CWE-94

Medium likelihood

Improper Control of Generation of Code ('Code Injection')

Parent: CWE-74 - Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection')

The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.

6,507 vulnerabilities with CWE-94
CVE-2024-37860 HIGH
Open Robotic Operating System 2 - Buffer Overflow
CVSS 7.3
CVE-2024-30964 HIGH
Open Robotics ROS2 navigation2-humble - Local Code Execution via nav2_bt_navigator initial_pose_sub Thread
CVSS 7.8
CVE-2024-30963 HIGH
Open Robotics Robotic Operating System 2 - Buffer Overflow
CVSS 7.8
CVE-2024-30962 HIGH
Open Robotics Robotic Operating System 2 navigation2-humble - Local Code Execution via nav2_amcl Buffer Overflow
CVSS 7.8
CVE-2024-30961 HIGH
Open Robotics Robotic Operating System 2 navigation2-humble - Local Code Execution via nav2_bt_navigator Error Handling
CVSS 7.8
CVE-2024-12232 LOW
code-projects Simple CRUD Functionality 1.0 - Cross-Site Scripting via newtitle/newdescr Parameters
CVSS 3.5
CVE-2024-48840 CRITICAL
ABB ASPECT/ENT/NEXUS/MATRIX Firmware < 3.08.03 - Unauthenticated Remote Code Execution
CVSS 10.0
CVE-2024-48839 CRITICAL
ABB ASPECT/Enterprise/NEXUS/MATRIX Firmware < 3.08.03 - Remote Code Execution
CVSS 10.0
CVE-2024-12183 LOW
dedecms < 5.7.116 - Cross-Site Scripting via RemoveXSS Function in /plus/carbuyaction.php
CVSS 3.5
CVE-2024-12182 LOW
dedecms < 5.7.116 - Cross-Site Scripting via /member/soft_add.php body Parameter
CVSS 3.5
CVE-2024-12181 LOW
dedecms < 5.7.116 - Cross-Site Scripting via mediatype Parameter in SWF File Handler
CVSS 3.5
CVE-2024-12180 LOW
dedecms < 5.7.116 - Cross-Site Scripting via article_add.php body Parameter
CVSS 3.5
CVE-2024-48453 CRITICAL
INOVANCE AM401_CPU1608TPTN - Remote Code Execution via ExecuteUserProgramUpgrade Function
CVSS 9.8
CVE-2024-10952 HIGH
The Authors List plugin <2.0.4 - RCE
CVSS 7.3
CVE-2024-12001 LOW
Wazifa System 1.0 - Cross-Site Scripting via Firstname Parameter in Setting Handler
CVSS 3.5
CVE-2024-12000 LOW
code-projects Blood Bank System 1.0 - Cross-Site Scripting via Firstname Parameter in Setting Handler
CVSS 3.5
CVE-2024-11997 LOW
Farmacia 1.0 - Cross-Site Scripting via notaFiscal Parameter
CVSS 3.5
CVE-2024-11996 LOW
Farmacia 1.0 - Cross-Site Scripting via cidade Parameter in /editar-fornecedor.php
CVSS 3.5
CVE-2024-11995 LOW
Farmacia 1.0 - Cross-Site Scripting via Pagamento Total Parameter
CVSS 3.5
CVE-2024-36622 CRITICAL
RaspAP raspap-webgui <3.0.9 - Command Injection
CVSS 9.8
CVE-2024-11971 LOW
Guizhou Xiaoma Technology jpress 5.1.2 - XSS
CVSS 3.5
CVE-2024-11620 HIGH
Rank Math SEO <1.0.231 - Code Injection
CVSS 7.2
CVE-2024-8672 CRITICAL
Widget Options WordPress Plugin <= 4.0.7 - Authenticated Remote Code Execution
CVSS 9.9
CVE-2024-53920 HIGH
GNU Emacs < 30.1 - Remote Code Execution via Unsafe Lisp Macro Expansion
CVSS 7.8
CVE-2024-53604 CRITICAL
PHPGurukul COVID 19 Testing Management System 1.0 - SQL Injection via mobnumber Parameter
CVSS 9.8
Details
Vulnerabilities 6,507
Exploit Likelihood Medium