CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,511 vulnerabilities with CWE-94
CVE-2023-1287
CRITICAL
ENOVIA Live Collaboration >= V6R2013xE < V6R2013xE_FP.CFA.2240 - Remote Code Execution via XSL Template
CVSS 9.0
CVE-2023-27986
HIGH
Emacs 28.1-28.2 - Remote Code Execution via mailto: URI Double-Quote Injection
CVSS 7.8
CVE-2023-1283
CRITICAL
Qwik < 0.21.0 - Code Injection
CVSS 10.0
CVE-2023-22889
CRITICAL
SmartBear Zephyr Enterprise <= 7.15.0 - Unauthenticated Remote Code Execution via Report Generation
CVSS 9.8
CVE-2023-0090
CRITICAL
Proofpoint Enterprise Protection <8.20.0 - RCE
CVSS 9.8
CVE-2023-0089
HIGH
Proofpoint Enterprise Protection <8.20.0 - Authenticated RCE
CVSS 8.8
CVE-2023-1003
MEDIUM
Typora < 1.5.5 - Code Injection via WSH JScript Handler
CVSS 5.3
CVE-2023-24776
CRITICAL
funadmin 3.2.0 - Remote Code Execution via Addon.php Controller
CVSS 9.8
CVE-2023-26107
MEDIUM
sketchsvg - Arbitrary Code Injection via Unsanitized shell.exec Command
CVSS 6.9
CVE-2023-22381
MEDIUM
GitHub Enterprise Server <3.8.0 - Code Injection
CVSS 4.1
CVE-2023-26477
CRITICAL
XWiki Platform <13.10.10, <14.9-rc-1, <14.4.6 - Code Injection
CVSS 10.0
CVE-2023-1097
CRITICAL
Baicells EG7035-M11 Firmware <= BCE-ODU-1.0.8 - Unauthenticated Remote Code Execution via HTTP GET Command Injection
CVSS 9.3
CVE-2023-23496
HIGH
Safari < 16.3 - Remote Code Execution via Malicious Web Content
CVSS 8.8
CVE-2023-1030
LOW
Online Boat Reservation System 1.0 - Cross-Site Scripting via POST Parameter Handler
CVSS 3.5
CVE-2023-1005
MEDIUM
Markdown-Electron - Code Injection
CVSS 5.3
CVE-2023-1004
MEDIUM
MarkText < 0.17.1 - Code Injection via WSH JScript Handler
CVSS 5.3
CVE-2023-24114
CRITICAL
typecho < 1.2.0 - Remote Code Execution via install.php
CVSS 9.8
CVE-2023-24107
CRITICAL
hour_of_code_python_2015 - Code Injection
CVSS 9.8
CVE-2023-25657
HIGH
Nautobot < 1.5.7 - Remote Code Execution via Jinja2 Template Rendering
CVSS 7.5
CVE-2023-24078
HIGH
FuguHub < 8.1 - Remote Code Execution via CMS Docs Component
CVSS 8.8
CVE-2023-0877
HIGH
froxlor < 2.0.11 - Code Injection
CVSS 8.8
CVE-2023-22855
CRITICAL
Kardex Mlog MCC 5.7.12+0-a203c2a213-master - Remote Code Execution via Path Traversal and T4 Template Injection
CVSS 9.8
CVE-2023-21553
HIGH
Azure DevOps Server - Remote Code Execution
CVSS 7.5
CVE-2023-25717
CRITICAL
KEV
Ruckus Wireless Admin < 10.4 - Unauthenticated Remote Code Execution via HTTP GET Request
CVSS 9.8
CVE-2023-23551
CRITICAL
Control By Web X-600M Firmware < 1.16.00 - Remote Code Execution via Lua Script Injection
CVSS 9.1
Details
Vulnerabilities
6,511
Exploit Likelihood
Medium