CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,506 vulnerabilities with CWE-94
CVE-2024-40673
MEDIUM
Android Java ZipFile - Dynamic Code Loading Remote Code Execution
CVSS 6.5
CVE-2024-13499
HIGH
GamiPress - Gamification <7.2.1 - RCE
CVSS 7.3
CVE-2024-13495
HIGH
GamiPress < 7.2.1 - Unauthenticated Arbitrary Shortcode Execution via gamipress_ajax_get_logs
CVSS 7.3
CVE-2024-49747
CRITICAL
Android Bluetooth GATT - Out-of-Bounds Write Remote Code Execution
CVSS 9.8
CVE-2024-43771
HIGH
Android - Remote Code Execution via Missing Bounds Check in gatts_process_read_req
CVSS 8.8
CVE-2024-43770
HIGH
Android - Remote Code Execution via Missing Bounds Check in gatts_process_find_info
CVSS 8.8
CVE-2024-24421
CRITICAL
Magma <= 1.8.0 - Remote Code Execution via NAS Packet Type Confusion
CVSS 9.8
CVE-2024-51941
HIGH
Ambari - Authenticated Code Injection
CVSS 8.8
CVE-2024-42936
CRITICAL
Ruijie RG-EW300N - ReyeeOS 1.300.1422 - RCE
CVSS 9.8
CVE-2024-55504
MEDIUM
RAR Extractor - Unarchiver Free and Pro <6.4.0 - Code Injection
CVSS 5.5
CVE-2024-10970
MEDIUM
Motors - Car Dealer, Classifieds & Listing < 1.4.43 - Authenticated Arbitrary Shortcode Execution via do_shortcode
CVSS 5.4
CVE-2024-27856
HIGH
Apple Safari and OSes - File Processing Arbitrary Code Execution
CVSS 7.8
CVE-2024-42911
HIGH
ECOVACS Robotics Deebot T20 OMNI & T20e OMNI <1.24.0 - RCE
CVSS 7.4
CVE-2024-49375
CRITICAL
Rasa < 3.6.21 and Rasa-Pro < 3.10.12 - Remote Code Execution via Malicious Model Deserialization
CVSS 9.0
CVE-2024-53561
HIGH
Arcadyan Meteor 2 CPE FG360 Firmware ETV2.10 - RCE
CVSS 8.7
CVE-2024-57487
MEDIUM
Car Rental System 1.0 File Upload RCE (Authenticated)
CVSS 6.5
CVE-2024-54999
MEDIUM
MonicaHQ 4.1.2 - Client-Side Injection via Last Name Parameter
CVSS 6.5
CVE-2024-9132
HIGH
Arista ng_firewall < 17.1.1 - Authenticated Code Injection via Captive Portal Script
CVSS 8.1
CVE-2024-54997
MEDIUM
MonicaHQ v4.1.1 - Authenticated Client-Side Injection via Journal Entry Text Field
CVSS 5.4
CVE-2024-54996
HIGH
MonicaHQ 4.1.2 - Authenticated Client-Side Injection via Reminder Title and Description Parameters
CVSS 8.8
CVE-2024-54724
CRITICAL
PHPYun < 7.0.2 - Remote Code Execution via Arbitrary File Write and Inclusion
CVSS 9.8
CVE-2024-13213
LOW
SingMR HouseRent 1.0 - Cross-Site Scripting via /toAdminUpdateHousePage hID Parameter
CVSS 3.5
CVE-2024-13209
LOW
Redaxo CMS 5.18.1 - Cross-Site Scripting via Article Name Parameter
CVSS 2.4
CVE-2024-13205
LOW
kurniaramadhan E-Commerce-PHP 1.0 - Stored Cross-Site Scripting via Create Product Page Name Parameter
CVSS 2.4
CVE-2024-13202
LOW
wander-chu SpringBoot-Blog 1.0 - XSS
CVSS 2.4
Details
Vulnerabilities
6,506
Exploit Likelihood
Medium