CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,528 vulnerabilities with CWE-94
CVE-2020-15171 MEDIUM
XWiki < 11.10.5 - Authenticated Remote Code Execution via Servlet Context Access
CVSS 6.6
CVE-2020-6318 HIGH
SAP NetWeaver <7.40 & ABAP Platform >7.40 - RCE
CVSS 7.2
CVE-2020-7381 MEDIUM
Rapid7 Nexpose < 6.6.40 - Unauthenticated Code Execution via Executable Spoofing
CVSS 5.8
CVE-2020-15167 HIGH
Miller 5.9.0 - Unauthenticated Remote Code Execution via Malicious .mlrrc File
CVSS 8.2
CVE-2020-6144 CRITICAL
OS4Ed openSIS 7.4 - Remote Code Execution via Username Variable in Install Step5
CVSS 9.8
CVE-2020-6143 CRITICAL
OS4Ed openSIS 7.4 - Remote Code Execution via Install Password Variable Injection
CVSS 9.8
CVE-2020-15150 CRITICAL
Paginator < 1.0.0 - Remote Code Execution via paginate() Function Input
CVSS 9.0
CVE-2020-15147 HIGH
Red Discord Bot < 3.3.12 - Remote Code Execution via Streams Module Going Live Message
CVSS 8.5
CVE-2020-7710 HIGH
safe-eval - Remote Code Execution
CVSS 8.1
CVE-2020-15070 HIGH
Zulip Server <2.1.7 - Code Injection
CVSS 8.8
CVE-2020-15865 CRITICAL
Stimulsoft Reports 2013.1.1600.0 - Remote Code Execution via Base-64 Encoded C# Scripts in Report XML
CVSS 9.8
CVE-2020-15142 HIGH
openapi-python-client <0.5.3 - Code Injection
CVSS 8.0
CVE-2020-10055 CRITICAL
Siemens Desigo CC and Desigo CC Compact - Remote Code Execution via BIRT Advanced Reporting Engine
CVSS 9.8
CVE-2020-8224 HIGH
Nextcloud Desktop Client 2.6.4 - Code Injection
CVSS 7.8
CVE-2020-8218 HIGH KEV
Pulse Connect Secure <9.1R8 - Code Injection
CVSS 7.2
CVE-2020-7694 LOW
uvicorn < 0.11.7 - ANSI Escape Sequence Injection via Request Logger
CVSS 3.7
CVE-2020-12013 CRITICAL
Mitsubishi Electric MC Works32 and MC Works64 < 10.95.208.31 - Remote Code Execution via WCF Client
CVSS 9.1
CVE-2020-11546 CRITICAL
SuperWebMailer < 7.40.0.01550 - Unauthenticated Remote Code Execution via Language Parameter
CVSS 9.8
CVE-2020-8194 MEDIUM
Citrix ADC & Gateway <13.0-58.30 - Code Injection
CVSS 6.5
CVE-2020-8163 HIGH
Rails < 5.0.1 - Remote Code Execution via Render Locals Argument
CVSS 8.8
CVE-2020-15348 CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Code Injection
CVSS 9.8
CVE-2020-5593 HIGH
Zenphoto < 1.5.7 - PHP Code Injection via Crafted ZIP Upload
CVSS 8.8
CVE-2020-7675 CRITICAL
cd-messenger <= 2.7.26 - Remote Code Execution via Color Argument Eval Injection
CVSS 9.8
CVE-2020-7674 CRITICAL
access-policy < 3.1.0 - Remote Code Execution via Template Function
CVSS 9.8
CVE-2020-7673 CRITICAL
node-extend < 0.2.0 - Remote Code Execution via Unsafe Eval in extend Function
CVSS 9.8
Details
Vulnerabilities 6,528
Exploit Likelihood Medium