CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,510 vulnerabilities with CWE-94
CVE-2023-26145 HIGH
pydash < 6.0.0 - OS Command Injection via Deep Path String Manipulation
CVSS 7.4
CVE-2023-38877 HIGH
gugoan's Economizzer <0.9-beta1 - Host Header Injection
CVSS 8.8
CVE-2023-41450 HIGH
phpkobo AjaxNewsTicker 1.0.5 - Remote Code Execution via reque Parameter
CVSS 8.8
CVE-2023-41444 HIGH
Binalyze IREC < 3.11.0 - Local Privilege Escalation via IREC.sys Driver
CVSS 7.8
CVE-2023-43651 HIGH
JumpServer <2.28.20 and <3.7.1 - Authenticated Code Execution via MongoDB Session
CVSS 8.5
CVE-2023-5221 MEDIUM
ForU CMS - Remote Code Injection via db_name Parameter in Install Script
CVSS 4.7
CVE-2023-43234 CRITICAL
DedeBIZ v6.2.11 - Remote Code Execution via file_manage_control.php Parameters
CVSS 9.8
CVE-2023-43222 CRITICAL
SeaCMS < 12.8 - Arbitrary Code Write via admin_ping.php
CVSS 9.8
CVE-2023-41984 HIGH
iPadOS < 16.7 - Remote Code Execution
CVSS 7.8
CVE-2023-0626 HIGH
Docker Desktop < 4.12.0 - Remote Code Execution via Message-Box Route Query Parameters
CVSS 8.0
CVE-2023-0625 HIGH
Docker Desktop < 4.12.0 - Remote Code Execution via Extension Description or Changelog
CVSS 8.0
CVE-2023-43270 CRITICAL
dst-admin 1.5.0 - Remote Code Execution via userId Parameter
CVSS 9.8
CVE-2023-4291 CRITICAL
Frauscher Sensortechnik GmbH FDS101 - RCE
CVSS 9.8
CVE-2023-0462 HIGH
Foreman < 3.8.0 - Authenticated Remote Code Execution via YAML Global Parameter Injection
CVSS 8.0
CVE-2023-22513 HIGH
Bitbucket Data Center and Server 8.0.0-8.9.4 - Authenticated Remote Code Execution
CVSS 8.8
CVE-2023-41179 HIGH KEV
Trend Micro Apex One - Command Injection
CVSS 7.2
CVE-2023-40221 HIGH
Socomec Modulys GP Firmware - Stored Cross-Site Scripting via MAIL_RCV Parameter
CVSS 8.8
CVE-2023-34195 HIGH
Insyde InsydeH2O 5.2-5.2.05.28.22 - Arbitrary Code Execution via GetImageProgress UEFI Variable
CVSS 7.8
CVE-2023-34999 HIGH
RTS VLink Virtual Matrix v5 < 5.7.6 and v6 < 6.5.0 - Remote Code Execution via Admin Web Interface
CVSS 8.4
CVE-2023-4994 CRITICAL
Allow PHP in Posts and Pages <= 3.0.4 - Authenticated Remote Code Execution via PHP Shortcode
CVSS 9.9
CVE-2023-4977 MEDIUM
librenms < 23.9.0 - Code Injection
CVSS 5.4
CVE-2023-41892 CRITICAL
Craft CMS unauthenticated Remote Code Execution (RCE)
CVSS 10.0
CVE-2023-40621 MEDIUM
SAP PowerDesigner Client -16.7 - Code Injection
CVSS 6.3
CVE-2023-42471 CRITICAL
wave.ai.browser < 1.0.35 - Remote Code Execution via Crafted Intent
CVSS 9.8
CVE-2023-42470 CRITICAL
Imou Life < 6.8.0 - Remote Code Execution via Exported MainActivity Component
CVSS 9.8
Details
Vulnerabilities 6,510
Exploit Likelihood Medium