CWE-94
Medium likelihoodImproper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
6,507 vulnerabilities with CWE-94
CVE-2024-5082
HIGH
Sonatype Nexus Repository <2.15.1 - RCE
CVE-2024-40671
HIGH
Devmem Server < - Privilege Escalation
CVSS 7.8
CVE-2024-11175
LOW
PublicCMS 5.202406.d - Cross-Site Scripting in Voting Management
CVSS 3.5
CVE-2024-21541
HIGH
dom-iterator < 1.0.1 - Remote Code Execution via Function Constructor
CVSS 7.3
CVE-2024-49048
HIGH
TorchGeo < 0.6.1 - Remote Code Execution
CVSS 8.1
CVE-2024-11130
LOW
ZZCMS < 2023 - Cross-Site Scripting via /admin/msg.php Keyword Parameter
CVSS 2.4
CVE-2024-11102
LOW
Hospital Management System 1.0 - Stored Cross-Site Scripting via Edit Doctor Name Parameter
CVSS 3.5
CVE-2024-50636
CRITICAL
PyMOL 2.5.0 - Remote Code Execution via Malicious .PYM File
CVSS 9.8
CVE-2024-46966
HIGH
Ikhgur mn.ikhgur.khotoch <1.0.42 - XSS
CVSS 8.1
CVE-2024-46964
HIGH
All Video Downloader through 11.28 - Remote Code Execution via StartActivity Component
CVSS 8.1
CVE-2024-46963
HIGH
Super Unlimited Video Downloader <5.1.9 - XSS
CVSS 8.1
CVE-2024-46962
CRITICAL
Master Video Downloader through 2.0 - Remote Code Execution via SpeedMainAct Component
CVSS 9.1
CVE-2024-46965
MEDIUM
Fast Video Downloader: Browser <1.6-RC1 - XSS
CVSS 5.4
CVE-2024-11078
LOW
Job Recruitment 1.0 - Cross-Site Scripting via /register.php e/role Parameter
CVSS 3.5
CVE-2024-11070
LOW
PublicCMS 5.202406.d - Cross-Site Scripting in Tag Type Handler via Name Argument
CVSS 3.5
CVE-2024-10958
HIGH
WP Photo Album Plus <= 8.8.08.007 - Unauthenticated Shortcode Execution via getshortcoderenderedfenodelay
CVSS 7.3
CVE-2024-11050
LOW
Amttgroup Hibos < 3.0.3.151204 - Code Injection
CVSS 3.5
CVE-2024-10640
HIGH
FOX - Currency Switcher Professional <1.4.2.2 - RCE
CVSS 7.3
CVE-2024-10261
HIGH
The Paid Membership Subscriptions - WordPress <2.13.0 - RCE
CVSS 7.3
CVE-2024-50808
HIGH
SeaCms 13.1 - Code Injection via Notify Variable in Admin Notify Module
CVSS 8.8
CVE-2024-46961
HIGH
Inshot com.downloader.privatebrowser through 1.3.5 - Remote Code Execution via PrivateMainActivity
CVSS 8.1
CVE-2024-46960
HIGH
ASD com.rocks.video.downloader <7.0.129 - XSS
CVSS 8.8
CVE-2024-43425
HIGH
Moodle Remote Code Execution (CVE-2024-43425)
CVSS 8.1
CVE-2024-51757
CRITICAL
happy-dom < 15.10.2 - Cross-Site Scripting via Script Tag Execution
CVE-2024-10263
HIGH
Tickera - WordPress Event Ticketing <3.5.4.4 - RCE
CVSS 7.3
Details
Vulnerabilities
6,507
Exploit Likelihood
Medium