22H2 and Windows 11 21H2-22H2 - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36571 HIGH
Microsoft Windows 10/11 and Windows Server 2008-2022 - Remote Code Execution in MSMQ
CVSS 7.3
CVE-2023-36570 HIGH
Microsoft Windows 10/11 and Windows Server - Remote Code Execution in Message Queuing
CVSS 7.3
CVE-2023-43625 CRITICAL
Simcenter Amesim < 2021.1 - Unauthenticated DLL Injection via SOAP Endpoint
CVSS 9.8
CVE-2023-44847 HIGH
SeaCMS < 12.8 - Remote Code Execution via admin_Weixin.php
CVSS 7.2
CVE-2023-44846 HIGH
SeaCMS < 12.8 - Remote Code Execution via admin_notify.php
CVSS 8.8
CVE-2023-44392 HIGH
Garden < 0.12.65 - Remote Code Execution via Cryo Deserialization in Test/Run Result ConfigMaps
CVSS 8.2
CVE-2023-45311 CRITICAL
fsevents < 1.2.11 - Remote Code Execution via Untrusted Binary Download URL
CVSS 9.8
CVE-2023-35897 HIGH
IBM Spectrum Protect Client & Storage Protect - Local RCE
CVSS 8.4
CVE-2023-3665 MEDIUM
Trellix Endpoint Security < 10.7.0 - Local Code Injection via Environment Variable Manipulation
CVSS 5.5
CVE-2023-3656 CRITICAL
cashit! < 03.a06rks_2023.02.37 - Unauthenticated Remote Code Execution via HTTP Endpoint
CVSS 9.8
CVE-2023-44011 CRITICAL
mojoportal 2.7.0.0 - Remote Code Execution via Skin Management Layout.master File
CVSS 9.8
CVE-2023-5201 CRITICAL
OpenHook <= 4.3.0 - Authenticated Remote Code Execution via PHP Shortcode
CVSS 9.9
Details
Vulnerabilities 6,510
Exploit Likelihood Medium