CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,511 vulnerabilities with CWE-94
CVE-2023-0792 MEDIUM
phpmyfaq < 3.1.11 - Code Injection
CVSS 6.5
CVE-2023-0788 HIGH
phpmyfaq < 3.1.11 - Code Injection
CVSS 8.1
CVE-2023-23912 HIGH
Ubiquiti EdgeRouter and UniFi Security Gateway - WAN Remote Code Execution
CVSS 8.8
CVE-2023-0575 HIGH
Yugabyte DB <2.2.0.0 - Code Injection
CVSS 7.2
CVE-2023-0671 HIGH
froxlor < 2.0.10 - Code Injection
CVSS 8.8
CVE-2023-24576 HIGH
Dell EMC NetWorker < 19.8 - Unauthenticated Remote Code Execution via NetWorker Client Execution Service
CVSS 7.5
CVE-2023-23477 HIGH
IBM WebSphere Application Server 8.5 and 9.0 - Remote Code Execution via Serialized Objects
CVSS 8.1
CVE-2023-23619 CRITICAL
lfprojects/modelina < 1.0.0 - Code Injection via Default Presets
CVSS 9.9
CVE-2023-24059 HIGH
Grand Theft Auto V - Remote Code Execution
CVSS 7.3
CVE-2023-21890 CRITICAL
Oracle Communications Converged Application Server <8.0.0 - RCE
CVSS 9.8
CVE-2023-21886 HIGH
Oracle VM VirtualBox <6.1.42 & <7.0.6 - Takeover
CVSS 8.1
CVE-2023-22731 CRITICAL
Shopware < 6.4.18.1 - Authenticated Remote Code Execution via Twig Filter PHP Function Injection
CVSS 9.9
CVE-2023-0297 CRITICAL
pyLoad js2py Python Execution
CVSS 9.8
CVE-2023-22853 HIGH
Tiki < 24.1 - PHP Object Injection via eval in structlib.php
CVSS 8.8
CVE-2023-22952 HIGH KEV
SugarCRM unauthenticated Remote Code Execution (RCE)
CVSS 8.8
CVE-2023-0022 CRITICAL
SAP BusinessObjects < - Code Injection
CVSS 9.9
CVE-2023-0048 HIGH
GitHub lirantal/daloradius <master - Code Injection
CVSS 8.8
CVE-2022-50972 CRITICAL
WooCommerce 7.1.0 Remote Code Execution via class-wc-meta-box-product-images.php
CVSS 9.8
CVE-2022-50944 HIGH
Aero CMS 0.0.1 PHP Code Injection via posts.php
CVSS 8.8
CVE-2022-50806 HIGH
4images 1.9 - Authenticated Remote Code Execution via Template Editing and Categories Endpoint
CVSS 7.2
CVE-2022-31491 CRITICAL
Voltronic Power ViewPower <1.04-24215, ViewPower Pro <2.0-22165, Po...
CVSS 10.0
CVE-2022-38946 CRITICAL
divscorp doctor-appointment 1.0 - Arbitrary File Upload and Remote Code Execution via signup_com.php
CVSS 9.8
CVE-2022-32897 HIGH
macOS < 12.5 - Remote Code Execution via Maliciously Crafted TIFF File
CVSS 7.8
CVE-2022-46070 HIGH
GV-ASManager V6.0.1.0 - Path Traversal
CVSS 7.5
CVE-2022-45177 HIGH
LIVEBOX Collaboration vDesk <= v031 - Observable Response Discrepancy in User Enable and Shared Search Endpoints
CVSS 7.5
Details
Vulnerabilities 6,511
Exploit Likelihood Medium