CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,511 vulnerabilities with CWE-94
CVE-2023-1287 CRITICAL
ENOVIA Live Collaboration >= V6R2013xE < V6R2013xE_FP.CFA.2240 - Remote Code Execution via XSL Template
CVSS 9.0
CVE-2023-27986 HIGH
Emacs 28.1-28.2 - Remote Code Execution via mailto: URI Double-Quote Injection
CVSS 7.8
CVE-2023-1283 CRITICAL
Qwik < 0.21.0 - Code Injection
CVSS 10.0
CVE-2023-22889 CRITICAL
SmartBear Zephyr Enterprise <= 7.15.0 - Unauthenticated Remote Code Execution via Report Generation
CVSS 9.8
CVE-2023-0090 CRITICAL
Proofpoint Enterprise Protection <8.20.0 - RCE
CVSS 9.8
CVE-2023-0089 HIGH
Proofpoint Enterprise Protection <8.20.0 - Authenticated RCE
CVSS 8.8
CVE-2023-1003 MEDIUM
Typora < 1.5.5 - Code Injection via WSH JScript Handler
CVSS 5.3
CVE-2023-24776 CRITICAL
funadmin 3.2.0 - Remote Code Execution via Addon.php Controller
CVSS 9.8
CVE-2023-26107 MEDIUM
sketchsvg - Arbitrary Code Injection via Unsanitized shell.exec Command
CVSS 6.9
CVE-2023-22381 MEDIUM
GitHub Enterprise Server <3.8.0 - Code Injection
CVSS 4.1
CVE-2023-26477 CRITICAL
XWiki Platform <13.10.10, <14.9-rc-1, <14.4.6 - Code Injection
CVSS 10.0
CVE-2023-1097 CRITICAL
Baicells EG7035-M11 Firmware <= BCE-ODU-1.0.8 - Unauthenticated Remote Code Execution via HTTP GET Command Injection
CVSS 9.3
CVE-2023-23496 HIGH
Safari < 16.3 - Remote Code Execution via Malicious Web Content
CVSS 8.8
CVE-2023-1030 LOW
Online Boat Reservation System 1.0 - Cross-Site Scripting via POST Parameter Handler
CVSS 3.5
CVE-2023-1005 MEDIUM
Markdown-Electron - Code Injection
CVSS 5.3
CVE-2023-1004 MEDIUM
MarkText < 0.17.1 - Code Injection via WSH JScript Handler
CVSS 5.3
CVE-2023-24114 CRITICAL
typecho < 1.2.0 - Remote Code Execution via install.php
CVSS 9.8
CVE-2023-24107 CRITICAL
hour_of_code_python_2015 - Code Injection
CVSS 9.8
CVE-2023-25657 HIGH
Nautobot < 1.5.7 - Remote Code Execution via Jinja2 Template Rendering
CVSS 7.5
CVE-2023-24078 HIGH
FuguHub < 8.1 - Remote Code Execution via CMS Docs Component
CVSS 8.8
CVE-2023-0877 HIGH
froxlor < 2.0.11 - Code Injection
CVSS 8.8
CVE-2023-22855 CRITICAL
Kardex Mlog MCC 5.7.12+0-a203c2a213-master - Remote Code Execution via Path Traversal and T4 Template Injection
CVSS 9.8
CVE-2023-21553 HIGH
Azure DevOps Server - Remote Code Execution
CVSS 7.5
CVE-2023-25717 CRITICAL KEV
Ruckus Wireless Admin < 10.4 - Unauthenticated Remote Code Execution via HTTP GET Request
CVSS 9.8
CVE-2023-23551 CRITICAL
Control By Web X-600M Firmware < 1.16.00 - Remote Code Execution via Lua Script Injection
CVSS 9.1
Details
Vulnerabilities 6,511
Exploit Likelihood Medium