CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,528 vulnerabilities with CWE-94
CVE-2019-15388 HIGH
Coolpad Mega 5 Firmware - Unauthenticated Remote Code Execution via MITM Command Injection
CVSS 8.1
CVE-2019-10211 CRITICAL
Postgresql <11.5-9.4.24 - Code Injection
CVSS 9.8
CVE-2019-17526 CRITICAL
SageMath Sage Cell Server - OS Command Injection via Python Code Execution
CVSS 9.8
CVE-2019-17613 CRITICAL
qibosoft 7 - Remote Code Execution via Point Introduction Management Feature
CVSS 9.8
CVE-2019-17408 CRITICAL
ZZZCMS zzzphp 1.7.3 - Remote Code Execution via Template Parser Bypass
CVSS 9.8
CVE-2019-3652 MEDIUM
McAfee Endpoint Security < 10.6.1 - Code Injection via EPSetup.exe
CVSS 5.0
CVE-2019-17310 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Campaigns Module
CVSS 7.2
CVE-2019-17309 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in EmailMan Module
CVSS 7.2
CVE-2019-17308 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Emails Module
CVSS 8.8
CVE-2019-17307 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Tracker Module
CVSS 7.2
CVE-2019-17306 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Configurator Module
CVSS 7.2
CVE-2019-17305 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 8.8
CVE-2019-17304 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 7.2
CVE-2019-17303 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 8.8
CVE-2019-17302 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in ModuleBuilder
CVSS 8.8
CVE-2019-17301 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via ModuleBuilder
CVSS 7.2
CVE-2019-17300 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Administration Module
CVSS 8.8
CVE-2019-17299 HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Administration Module
CVSS 7.2
CVE-2019-15746 CRITICAL
SITOS six v6.2.1 - OS Command Injection
CVSS 9.8
CVE-2019-17132 CRITICAL
vBulletin <= 5.5.4 - Remote Code Execution via Custom Avatar Handling
CVSS 9.8
CVE-2019-10431 CRITICAL
Jenkins Script Security Plugin < 1.64 - Sandbox Bypass via Default Parameter Expressions
CVSS 9.9
CVE-2019-16759 CRITICAL KEV
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
CVSS 9.8
CVE-2019-16645 HIGH
Embedthis GoAhead 2.5.0 - Info Disclosure
CVSS 8.6
CVE-2019-15087 HIGH
PRiSE adAS 1.7.0 - Authenticated Remote Code Execution via Password Hash Function Manipulation
CVSS 7.2
CVE-2019-15001 HIGH
Atlassian Jira Server/Data Center RCE via Template Injection (7.0.10-8.4.0)
CVSS 7.2
Details
Vulnerabilities 6,528
Exploit Likelihood Medium