CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,528 vulnerabilities with CWE-94
CVE-2020-10389
HIGH
Chadha PHPKB Standard Multi-Language 9 - Authenticated Remote Code Execution via Global Settings POST Parameters
CVSS 7.2
CVE-2020-5203
CRITICAL
Fat-Free Framework < 3.7.2 - Remote Code Execution via Clear Method
CVSS 9.8
CVE-2020-5259
HIGH
dojox < 1.11.10 - Prototype Pollution via jqMix Method
CVSS 7.7
CVE-2020-5258
HIGH
dojo < 1.11.10 - Prototype Pollution via deepCopy Method
CVSS 7.7
CVE-2020-10257
CRITICAL
ThemeREX Addons < 2020-03-09 - Unauthenticated Remote Code Execution via REST API Endpoint
CVSS 9.8
CVE-2020-9530
MEDIUM
MIUI Firmware - Information Disclosure via GetApps Export Component
CVSS 6.5
CVE-2020-8132
CRITICAL
pdf-image <= 2.0.0 - Remote Code Execution via Untrusted PDF File Path
CVSS 9.8
CVE-2020-9406
CRITICAL
IBL Online Weather < 4.3.5 - Unauthenticated Code Injection via queryBCP Method
CVSS 9.8
CVE-2020-8518
CRITICAL
Horde Groupware Webmail Edition <5.2.22 - Code Injection
CVSS 9.8
CVE-2020-8129
CRITICAL
script-manager < 0.8.6 - Remote Code Execution via Unintended Require
CVSS 9.8
CVE-2020-5529
HIGH
HtmlUnit < 2.37.0 - Remote Code Execution via Improper Rhino Engine Initialization
CVSS 8.1
CVE-2020-8644
CRITICAL
KEV
playsms < 1.4.3 - Unauthenticated Remote Code Execution via Template Injection
CVSS 9.8
CVE-2020-6836
CRITICAL
hot-formula-parser < 3.0.1 - Remote Code Execution via Unsanitized Formula Input
CVSS 9.8
CVE-2019-25468
CRITICAL
NetGain EM Plus 10.1.68 - Unauthenticated Remote Code Execution via script_test.jsp Content Parameter
CVSS 9.8
CVE-2019-25262
LOW
elinicksic Razgover <db37dfc5c82f023a40f2f7834ded6633fb2b5262 - XSS
CVSS 3.5
CVE-2019-8900
MEDIUM
Apple SecureROM - Unauthenticated Arbitrary Code Execution via DFU Mode Exploit
CVSS 6.8
CVE-2019-16283
HIGH
HP SoftPaq Installer - Arbitrary Code Execution
CVSS 7.8
CVE-2019-14827
MEDIUM
Moodle 3.5.0-3.5.7 - Cross-Site Scripting via Mustache Template Recursive Rendering
CVSS 6.1
CVE-2019-20920
HIGH
Handlebars <3.0.8 & 4.x <4.5.3 - RCE
CVSS 8.1
CVE-2019-7177
HIGH
Pexip Infinity <20.1 - Code Injection
CVSS 7.2
CVE-2019-5997
CRITICAL
Panasonic Video Insight VMS < 7.5 - Remote Code Injection
CVSS 9.8
CVE-2019-19089
MEDIUM
Hitachi Energy eSOMS 4.0-6.0.3 - Missing X-Content-Type-Options Header
CVSS 6.1
CVE-2019-9163
CRITICAL
March Networks Command Client < 2.7.2 - Remote Code Execution via Crafted XAML Objects
CVSS 9.8
CVE-2019-16108
HIGH
phpBB 3.2.7 - Cascading Style Sheets Injection via BBCode
CVSS 7.5
CVE-2019-18582
HIGH
Dell EMC Data Protection Advisor <19.1-6.5 - Server-Side Template I...
CVSS 7.2
Details
Vulnerabilities
6,528
Exploit Likelihood
Medium