CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,506 vulnerabilities with CWE-94
CVE-2024-40673 MEDIUM
Android Java ZipFile - Dynamic Code Loading Remote Code Execution
CVSS 6.5
CVE-2024-13499 HIGH
GamiPress - Gamification <7.2.1 - RCE
CVSS 7.3
CVE-2024-13495 HIGH
GamiPress < 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs
CVSS 7.3
CVE-2024-49747 CRITICAL
Android Bluetooth GATT - Out-of-Bounds Write Remote Code Execution
CVSS 9.8
CVE-2024-43771 HIGH
Android - Remote Code Execution via Missing Bounds Check in gatts_process_read_req
CVSS 8.8
CVE-2024-43770 HIGH
Android - Remote Code Execution via Missing Bounds Check in gatts_process_find_info
CVSS 8.8
CVE-2024-24421 CRITICAL
Magma <= 1.8.0 - Remote Code Execution via NAS Packet Type Confusion
CVSS 9.8
CVE-2024-51941 HIGH
Ambari - Authenticated Code Injection
CVSS 8.8
CVE-2024-42936 CRITICAL
Ruijie RG-EW300N - ReyeeOS 1.300.1422 - RCE
CVSS 9.8
CVE-2024-55504 MEDIUM
RAR Extractor - Unarchiver Free and Pro <6.4.0 - Code Injection
CVSS 5.5
CVE-2024-10970 MEDIUM
Motors - Car Dealer, Classifieds & Listing < 1.4.43 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 5.4
CVE-2024-27856 HIGH
Apple Safari and OSes - File Processing Arbitrary Code Execution
CVSS 7.8
CVE-2024-42911 HIGH
ECOVACS Robotics Deebot T20 OMNI & T20e OMNI <1.24.0 - RCE
CVSS 7.4
CVE-2024-49375 CRITICAL
Rasa < 3.6.21 and Rasa-Pro < 3.10.12 - Remote Code Execution via Malicious Model Deserialization
CVSS 9.0
CVE-2024-53561 HIGH
Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 - RCE
CVSS 8.7
CVE-2024-57487 MEDIUM
Car Rental System 1.0 File Upload RCE (Authenticated)
CVSS 6.5
CVE-2024-54999 MEDIUM
MonicaHQ 4.1.2 - Client-Side Injection via Last Name Parameter
CVSS 6.5
CVE-2024-9132 HIGH
Arista ng_firewall < 17.1.1 - Authenticated Code Injection via Captive Portal Script
CVSS 8.1
CVE-2024-54997 MEDIUM
MonicaHQ v4.1.1 - Authenticated Client-Side Injection via Journal Entry Text Field
CVSS 5.4
CVE-2024-54996 HIGH
MonicaHQ 4.1.2 - Authenticated Client-Side Injection via Reminder Title and Description Parameters
CVSS 8.8
CVE-2024-54724 CRITICAL
PHPYun < 7.0.2 - Remote Code Execution via Arbitrary File Write and Inclusion
CVSS 9.8
CVE-2024-13213 LOW
SingMR HouseRent 1.0 - Cross-Site Scripting via /toAdminUpdateHousePage hID Parameter
CVSS 3.5
CVE-2024-13209 LOW
Redaxo CMS 5.18.1 - Cross-Site Scripting via Article Name Parameter
CVSS 2.4
CVE-2024-13205 LOW
kurniaramadhan E-Commerce-PHP 1.0 - Stored Cross-Site Scripting via Create Product Page Name Parameter
CVSS 2.4
CVE-2024-13202 LOW
wander-chu SpringBoot-Blog 1.0 - XSS
CVSS 2.4
Details
Vulnerabilities 6,506
Exploit Likelihood Medium