CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,510 vulnerabilities with CWE-94
CVE-2023-26145
HIGH
pydash < 6.0.0 - OS Command Injection via Deep Path String Manipulation
CVSS 7.4
CVE-2023-38877
HIGH
gugoan's Economizzer <0.9-beta1 - Host Header Injection
CVSS 8.8
CVE-2023-41450
HIGH
phpkobo AjaxNewsTicker 1.0.5 - Remote Code Execution via reque Parameter
CVSS 8.8
CVE-2023-41444
HIGH
Binalyze IREC < 3.11.0 - Local Privilege Escalation via IREC.sys Driver
CVSS 7.8
CVE-2023-43651
HIGH
JumpServer <2.28.20 and <3.7.1 - Authenticated Code Execution via MongoDB Session
CVSS 8.5
CVE-2023-5221
MEDIUM
ForU CMS - Remote Code Injection via db_name Parameter in Install Script
CVSS 4.7
CVE-2023-43234
CRITICAL
DedeBIZ v6.2.11 - Remote Code Execution via file_manage_control.php Parameters
CVSS 9.8
CVE-2023-43222
CRITICAL
SeaCMS < 12.8 - Arbitrary Code Write via admin_ping.php
CVSS 9.8
CVE-2023-41984
HIGH
iPadOS < 16.7 - Remote Code Execution
CVSS 7.8
CVE-2023-0626
HIGH
Docker Desktop < 4.12.0 - Remote Code Execution via Message-Box Route Query Parameters
CVSS 8.0
CVE-2023-0625
HIGH
Docker Desktop < 4.12.0 - Remote Code Execution via Extension Description or Changelog
CVSS 8.0
CVE-2023-43270
CRITICAL
dst-admin 1.5.0 - Remote Code Execution via userId Parameter
CVSS 9.8
CVE-2023-4291
CRITICAL
Frauscher Sensortechnik GmbH FDS101 - RCE
CVSS 9.8
CVE-2023-0462
HIGH
Foreman < 3.8.0 - Authenticated Remote Code Execution via YAML Global Parameter Injection
CVSS 8.0
CVE-2023-22513
HIGH
Bitbucket Data Center and Server 8.0.0-8.9.4 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2023-41179
HIGH
KEV
Trend Micro Apex One - Command Injection
CVSS 7.2
CVE-2023-40221
HIGH
Socomec Modulys GP Firmware - Stored Cross-Site Scripting via MAIL_RCV Parameter
CVSS 8.8
CVE-2023-34195
HIGH
Insyde InsydeH2O 5.2-5.2.05.28.22 - Arbitrary Code Execution via GetImageProgress UEFI Variable
CVSS 7.8
CVE-2023-34999
HIGH
RTS VLink Virtual Matrix v5 < 5.7.6 and v6 < 6.5.0 - Remote Code Execution via Admin Web Interface
CVSS 8.4
CVE-2023-4994
CRITICAL
Allow PHP in Posts and Pages <= 3.0.4 - Authenticated Remote Code Execution via PHP Shortcode
CVSS 9.9
CVE-2023-4977
MEDIUM
librenms < 23.9.0 - Code Injection
CVSS 5.4
CVE-2023-41892
CRITICAL
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
CVE-2023-40621
MEDIUM
SAP PowerDesigner Client -16.7 - Code Injection
CVSS 6.3
CVE-2023-42471
CRITICAL
wave.ai.browser < 1.0.35 - Remote Code Execution via Crafted Intent
CVSS 9.8
CVE-2023-42470
CRITICAL
Imou Life < 6.8.0 - Remote Code Execution via Exported MainActivity Component
CVSS 9.8
Details
Vulnerabilities
6,510
Exploit Likelihood
Medium