CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,511 vulnerabilities with CWE-94
CVE-2023-0792
MEDIUM
phpmyfaq < 3.1.11 - Code Injection
CVSS 6.5
CVE-2023-0788
HIGH
phpmyfaq < 3.1.11 - Code Injection
CVSS 8.1
CVE-2023-23912
HIGH
Ubiquiti EdgeRouter and UniFi Security Gateway - WAN Remote Code Execution
CVSS 8.8
CVE-2023-0575
HIGH
Yugabyte DB <2.2.0.0 - Code Injection
CVSS 7.2
CVE-2023-0671
HIGH
froxlor < 2.0.10 - Code Injection
CVSS 8.8
CVE-2023-24576
HIGH
Dell EMC NetWorker < 19.8 - Unauthenticated Remote Code Execution via NetWorker Client Execution Service
CVSS 7.5
CVE-2023-23477
HIGH
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via Serialized Objects
CVSS 8.1
CVE-2023-23619
CRITICAL
lfprojects/modelina < 1.0.0 - Code Injection via Default Presets
CVSS 9.9
CVE-2023-24059
HIGH
Grand Theft Auto V - Remote Code Execution
CVSS 7.3
CVE-2023-21890
CRITICAL
Oracle Communications Converged Application Server <8.0.0 - RCE
CVSS 9.8
CVE-2023-21886
HIGH
Oracle VM VirtualBox <6.1.42 & <7.0.6 - Takeover
CVSS 8.1
CVE-2023-22731
CRITICAL
Shopware < 6.4.18.1 - Authenticated Remote Code Execution via Twig Filter PHP Function Injection
CVSS 9.9
CVE-2023-0297
CRITICAL
pyLoad js2py Python Execution
CVSS 9.8
CVE-2023-22853
HIGH
Tiki < 24.1 - PHP Object Injection via eval in structlib.php
CVSS 8.8
CVE-2023-22952
HIGH
KEV
SugarCRM unauthenticated Remote Code Execution (RCE)
CVSS 8.8
CVE-2023-0022
CRITICAL
SAP BusinessObjects < - Code Injection
CVSS 9.9
CVE-2023-0048
HIGH
GitHub lirantal/daloradius <master - Code Injection
CVSS 8.8
CVE-2022-50972
CRITICAL
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
CVSS 9.8
CVE-2022-50944
HIGH
Aero CMS 0.0.1 PHP Code Injection via posts.php
CVSS 8.8
CVE-2022-50806
HIGH
4images 1.9 - Authenticated Remote Code Execution via Template Editing and Categories Endpoint
CVSS 7.2
CVE-2022-31491
CRITICAL
Voltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
CVSS 10.0
CVE-2022-38946
CRITICAL
divscorp doctor-appointment 1.0 - Arbitrary File Upload and Remote Code Execution via signup_com.php
CVSS 9.8
CVE-2022-32897
HIGH
macOS < 12.5 - Remote Code Execution via Maliciously Crafted TIFF File
CVSS 7.8
CVE-2022-46070
HIGH
GV-ASManager V6.0.1.0 - Path Traversal
CVSS 7.5
CVE-2022-45177
HIGH
LIVEBOX Collaboration vDesk <= v031 - Observable Response Discrepancy in User Enable and Shared Search Endpoints
CVSS 7.5
Details
Vulnerabilities
6,511
Exploit Likelihood
Medium