CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,530 vulnerabilities with CWE-94
CVE-2018-20988 HIGH
Google Forms < 0.94 - Code Injection
CVSS 7.5
CVE-2018-18573 HIGH
osCommerce 2.3.4.1 - Authenticated Remote Code Execution via .htaccess Upload
CVSS 7.2
CVE-2018-20931 MEDIUM
cPanel 61.9999.55-70.0.22 - Authenticated Remote Code Execution via Landing Page
CVSS 6.3
CVE-2018-20896 LOW
cPanel 61.9999.55-61.9999.9999 - Code Injection in WHM cPAddons Interface
CVSS 3.9
CVE-2018-17170 HIGH
Grouptime Teamwire Desktop Client <1.9.0 - Code Injection
CVSS 8.1
CVE-2018-18836 MEDIUM
Netdata 1.10.0 - JSON Injection via tqx Parameter
CVSS 6.5
CVE-2018-18879 HIGH
Columbia Weather MicroServer Firmware MS_2.6.9900 - Authenticated OS Command Injection via networkdiags.php
CVSS 8.8
CVE-2018-19641 MEDIUM
Micro Focus Solutions Business Manager < 11.5 - Unauthenticated Remote Code Execution
CVSS 6.1
CVE-2018-3700 MEDIUM
Intel USB 3.0 eXtensible Host Controller Driver < 5.0.4.43v2 - Code Injection via Installer
CVSS 6.7
CVE-2018-20775 HIGH
Frog CMS 0.9.5 - Unauthenticated Remote Code Execution via File Manager Plugin
CVSS 7.2
CVE-2018-20773 HIGH
Frog CMS 0.9.5 - PHP Code Injection via Page Edit Function
CVSS 7.2
CVE-2018-20772 HIGH
Frog CMS 0.9.5 - PHP Code Execution via Layout Edit URI
CVSS 7.2
CVE-2018-20768 CRITICAL
Xerox WorkCentre Multiple Models < R18-05 073.xxx.0487.15000 - PHP Code Execution
CVSS 9.8
CVE-2018-19002 HIGH
LCDS Laquis SCADA < 4.1.0.4150 - Remote Code Execution via Crafted Project File
CVSS 7.8
CVE-2018-19011 HIGH
CX-Supervisor < 3.42 - Code Injection via Project File
CVSS 8.8
CVE-2018-20717 HIGH
PrestaShop < 1.7.2.5 - Authenticated Remote Code Execution via Serialized Object Injection
CVSS 8.8
CVE-2018-0461 MEDIUM
Cisco IP Phone 8800 Series Firmware - Unauthenticated Arbitrary Script Injection via User-Supplied Data
CVSS 6.5
CVE-2018-16168 CRITICAL
LogonTracer < 1.2.0 - Remote Code Execution via Python Code Injection
CVSS 9.8
CVE-2018-20605 CRITICAL
imcat 4.4 - Remote Code Execution via bootskip.php Modification
CVSS 9.8
CVE-2018-20599 HIGH
UCMS 1.4.7 - Remote Code Execution via sadmin_fileedit Action
CVSS 8.8
CVE-2018-7801 HIGH
EVLink Parking <3.2.0-12_v1 - Code Injection
CVSS 8.8
CVE-2018-20325 CRITICAL
Definitions Parser - Command Injection
CVSS 9.8
CVE-2018-1000881 CRITICAL
Traccar Server <4.0 - Code Injection
CVSS 9.8
CVE-2018-20300 CRITICAL
Empire CMS 7.5 - Remote Code Execution
CVSS 9.8
CVE-2018-20133 CRITICAL
ymlref - Code Injection
CVSS 9.8
Details
Vulnerabilities 6,530
Exploit Likelihood Medium