CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,511 vulnerabilities with CWE-94
CVE-2023-29492
CRITICAL
KEV
novi_survey < 8.9.43676 - Remote Code Execution
CVSS 9.8
CVE-2023-27897
MEDIUM
SAP CRM 700-713 - Authenticated Code Injection via Vulnerable Interface
CVSS 6.0
CVE-2023-27650
CRITICAL
APUS Launcher 3.10.73 and 3.10.88 - Remote Code Execution via FONT_FILE Parameter
CVSS 9.8
CVE-2023-1947
MEDIUM
taoCMS 3.0.2 - Remote Code Injection in /admin/admin.php
CVSS 6.3
CVE-2023-28706
CRITICAL
Apache Airflow Hive Provider <6.0.0 - Code Injection
CVSS 9.8
CVE-2023-26817
HIGH
codefever < 2023-02-07 - Remote Code Execution via User API Controller
CVSS 8.8
CVE-2023-24538
CRITICAL
Go Templates - Code Injection via JavaScript Template Literals
CVSS 9.8
CVE-2023-1708
MEDIUM
GitLab CE/EE <15.8.5-15.10.1 - Code Injection
CVSS 5.7
CVE-2023-27770
HIGH
Wondershare Edraw Max 12.0.4 - Remote Code Execution via Setup Executable
CVSS 7.8
CVE-2023-26119
CRITICAL
net.sourceforge.htmlunit:htmlunit <3.0.0 - RCE
CVSS 9.8
CVE-2023-1773
MEDIUM
Rockoa 2.3.2 - Code Injection in Configuration File Handler
CVSS 6.3
CVE-2023-25261
CRITICAL
Stimulsoft Designer and Viewer - Remote Code Execution via Report Variable Injection
CVSS 9.8
CVE-2023-24835
HIGH
Softnext SPAM SQR < 2.221231 - Authenticated Code Injection
CVSS 7.2
CVE-2023-28333
CRITICAL
moodle 3.9.0-3.9.19 and 4.1.0-4.1.1 - Code Injection via Mustache Pix Helper
CVSS 9.8
CVE-2023-24709
HIGH
Paradox Security Systems IPR512 - DoS
CVSS 7.5
CVE-2023-1306
HIGH
Rapid7 InsightCloudSec < 2023.02.01 & InsightAppSec < 23.2.1 - RCE via Jinja Template Injection
CVSS 8.8
CVE-2023-1304
HIGH
Rapid7 InsightCloudSec < 2023.02.01 & InsightAppSec < 23.2.1 - RCE via Jinja Template Injection
CVSS 8.8
CVE-2023-1250
HIGH
OTRS 6.0.1-6.0.34 and 7.0.0-7.0.41 - Local Code Execution via ACL Comment Injection
CVSS 7.4
CVE-2023-1482
MEDIUM
HkCms 2.2.4.230206 - Code Injection
CVSS 4.7
CVE-2023-0598
HIGH
GE Digital Proficy iFIX 2022 v6.1 v6.5 - Code Injection via Malicious Configuration Files
CVSS 7.8
CVE-2023-24795
CRITICAL
JHR-N916R Firmware <= 21.11.1.1483 - Remote Code Execution
CVSS 9.8
CVE-2023-25344
CRITICAL
swig-templates < 2.0.4 and swig < 1.4.2 - Remote Code Execution via Object.prototype Function Injection
CVSS 9.8
CVE-2023-27893
HIGH
SAP Solution Manager - Authenticated Remote Code Execution via Vulnerable Interface
CVSS 8.8
CVE-2023-1367
LOW
easyappointments < 1.5.0 - Code Injection
CVSS 3.8
CVE-2023-0888
MEDIUM
B.Braun Battery Pack SP with WiFi Firmware L90/U70 and L92/U92 - Authenticated Eval Injection in Embedded Web Server
CVSS 4.9
Details
Vulnerabilities
6,511
Exploit Likelihood
Medium