CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-12841
MEDIUM
emlog < 2.4.1 - Cross-Site Scripting via /admin/tag.php Keyword Parameter
CVSS 4.3
CVE-2024-56327
CRITICAL
pyrage 1.2.0-1.2.2 - Remote Code Execution via Malicious Plugin
CVSS 9.8
CVE-2024-12729
HIGH
Sophos Firewall < 21.0.1 - Authenticated Remote Code Execution via User Portal
CVSS 8.8
CVE-2024-12790
LOW
Hostel Management Site 1.0 - Cross-Site Scripting in room-details.php
CVSS 3.5
CVE-2024-12789
MEDIUM
PbootCMS < 3.2.4 - Remote Code Execution via Tag Parameter in IndexController
CVSS 6.3
CVE-2024-9154
HIGH
HMS Networks Ewon Flexy 205 <14.8s0 - Code Injection
CVE-2024-12783
LOW
Vehicle Management System 1.0 - Cross-Site Scripting via billaction.php Extra-Cost Parameter
CVSS 3.5
CVE-2024-11740
HIGH
WordPress Download Manager <= 3.3.03 - Unauthenticated Shortcode Execution
CVSS 7.3
CVE-2024-55505
HIGH
CodeAstro Complaint Management System 1.0 - Privilege Escalation via mess-view.php
CVSS 8.8
CVE-2024-56145
CRITICAL
KEV
Craft CMS Twig Template Injection RCE via FTP Templates Path
CVSS 9.8
CVE-2024-36694
HIGH
OpenCart 4.0.2.3 - Server-Side Template Injection via Theme Editor Function
CVSS 7.2
CVE-2024-56051
HIGH
VibeThemes WPLMS < 1.9.9.5 - Remote Code Execution
CVSS 8.5
CVE-2024-12372
CRITICAL
Rockwell Automation Power Monitor 1000 - RCE/DoS
CVE-2024-21546
CRITICAL
unisharp/laravel-filemanager < 2.9.1 - Remote Code Execution via Mimetype and File Extension Manipulation
CVSS 9.8
CVE-2024-55085
CRITICAL
GetSimple CMS CE 3.3.19 - Remote Code Execution via Template Editing Function
CVSS 9.8
CVE-2024-37773
MEDIUM
Sunbird DCIM dcTrack 9.1.2 - Authenticated HTML Injection in Admin Screen
CVSS 4.8
CVE-2024-12665
LOW
ruifang-tech Rebuild 3.8.5 - Stored Cross-Site Scripting in Task Comment Attachment Upload
CVSS 3.5
CVE-2024-12664
LOW
ruifang-tech Rebuild 3.8.5 - Stored Cross-Site Scripting in Project Task Comment Handler
CVSS 3.5
CVE-2024-56072
HIGH
FastNetMon Community Edition < 1.2.7 - Denial of Service via sFlow v5 Plugin
CVSS 7.5
CVE-2024-55661
HIGH
Laravel Pulse < 1.3.1 - Authenticated Remote Code Execution via Livewire remember() Method
CVSS 8.8
CVE-2024-21577
CRITICAL
ComfyUI-Ace-Nodes - Remote Code Execution via ACE_ExpressionEval Node
CVSS 10.0
CVE-2024-21576
CRITICAL
ComfyUI-Bmad-Nodes - Code Injection
CVSS 10.0
CVE-2024-11012
MEDIUM
The Notibar - Notification Bar for WordPress plugin <2.1.4 - RCE
CVSS 6.3
CVE-2024-12421
MEDIUM
The Coupon Affiliates - Affiliate Plugin for WooCommerce <5.16.7.1 ...
CVSS 6.5
CVE-2024-12420
MEDIUM
WordPress WPMobile.App <= 11.52 - Unauthenticated Shortcode Execution
CVSS 6.5
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium