CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,503 vulnerabilities with CWE-94
CVE-2024-10572
HIGH
h2o 3.46.0.1 - Denial of Service via XGBoostLibExtractTool in run_tool Command
CVSS 7.5
CVE-2024-10252
HIGH
langgenius/dify <=v0.9.1 - Code Injection
CVSS 7.2
CVE-2024-57061
CRITICAL
Termius 9.9.0-9.16.0 - Arbitrary Code Execution via Insecure Electron Fuses Configuration
CVSS 9.8
CVE-2024-21760
HIGH
FortiSOAR 6.4.0-7.4.4 - Authenticated Code Injection via Playbook Code Snippet
CVSS 8.4
CVE-2024-54448
HIGH
LogicalDOC < 9.1 - Authenticated Remote Code Execution via Automation Scripting
CVSS 7.2
CVE-2024-29409
MEDIUM
nestjs/nest 10.3.2 - Remote Code Execution via Content-Type Header
CVSS 5.5
CVE-2024-13895
MEDIUM
Code Snippets CPT < 2.1.0 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 4.3
CVE-2024-13890
HIGH
Allow PHP Execute <= 1.0 - Authenticated PHP Code Injection via Unfiltered HTML
CVSS 7.2
CVE-2024-42733
CRITICAL
Docmosis Tornado < 2.9.7 - Remote Code Execution via UNC Path Input
CVSS 9.8
CVE-2024-53693
HIGH
QNAP QTS and QuTS hero - CRLF Injection
CVSS 7.1
CVE-2024-50405
MEDIUM
QNAP OS <5.2.3.3006 - CRLF Injection
CVSS 5.5
CVE-2024-13902
LOW
huang-yk student-manage 1.0 - Cross-Site Scripting via Class Parameter
CVSS 2.4
CVE-2024-13815
MEDIUM
Listingo <= 3.2.7 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 6.5
CVE-2024-50707
CRITICAL
Uniguest Tripleplay < 24.2.1 - Unauthenticated Remote Code Execution via X-Forwarded-For Header
CVSS 10.0
CVE-2024-50704
CRITICAL
Uniguest Tripleplay < 24.2.1 - Unauthenticated Remote Code Execution via HTTP POST Request
CVSS 10.0
CVE-2024-53386
MEDIUM
stage.js < 0.8.10 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
CVSS 4.9
CVE-2024-53382
MEDIUM
PrismJS < 1.29.0 - DOM Clobbering and Cross-Site Scripting via document.currentScript Shadowing
CVSS 4.9
CVE-2024-13806
MEDIUM
The Authors List plugin <2.0.6 - RCE
CVSS 6.5
CVE-2024-53944
CRITICAL
Tuoshi/Dionlink LT15D/LT21B - Command Injection
CVSS 9.8
CVE-2024-9285
MEDIUM
Via Browser <= 5.9.0 - Cross-Site Scripting via JavaScript Bridge
CVSS 4.3
CVE-2024-52925
MEDIUM
OPSWAT MetaDefender Kiosk <4.7.0 - RCE
CVSS 6.8
CVE-2024-47051
CRITICAL
Mautic < 5.2.3 - Authenticated Remote Code Execution and Path Traversal via Asset Upload
CVSS 9.1
CVE-2024-13900
MEDIUM
Head, Footer and Post Injections <= 3.3.0 - Authenticated PHP Code Injection
CVSS 4.1
CVE-2024-54756
CRITICAL
GZDoom 4.13.1 - Remote Code Execution via Crafted PK3 ZScript File
CVSS 9.8
CVE-2024-57401
CRITICAL
Uniclare Student Portal <2 - SQL Injection
CVSS 9.8
Details
Vulnerabilities
6,503
Exploit Likelihood
Medium