CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,518 vulnerabilities with CWE-94
CVE-2021-3661
HIGH
HP Z1 All-in-one G3 Firmware - Code Injection
CVSS 8.4
CVE-2021-26731
CRITICAL
Lanner Inc IAC-AST2500A Firmware 1.10.0 - Authenticated Stack-Based Buffer Overflow in modifyUserb_func
CVSS 9.1
CVE-2021-26729
CRITICAL
Lanner Inc IAC-AST2500A Firmware 1.10.0 - Stack-Based Buffer Overflow and Command Injection in Login Handler
CVSS 10.0
CVE-2021-26728
CRITICAL
Lanner Inc IAC-AST2500A Firmware 1.10.0 - Stack-Based Buffer Overflow and Command Injection in KillDupUsr_func
CVSS 10.0
CVE-2021-26727
CRITICAL
Lanner Inc IAC-AST2500A standard firmware 1.10.0 - Stack-based Buffer Overflow in SubNet_handler_func
CVSS 10.0
CVE-2021-22646
HIGH
Ovarro TWinSoft < 12.4 - Remote Code Execution via Malicious IPK Package
CVSS 8.8
CVE-2021-40553
HIGH
piwigo 11.5.0 - Remote Code Execution in LocalFiles Editor
CVSS 8.8
CVE-2021-41402
HIGH
flatcore-cms 2.0.8 - Remote Code Execution
CVSS 8.8
CVE-2021-41749
CRITICAL
nystudio107 SEOmatic < 3.4.11 - Unauthenticated Server-Side Template Injection
CVSS 9.8
CVE-2021-27446
CRITICAL
Weintek cMT Firmware < 20210305 - Unauthenticated Remote Code Execution
CVSS 10.0
CVE-2021-42651
HIGH
Pentest-Collaboration-Framework 1.0.8 - Authenticated Server-Side Template Injection via Reports Endpoint
CVSS 8.8
CVE-2021-40219
HIGH
Bolt CMS <= 4.2 - Authenticated Remote Code Execution via Theme Template Injection
CVSS 8.8
CVE-2021-39114
HIGH
Atlassian Confluence Data Center < 6.13.23 - Code Injection
CVSS 8.8
CVE-2021-39908
MEDIUM
GitLab 0.8.0-14.2.5, 14.3.0-14.3.3, 14.4.0 - Code Injection via Unicode Character Obfuscation
CVSS 6.5
CVE-2021-43097
HIGH
DIYHi BBS 5.3 - Server-Side Template Injection in TemplateManageAction
CVSS 7.2
CVE-2021-26622
CRITICAL
Genian NAC 4.0-4.0.145.0831 - Remote Code Execution via SSTI and File Name Parameter
CVSS 9.6
CVE-2021-38745
MEDIUM
Chamilo LMS <1.11.14 - Code Injection
CVSS 6.8
CVE-2021-39383
CRITICAL
DWSurvey 3.2.0 - Remote Code Execution via SysPropertyAction Component
CVSS 9.8
CVE-2021-25003
CRITICAL
WPCargo Track & Trace < 6.9.0 - Unauthenticated Arbitrary File Write and Remote Code Execution
CVSS 9.8
CVE-2021-44618
CRITICAL
nystudio107 seomatic < 3.4.12 - Server-Side Template Injection via Host Header
CVSS 9.8
CVE-2021-43944
HIGH
Atlassian Jira Server/Data Center <8.13.15 & <8.20.3 - RCE
CVSS 7.2
CVE-2021-44238
HIGH
AyaCMS 3.1.2 - Remote Code Execution via ust_tab_e.inc.php
CVSS 7.2
CVE-2021-22395
HIGH
Huawei EMUI - Code Injection
CVSS 7.5
CVE-2021-46063
CRITICAL
MCMS v5.2.5 - Server-Side Template Injection via Template Management Module
CVSS 9.1
CVE-2021-46362
CRITICAL
Magnolia CMS < 6.2.4 - Server-Side Template Injection via Registration and Forgotten Password Forms
CVSS 9.8
Details
Vulnerabilities
6,518
Exploit Likelihood
Medium