CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,503 vulnerabilities with CWE-94
CVE-2024-10572 HIGH
h2o 3.46.0.1 - Denial of Service via XGBoostLibExtractTool in run_tool Command
CVSS 7.5
CVE-2024-10252 HIGH
langgenius/dify <=v0.9.1 - Code Injection
CVSS 7.2
CVE-2024-57061 CRITICAL
Termius 9.9.0-9.16.0 - Arbitrary Code Execution via Insecure Electron Fuses Configuration
CVSS 9.8
CVE-2024-21760 HIGH
FortiSOAR 6.4.0-7.4.4 - Authenticated Code Injection via Playbook Code Snippet
CVSS 8.4
CVE-2024-54448 HIGH
LogicalDOC < 9.1 - Authenticated Remote Code Execution via Automation Scripting
CVSS 7.2
CVE-2024-29409 MEDIUM
nestjs/nest 10.3.2 - Remote Code Execution via Content-Type Header
CVSS 5.5
CVE-2024-13895 MEDIUM
Code Snippets CPT < 2.1.0 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 4.3
CVE-2024-13890 HIGH
Allow PHP Execute <= 1.0 - Authenticated PHP Code Injection via Unfiltered HTML
CVSS 7.2
CVE-2024-42733 CRITICAL
Docmosis Tornado < 2.9.7 - Remote Code Execution via UNC Path Input
CVSS 9.8
CVE-2024-53693 HIGH
QNAP QTS and QuTS hero - CRLF Injection
CVSS 7.1
CVE-2024-50405 MEDIUM
QNAP OS <5.2.3.3006 - CRLF Injection
CVSS 5.5
CVE-2024-13902 LOW
huang-yk student-manage 1.0 - Cross-Site Scripting via Class Parameter
CVSS 2.4
CVE-2024-13815 MEDIUM
Listingo <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 6.5
CVE-2024-50707 CRITICAL
Uniguest Tripleplay < 24.2.1 - Unauthenticated Remote Code Execution via X-Forwarded-For Header
CVSS 10.0
CVE-2024-50704 CRITICAL
Uniguest Tripleplay < 24.2.1 - Unauthenticated Remote Code Execution via HTTP POST Request
CVSS 10.0
CVE-2024-53386 MEDIUM
stage.js < 0.8.10 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
CVSS 4.9
CVE-2024-53382 MEDIUM
PrismJS < 1.29.0 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
CVSS 4.9
CVE-2024-13806 MEDIUM
The Authors List plugin <2.0.6 - RCE
CVSS 6.5
CVE-2024-53944 CRITICAL
Tuoshi/Dionlink LT15D/LT21B - Command Injection
CVSS 9.8
CVE-2024-9285 MEDIUM
Via Browser <= 5.9.0 - Cross-Site Scripting via JavaScript Bridge
CVSS 4.3
CVE-2024-52925 MEDIUM
OPSWAT MetaDefender Kiosk <4.7.0 - RCE
CVSS 6.8
CVE-2024-47051 CRITICAL
Mautic < 5.2.3 - Authenticated Remote Code Execution and Path Traversal via Asset Upload
CVSS 9.1
CVE-2024-13900 MEDIUM
Head, Footer and Post Injections <= 3.3.0 - Authenticated PHP Code Injection
CVSS 4.1
CVE-2024-54756 CRITICAL
GZDoom 4.13.1 - Remote Code Execution via Crafted PK3 ZScript File
CVSS 9.8
CVE-2024-57401 CRITICAL
Uniclare Student Portal <2 - SQL Injection
CVSS 9.8
Details
Vulnerabilities 6,503
Exploit Likelihood Medium