CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,530 vulnerabilities with CWE-94
CVE-2018-20988
HIGH
Google Forms < 0.94 - Code Injection
CVSS 7.5
CVE-2018-18573
HIGH
osCommerce 2.3.4.1 - Authenticated Remote Code Execution via .htaccess Upload
CVSS 7.2
CVE-2018-20931
MEDIUM
cPanel 61.9999.55-70.0.22 - Authenticated Remote Code Execution via Landing Page
CVSS 6.3
CVE-2018-20896
LOW
cPanel 61.9999.55-61.9999.9999 - Code Injection in WHM cPAddons Interface
CVSS 3.9
CVE-2018-17170
HIGH
Grouptime Teamwire Desktop Client <1.9.0 - Code Injection
CVSS 8.1
CVE-2018-18836
MEDIUM
Netdata 1.10.0 - JSON Injection via tqx Parameter
CVSS 6.5
CVE-2018-18879
HIGH
Columbia Weather MicroServer Firmware MS_2.6.9900 - Authenticated OS Command Injection via networkdiags.php
CVSS 8.8
CVE-2018-19641
MEDIUM
Micro Focus Solutions Business Manager < 11.5 - Unauthenticated Remote Code Execution
CVSS 6.1
CVE-2018-3700
MEDIUM
Intel USB 3.0 eXtensible Host Controller Driver < 5.0.4.43v2 - Code Injection via Installer
CVSS 6.7
CVE-2018-20775
HIGH
Frog CMS 0.9.5 - Unauthenticated Remote Code Execution via File Manager Plugin
CVSS 7.2
CVE-2018-20773
HIGH
Frog CMS 0.9.5 - PHP Code Injection via Page Edit Function
CVSS 7.2
CVE-2018-20772
HIGH
Frog CMS 0.9.5 - PHP Code Execution via Layout Edit URI
CVSS 7.2
CVE-2018-20768
CRITICAL
Xerox WorkCentre Multiple Models < R18-05 073.xxx.0487.15000 - PHP Code Execution
CVSS 9.8
CVE-2018-19002
HIGH
LCDS Laquis SCADA < 4.1.0.4150 - Remote Code Execution via Crafted Project File
CVSS 7.8
CVE-2018-19011
HIGH
CX-Supervisor < 3.42 - Code Injection via Project File
CVSS 8.8
CVE-2018-20717
HIGH
PrestaShop < 1.7.2.5 - Authenticated Remote Code Execution via Serialized Object Injection
CVSS 8.8
CVE-2018-0461
MEDIUM
Cisco IP Phone 8800 Series Firmware - Unauthenticated Arbitrary Script Injection via User-Supplied Data
CVSS 6.5
CVE-2018-16168
CRITICAL
LogonTracer < 1.2.0 - Remote Code Execution via Python Code Injection
CVSS 9.8
CVE-2018-20605
CRITICAL
imcat 4.4 - Remote Code Execution via bootskip.php Modification
CVSS 9.8
CVE-2018-20599
HIGH
UCMS 1.4.7 - Remote Code Execution via sadmin_fileedit Action
CVSS 8.8
CVE-2018-7801
HIGH
EVLink Parking <3.2.0-12_v1 - Code Injection
CVSS 8.8
CVE-2018-20325
CRITICAL
Definitions Parser - Command Injection
CVSS 9.8
CVE-2018-1000881
CRITICAL
Traccar Server <4.0 - Code Injection
CVSS 9.8
CVE-2018-20300
CRITICAL
Empire CMS 7.5 - Remote Code Execution
CVSS 9.8
CVE-2018-20133
CRITICAL
ymlref - Code Injection
CVSS 9.8
Details
Vulnerabilities
6,530
Exploit Likelihood
Medium