CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,506 vulnerabilities with CWE-94
CVE-2024-13900
MEDIUM
Head, Footer and Post Injections <= 3.3.0 - Authenticated PHP Code Injection
CVSS 4.1
CVE-2024-54756
CRITICAL
GZDoom 4.13.1 - Remote Code Execution via Crafted PK3 ZScript File
CVSS 9.8
CVE-2024-57401
CRITICAL
Uniclare Student Portal <2 - SQL Injection
CVSS 9.8
CVE-2024-13792
HIGH
WooCommerce Food - Restaurant Menu & Food ordering <= 3.3.2 - Unauthenticated Arbitrary Shortcode Execution
CVSS 7.3
CVE-2024-13689
MEDIUM
Uncode Core <= 2.9.1.6 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 6.3
CVE-2024-13797
HIGH
PressMart Modern Elementor WooCommerce WordPress Theme <= 1.2.16 - Unauthenticated Arbitrary Shortcode Execution
CVSS 7.3
CVE-2024-13346
HIGH
WordPress Avada <= 7.11.13 - Unauthenticated Shortcode Execution
CVSS 7.3
CVE-2024-13345
HIGH
Avada Builder < 3.11.13 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 7.3
CVE-2024-13814
MEDIUM
Global Gallery - WordPress Responsive Gallery <= 9.1.5 - Authenticated Arbitrary Shortcode Execution
CVSS 5.4
CVE-2024-10644
CRITICAL
Ivanti Connect Secure < 22.7R2.4 and Policy Secure < 22.7R1.3 - Authenticated Remote Code Execution via Code Injection
CVSS 9.1
CVE-2024-27859
HIGH
Apple iOS iPadOS macOS tvOS visionOS watchOS < 17.4 14.4 17.4 1.1 10.4 - Remote Code Execution
CVSS 8.8
CVE-2024-7425
MEDIUM
WP All Export Pro <= 1.9.1 - Authenticated Privilege Escalation via Arbitrary Option Update
CVSS 6.8
CVE-2024-7419
HIGH
WP All Export Pro <= 1.9.1 - Unauthenticated Remote Code Execution via Custom Export Fields
CVSS 8.3
CVE-2024-57707
CRITICAL
DataEase v1 - Remote Code Execution via User Account and Password Components
CVSS 9.8
CVE-2024-57609
HIGH
Kanaries Inc Pygwalker <0.4.9.9 - RCE
CVSS 8.6
CVE-2024-55241
HIGH
LMM-As-Chatbot <commit 99c2c03 - RCE
CVSS 8.8
CVE-2024-13487
HIGH
CURCY - Multi Currency for WooCommerce <2.2.5 - RCE
CVSS 7.3
CVE-2024-57099
CRITICAL
ClassCMS 4.8 - Remote Code Execution via Model Management Classview Parameter
CVSS 9.8
CVE-2024-12415
MEDIUM
AI Infographic Maker <= 4.9.0 - Unauthenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 6.5
CVE-2024-13472
HIGH
WooCommerce Product Table Lite <3.9.4 - RCE
CVSS 7.3
CVE-2024-23921
HIGH
ChargePoint Home Flex Firmware - Unauthenticated Remote Code Execution via wlanapp Module
CVSS 8.8
CVE-2024-23963
HIGH
Alpine Halo9 ilx-f509_firmware - Remote Code Execution via PBAP_DecodeVCARD Buffer Overflow
CVSS 8.0
CVE-2024-11600
HIGH
WordPress Borderless <= 1.6.0 - Admin write_config Code Execution
CVSS 7.2
CVE-2024-13453
HIGH
WordPress PirateForms <= 2.6.0 - Unauthenticated Shortcode Execution
CVSS 7.3
CVE-2024-10001
HIGH
GitHub Enterprise Server - Code Injection
CVSS 7.1
Details
Vulnerabilities
6,506
Exploit Likelihood
Medium