CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,528 vulnerabilities with CWE-94
CVE-2019-15388
HIGH
Coolpad Mega 5 Firmware - Unauthenticated Remote Code Execution via MITM Command Injection
CVSS 8.1
CVE-2019-10211
CRITICAL
Postgresql <11.5-9.4.24 - Code Injection
CVSS 9.8
CVE-2019-17526
CRITICAL
SageMath Sage Cell Server - OS Command Injection via Python Code Execution
CVSS 9.8
CVE-2019-17613
CRITICAL
qibosoft 7 - Remote Code Execution via Point Introduction Management Feature
CVSS 9.8
CVE-2019-17408
CRITICAL
ZZZCMS zzzphp 1.7.3 - Remote Code Execution via Template Parser Bypass
CVSS 9.8
CVE-2019-3652
MEDIUM
McAfee Endpoint Security < 10.6.1 - Code Injection via EPSetup.exe
CVSS 5.0
CVE-2019-17310
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Campaigns Module
CVSS 7.2
CVE-2019-17309
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in EmailMan Module
CVSS 7.2
CVE-2019-17308
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Emails Module
CVSS 8.8
CVE-2019-17307
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Tracker Module
CVSS 7.2
CVE-2019-17306
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Configurator Module
CVSS 7.2
CVE-2019-17305
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 8.8
CVE-2019-17304
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 7.2
CVE-2019-17303
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via MergeRecords Module
CVSS 8.8
CVE-2019-17302
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in ModuleBuilder
CVSS 8.8
CVE-2019-17301
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection via ModuleBuilder
CVSS 7.2
CVE-2019-17300
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Administration Module
CVSS 8.8
CVE-2019-17299
HIGH
SugarCRM 7.9.0.0-7.9.5.0 - Authenticated PHP Code Injection in Administration Module
CVSS 7.2
CVE-2019-15746
CRITICAL
SITOS six v6.2.1 - OS Command Injection
CVSS 9.8
CVE-2019-17132
CRITICAL
vBulletin <= 5.5.4 - Remote Code Execution via Custom Avatar Handling
CVSS 9.8
CVE-2019-10431
CRITICAL
Jenkins Script Security Plugin < 1.64 - Sandbox Bypass via Default Parameter Expressions
CVSS 9.9
CVE-2019-16759
CRITICAL
KEV
vBulletin 5.x /ajax/render/widget_tabbedcontainer_tab_panel PHP remote code execution.
CVSS 9.8
CVE-2019-16645
HIGH
Embedthis GoAhead 2.5.0 - Info Disclosure
CVSS 8.6
CVE-2019-15087
HIGH
PRiSE adAS 1.7.0 - Authenticated Remote Code Execution via Password Hash Function Manipulation
CVSS 7.2
CVE-2019-15001
HIGH
Atlassian Jira Server/Data Center RCE via Template Injection (7.0.10-8.4.0)
CVSS 7.2
Details
Vulnerabilities
6,528
Exploit Likelihood
Medium