CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,510 vulnerabilities with CWE-94
CVE-2023-2583
CRITICAL
jsreport < 3.11.3 - Code Injection
CVSS 10.0
CVE-2023-29963
HIGH
S-CMS v5.0 - Authenticated Remote Code Execution via /admin/ajax.php
CVSS 7.2
CVE-2023-31415
HIGH
Kibana 8.7.0 - Authenticated Remote Code Execution via Uptime/Synthetics Feature
CVSS 8.8
CVE-2023-31414
HIGH
Kibana 8.0.0-8.7.0 - Authenticated Remote Code Execution via YAML or ENV Configuration
CVSS 8.8
CVE-2023-1178
MEDIUM
GitLab 8.6-15.9.5, 15.10-15.10.4, 15.11 - File Integrity Compromise via Tag or Release Reference
CVSS 5.7
CVE-2023-26546
HIGH
IUCLID <6.27.6 - Authenticated Code Injection
CVSS 8.8
CVE-2023-26782
MEDIUM
mccms 2.6.1 - Denial of Service via Cache Security Character Configuration
CVSS 6.5
CVE-2023-30349
CRITICAL
JFinal CMS 5.1.0 - Remote Code Execution via ActionEnter Function
CVSS 9.8
CVE-2023-30404
CRITICAL
Aigital Wireless-N Repeater Mini Router Firmware v0.131229 - Remote Code Execution via sysCmd Parameter
CVSS 9.8
CVE-2023-2259
HIGH
GitHub alfio-event/alf.io <2.0-M4-2304 - Info Disclosure
CVSS 7.2
CVE-2023-29566
CRITICAL
dawnsparks-node-tesseract 0.4.0-0.4.1 - Remote Code Execution via child_process Function
CVSS 9.8
CVE-2023-26060
MEDIUM
Nokia NetAct <22 FP2211 - Client-side Template Injection
CVSS 6.8
CVE-2023-25550
HIGH
StruxureWare Data Center Expert < 7.9.2 - Remote Code Execution via Hostname Parameter
CVSS 7.2
CVE-2023-25549
HIGH
StruxureWare Data Center Expert <= 7.9.2 - Remote Code Execution via DCE Network Settings Endpoint
CVSS 7.2
CVE-2023-2017
HIGH
Shopware 6 <= v6.4.20.0,v6.5.0.0-rc1 <= v6.5.0.0-rc4 - Code Injection
CVSS 8.8
CVE-2023-30537
CRITICAL
XWiki 12.6.6-13.10.10 - Authenticated Remote Code Execution via FlamingoThemesCode.WebHome Style Property
CVSS 9.9
CVE-2023-29509
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via DocumentTree Macro Parameter Injection
CVSS 9.9
CVE-2023-29214
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via IncludedDocuments Panel
CVSS 9.9
CVE-2023-29212
CRITICAL
XWiki 14.0-14.4.7 - Authenticated Remote Code Execution via Insufficient Escaping in Included Documents Edit Panel
CVSS 9.9
CVE-2023-29211
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Improper WikiId Parameter Escaping
CVSS 9.9
CVE-2023-29210
CRITICAL
XWiki < 13.10.11 - Authenticated Remote Code Execution via Notification Preferences Macro
CVSS 9.9
CVE-2023-29209
CRITICAL
XWiki <13.10.11 - Code Execution via Legacy Notification Activity Macro
CVSS 9.9
CVE-2023-2056
MEDIUM
dedecms < 5.7.87 - Remote Code Execution via GetSystemFile Function
CVSS 6.3
CVE-2023-30638
HIGH
Atos Unify Openscape Bcf < 10r10.7.0 - Command Injection
CVSS 7.2
CVE-2023-29492
CRITICAL
KEV
novi_survey < 8.9.43676 - Remote Code Execution
CVSS 9.8
Details
Vulnerabilities
6,510
Exploit Likelihood
Medium