CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,528 vulnerabilities with CWE-94
CVE-2020-7672 HIGH
mosc < 1.0.0 - Remote Code Execution via Eval Injection in Properties Argument
CVSS 8.6
CVE-2020-8180 CRITICAL
Nextcloud Talk <8.0.7 - Code Injection
CVSS 9.9
CVE-2020-7013 HIGH
Kibana < 6.8.9 - Authenticated Remote Code Execution via TSVB Visualization
CVSS 7.2
CVE-2020-7012 HIGH
Kibana 6.7.0-6.8.8 and 7.0.0-7.6.2 - Authenticated Code Injection in Upgrade Assistant
CVSS 8.8
CVE-2020-13756 CRITICAL
sabberworm/php_css_parser < 8.3.1 - Remote Code Execution via eval in allSelectors or getSelectorsBySpecificity
CVSS 9.8
CVE-2020-11079 HIGH
node-dns-sync <0.2.1 - Command Injection
CVSS 8.6
CVE-2020-13144 HIGH
Open edX Ironwood 2.5 - Unauthenticated Remote Code Execution via Custom Python Evaluated Code
CVSS 8.8
CVE-2020-8149 CRITICAL
logkitty < 0.7.1 - Remote Code Execution via Unsanitized Output
CVSS 9.8
CVE-2020-11057 CRITICAL
XWiki 7.2-11.10.2 - Authenticated Remote Code Execution via Personal Dashboard Script Injection
CVSS 9.9
CVE-2020-6262 HIGH
SAP Application Server ABAP <740 - Code Injection
CVSS 8.8
CVE-2020-6248 HIGH
SAP Adaptive Server Enterprise Backup Server 16.0 - Authenticated Code Injection via DUMP or LOAD Command
CVSS 7.2
CVE-2020-6243 HIGH
SAP Adaptive Server Enterprise <16.0 - Privilege Escalation
CVSS 8.8
CVE-2020-11056 HIGH
Sprout Forms < 3.9.0 - Server-Side Template Injection via Notification Email Custom Fields
CVSS 7.4
CVE-2020-10176 CRITICAL
ASSA ABLOY Yale WIPC-301W 2.x.2.29-2.x.2.43_p1 - Remote Code Execution via Eval Injection
CVSS 9.8
CVE-2020-7609 CRITICAL
node-rules 3.0.0-5.0.0 - Remote Code Execution via fromJSON() Argument Injection
CVSS 9.8
CVE-2020-5739 HIGH
Grandstream GXP1600 - Authenticated Command Injection
CVSS 8.8
CVE-2020-10948 CRITICAL
AlienForm2 2.0.2 - Unauthenticated Remote Command Execution via Eval Injection
CVSS 9.8
CVE-2020-5558 HIGH
CuteNews 2.0.1 - Authenticated PHP Code Injection
CVSS 8.8
CVE-2020-5553 CRITICAL
mailform 1.04 - Remote Code Execution
CVSS 9.8
CVE-2020-10684 HIGH
Ansible Engine <2.7.17, 2.8.9, 2.9.6 - Privilege Escalation/Code In...
CVSS 7.9
CVE-2020-7480 CRITICAL
Andover Continuum - Code Injection via XML Processing
CVSS 9.8
CVE-2020-6650 HIGH
Eaton UPS Companion < 1.05 - Remote Code Execution via Update Manager Eval Injection
CVSS 8.3
CVE-2020-8140 MEDIUM
Nextcloud Desktop Client <2.6.2 - Code Injection
CVSS 6.7
CVE-2020-8137 CRITICAL
blamer < 1.0.1 - Remote Code Execution via Code Injection
CVSS 9.8
CVE-2020-8141 HIGH
dot package <1.1.2 - Code Injection
CVSS 8.8
Details
Vulnerabilities 6,528
Exploit Likelihood Medium