CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,528 vulnerabilities with CWE-94
CVE-2021-21353
MEDIUM
pug < 3.0.1 - Remote Code Execution via Pretty Option Injection
CVSS 6.8
CVE-2021-25283
CRITICAL
SaltStack Salt <3002.5 - Code Injection
CVSS 9.8
CVE-2021-3273
HIGH
Nagios XI < 5.7 - Authenticated Code Injection in graphtemplates.php
CVSS 7.2
CVE-2021-26120
CRITICAL
Smarty < 3.1.39 - Code Injection via Unexpected Function Name
CVSS 9.8
CVE-2021-23337
HIGH
Lodash <4.17.21 - Command Injection
CVSS 7.2
CVE-2021-25251
HIGH
Trend Micro Security - Code Injection
CVSS 7.2
CVE-2021-21477
CRITICAL
SAP Commerce Cloud 1808,1811,1905,2005,2011 - Authenticated Remote Code Execution via Drools Rule Injection
CVSS 9.9
CVE-2021-26551
HIGH
SmartFoxServer 2.17.0 - Remote Code Execution via Console Module Unlock Bypass
CVSS 8.8
CVE-2021-21305
HIGH
CarrierWave <2.1.1 - Code Injection
CVSS 7.4
CVE-2021-25770
CRITICAL
JetBrains YouTrack < 2020.5.3123 - Server-Side Template Injection
CVSS 9.8
CVE-2021-21277
HIGH
angular-expressions < 1.1.2 - Remote Code Execution via Constructor Bypass
CVSS 8.5
CVE-2021-20187
HIGH
Moodle < 3.5.16, 3.8.7, 3.9.4, 3.10.1 - Authenticated Remote Code Execution via Shibboleth PHP Include
CVSS 7.2
CVE-2021-21248
CRITICAL
OneDev < 4.0.3 - Remote Code Execution via Build Endpoint Parameter Injection
CVSS 9.6
CVE-2021-21244
CRITICAL
OneDev <4.0.3 - Server Side Template Injection
CVSS 10.0
CVE-2021-21466
HIGH
SAP Business Warehouse and BW/4HANA - Code Injection via Remote Function Module
CVSS 8.8
CVE-2020-37167
HIGH
ClamAV/ClamBC < 0.103.0-rc - Code Injection via ClamBC Bytecode Function Name Manipulation
CVSS 8.4
CVE-2020-37186
CRITICAL
Chevereto 3.13.4 - Remote Code Execution via Database Table Prefix Manipulation
CVSS 9.8
CVE-2020-37178
HIGH
KeePass Password Safe < 2.44 - Denial of Service via Malicious HTML File in Help System
CVSS 7.5
CVE-2020-37137
MEDIUM
PHP-Fusion 9.03.50 - Remote Code Execution via panels.php Panel Content Parameter
CVSS 6.1
CVE-2020-37052
CRITICAL
Ubiquiti AirControl 1.4.2 - Unauthenticated Remote Code Execution via Java Expression Injection in /.seam Endpoint
CVSS 9.8
CVE-2020-36875
CRITICAL
AccessAlly WordPress Plugin < 3.3.2 - Unauthenticated Remote Code Execution via Login Widget
CVE-2020-36870
CRITICAL
Ruijie Gateway EG and NBR Series 11.1(6)B9P1-11.9(4)B12P1 - Remote Code Execution via EWEB Management System
CVE-2020-36767
HIGH
tinyfiledialogs <3.8.0 - Command Injection
CVSS 7.5
CVE-2020-22612
CRITICAL
MyBB < 1.8.22 - Remote Code Execution via Installer Settings File Write
CVSS 9.8
CVE-2020-20918
HIGH
Pluck CMS 4.7.10-dev2 - Remote Code Execution via Admin Page Edit Parameter
CVSS 7.2
Details
Vulnerabilities
6,528
Exploit Likelihood
Medium