CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,528 vulnerabilities with CWE-94
CVE-2020-15171
MEDIUM
XWiki < 11.10.5 - Authenticated Remote Code Execution via Servlet Context Access
CVSS 6.6
CVE-2020-6318
HIGH
SAP NetWeaver <7.40 & ABAP Platform >7.40 - RCE
CVSS 7.2
CVE-2020-7381
MEDIUM
Rapid7 Nexpose < 6.6.40 - Unauthenticated Code Execution via Executable Spoofing
CVSS 5.8
CVE-2020-15167
HIGH
Miller 5.9.0 - Unauthenticated Remote Code Execution via Malicious .mlrrc File
CVSS 8.2
CVE-2020-6144
CRITICAL
OS4Ed openSIS 7.4 - Remote Code Execution via Username Variable in Install Step5
CVSS 9.8
CVE-2020-6143
CRITICAL
OS4Ed openSIS 7.4 - Remote Code Execution via Install Password Variable Injection
CVSS 9.8
CVE-2020-15150
CRITICAL
Paginator < 1.0.0 - Remote Code Execution via paginate() Function Input
CVSS 9.0
CVE-2020-15147
HIGH
Red Discord Bot < 3.3.12 - Remote Code Execution via Streams Module Going Live Message
CVSS 8.5
CVE-2020-7710
HIGH
safe-eval - Remote Code Execution
CVSS 8.1
CVE-2020-15070
HIGH
Zulip Server <2.1.7 - Code Injection
CVSS 8.8
CVE-2020-15865
CRITICAL
Stimulsoft Reports 2013.1.1600.0 - Remote Code Execution via Base-64 Encoded C# Scripts in Report XML
CVSS 9.8
CVE-2020-15142
HIGH
openapi-python-client <0.5.3 - Code Injection
CVSS 8.0
CVE-2020-10055
CRITICAL
Siemens Desigo CC and Desigo CC Compact - Remote Code Execution via BIRT Advanced Reporting Engine
CVSS 9.8
CVE-2020-8224
HIGH
Nextcloud Desktop Client 2.6.4 - Code Injection
CVSS 7.8
CVE-2020-8218
HIGH
KEV
Pulse Connect Secure <9.1R8 - Code Injection
CVSS 7.2
CVE-2020-7694
LOW
uvicorn < 0.11.7 - ANSI Escape Sequence Injection via Request Logger
CVSS 3.7
CVE-2020-12013
CRITICAL
Mitsubishi Electric MC Works32 and MC Works64 < 10.95.208.31 - Remote Code Execution via WCF Client
CVSS 9.1
CVE-2020-11546
CRITICAL
SuperWebMailer < 7.40.0.01550 - Unauthenticated Remote Code Execution via Language Parameter
CVSS 9.8
CVE-2020-8194
MEDIUM
Citrix ADC & Gateway <13.0-58.30 - Code Injection
CVSS 6.5
CVE-2020-8163
HIGH
Rails < 5.0.1 - Remote Code Execution via Render Locals Argument
CVSS 8.8
CVE-2020-15348
CRITICAL
Zyxel CloudCNM SecuManager <3.1.1 - Code Injection
CVSS 9.8
CVE-2020-5593
HIGH
Zenphoto < 1.5.7 - PHP Code Injection via Crafted ZIP Upload
CVSS 8.8
CVE-2020-7675
CRITICAL
cd-messenger <= 2.7.26 - Remote Code Execution via Color Argument Eval Injection
CVSS 9.8
CVE-2020-7674
CRITICAL
access-policy < 3.1.0 - Remote Code Execution via Template Function
CVSS 9.8
CVE-2020-7673
CRITICAL
node-extend < 0.2.0 - Remote Code Execution via Unsafe Eval in extend Function
CVSS 9.8
Details
Vulnerabilities
6,528
Exploit Likelihood
Medium