CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 40 of 143
- CVE-2014-8661HIGHCVSS v2 10.0EG 10.02014-11-06
The SAP CRM Internet Sales module allows remote attackers to execute arbitrary commands via unspecified vectors.
- CVE-2014-8669HIGHCVSS v2 10.0EG 10.02014-11-06
The SAP Promotion Guidelines (CRM-MKT-MPL-TPM-PPG) module for SAP CRM allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2014-8677MEDIUMCVSS 5.3EG 5.32017-08-31
The installation process for SOPlanning 1.32 and earlier allows remote authenticated users with a prepared database, and access to an existing database with a crafted name, or permissions to create arbitrary databases, or if PHP before 5.2…
- CVE-2014-8770HIGHCVSS v2 9.0EG 9.02014-11-13
Unrestricted file upload vulnerability in magmi/web/magmi.php in the MAGMI (aka Magento Mass Importer) plugin 0.7.17a and earlier for Magento Community Edition (CE) allows remote authenticated users to execute arbitrary code by uploading a…
- CVE-2014-8791MEDIUMCVSS v2 6.0EG 6.02014-12-02
project/register.php in Tuleap before 7.7, when sys_create_project_in_one_step is disabled, allows remote authenticated users to conduct PHP object injection attacks and execute arbitrary PHP code via the data parameter.
- CVE-2014-8872HIGHCVSS 7.8EG 7.82017-08-29
Improper Verification of Cryptographic Signature in AVM FRITZ!Box 6810 LTE after firmware 5.22, FRITZ!Box 6840 LTE after firmware 5.23, and other models with firmware 5.50.
- CVE-2014-8877HIGHCVSS v2 10.0EG 10.02014-12-05
The alterSearchQuery function in lib/controllers/CmdownloadController.php in the CreativeMinds CM Downloads Manager plugin before 2.0.4 for WordPress allows remote attackers to execute arbitrary PHP code via the CMDsearch parameter to cmdo…
- CVE-2014-8949MEDIUMCVSS v2 6.0EG 6.02014-11-16
The iMember360 plugin 3.8.012 through 3.9.001 for WordPress allows remote authenticated administrators to execute arbitrary commands via shell metacharacters in the i4w_trace parameter. NOTE: this can be leveraged with CVE-2014-8948 to al…
- CVE-2014-8997HIGHCVSS v2 7.5EG 7.52014-11-20
Unrestricted file upload vulnerability in the Photo functionality in DigitalVidhya Digi Online Examination System 2.0 allows remote attackers to execute arbitrary code by uploading a file with an executable extension, then accessing it via…
- CVE-2014-8998MEDIUMCVSS v2 6.5EG 6.52014-11-20
lib/message.php in X7 Chat 2.0.0 through 2.0.5.1 allows remote authenticated users to execute arbitrary PHP code via a crafted HTTP header to index.php, which is processed by the preg_replace function with the eval switch.
- CVE-2014-9001MEDIUMCVSS v2 6.5EG 6.52014-11-20
reminders/index.php in Incredible PBX 11 2.0.6.5.0 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the (1) APPTMIN, (2) APPTHR, (3) APPTDA, (4) APPTMO, (5) APPTYR, or (6) APPTPHONE parameters.
- CVE-2014-9158HIGHCVSS v2 10.0EG 10.02014-12-10
Adobe Reader and Acrobat 10.x before 10.1.13 and 11.x before 11.0.10 on Windows and OS X allow attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified vectors, a different vulnerability than CVE…
- CVE-2014-9164HIGHCVSS v2 10.0EG 10.02014-12-10
Adobe Flash Player before 13.0.0.259 and 14.x through 16.x before 16.0.0.235 on Windows and OS X and before 11.2.202.425 on Linux allows attackers to execute arbitrary code or cause a denial of service (memory corruption) via unspecified v…
- CVE-2014-9185MEDIUMCVSS v2 6.5EG 6.52014-12-19
Static code injection vulnerability in install.php in Morfy CMS 1.05 allows remote authenticated users to inject arbitrary PHP code into config.php via the site_url parameter.
- CVE-2014-9266MEDIUMCVSS v2 6.8EG 6.82014-12-08
The STWConfig ActiveX control in Samsung SmartViewer does not properly initialize a variable, which allows remote attackers to execute arbitrary code via unspecified vectors.
- CVE-2014-9280HIGHCVSS v2 7.5EG 7.52014-12-08
The current_user_get_bug_filter function in core/current_user_api.php in MantisBT before 1.2.18 allows remote attackers to execute arbitrary PHP code via the filter parameter.
- CVE-2014-9463HIGHCVSS 8.8EG 8.82017-09-15
functions_vbseo_hook.php in the VBSEO module for vBulletin allows remote authenticated users to execute arbitrary code via the HTTP Referer header to visitormessage.php.
- CVE-2014-9521HIGHCVSS v2 7.5EG 7.52015-01-05
Unrestricted file upload vulnerability in uploadScript.php in InfiniteWP Admin Panel before 2.4.4, when the allWPFiles query parameter is set, allows remote attackers to execute arbitrary code by uploading a file with a double extension, t…
- CVE-2014-9567HIGHCVSS v2 7.5EG 7.52015-01-07
Unrestricted file upload vulnerability in process-upload.php in ProjectSend (formerly cFTP) r100 through r561 allows remote attackers to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct re…
- CVE-2015-0088HIGHCVSS v2 9.3EG 9.32015-03-11
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to e…
- CVE-2015-0090HIGHCVSS v2 9.3EG 9.32015-03-11
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to e…
- CVE-2015-0091HIGHCVSS v2 9.3EG 9.32015-03-11
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to e…
- CVE-2015-0092HIGHCVSS v2 9.3EG 9.32015-03-11
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to e…
- CVE-2015-0093HIGHCVSS v2 9.3EG 9.32015-03-11
Adobe Font Driver in Microsoft Windows Server 2003 SP2, Windows Vista SP2, Windows Server 2008 SP2 and R2 SP1, Windows 7 SP1, Windows 8, Windows 8.1, Windows Server 2012 Gold and R2, and Windows RT Gold and 8.1 allows remote attackers to e…
- CVE-2015-0249HIGHCVSS 7.2EG 7.22017-07-17
The weblog page template in Apache Roller 5.1 through 5.1.1 allows remote authenticated users with admin privileges for a weblog to execute arbitrary Java code via crafted Velocity Text Language (aka VTL).
- CVE-2015-0279MEDIUMCVSS v2 6.8EG 6.82015-03-26
JBoss RichFaces before 4.5.4 allows remote attackers to inject expression language (EL) expressions and execute arbitrary Java code via the do parameter.
- CVE-2015-0855CRITICALCVSS 9.8EG 9.82017-03-23
The _mediaLibraryPlayCb function in mainwindow.py in pitivi before 0.95 allows attackers to execute arbitrary code via shell metacharacters in a file path.
- CVE-2015-0898HIGHCVSS v2 7.5EG 7.52015-03-21
futomi CGI Cafe MP Form Mail CGI eCommerce before 2.0.12 on Windows allows remote attackers to execute arbitrary Perl code via unspecified vectors.
- CVE-2015-0925HIGHCVSS v2 9.0EG 9.02015-01-22
The client in iPass Open Mobile before 2.4.5 on Windows allows remote authenticated users to execute arbitrary code via a DLL pathname in a crafted Unicode string that is improperly handled by a subprocess reached through a named pipe, as …
- CVE-2015-10009MEDIUMCVSS 5.5EG 5.52023-01-02
A vulnerability was found in nterchange up to 4.1.0. It has been rated as critical. This issue affects the function getContent of the file app/controllers/code_caller_controller.php. The manipulation of the argument q with the input %5C%27…
- CVE-2015-1059MEDIUMCVSS v2 6.5EG 6.52015-01-16
Unrestricted file upload vulnerability in admin/files/add in AdaptCMS 3.0.3 allows remote authenticated users to execute arbitrary PHP code by uploading a file with a PHP extension, then accessing it via a direct request to the file in /ap…
- CVE-2015-1061HIGHCVSS v2 9.3EG 9.32015-03-12
IOSurface in Apple iOS before 8.2, Apple OS X through 10.10.2, and Apple TV before 7.1 allows attackers to execute arbitrary code in a privileged context via a crafted app that leverages "type confusion" during serialized-object handling.
- CVE-2015-1311HIGHCVSS v2 10.0EG 10.02015-01-22
The Extended Application Services (XS) in SAP HANA allows remote attackers to inject arbitrary ABAP code via unspecified vectors, aka SAP Note 2098906. NOTE: the provenance of this information is unknown; the details are obtained solely f…
- CVE-2015-1497HIGHCVSS v2 10.0EG 10.02015-02-16
radexecd.exe in Persistent Systems Radia Client Automation (RCA) 7.9, 8.1, 9.0, and 9.1 allows remote attackers to execute arbitrary commands via a crafted request to TCP port 3465.
- CVE-2015-1501MEDIUMCVSS v2 6.8EG 6.82015-02-16
The factory.loadExtensionFactory function in TSUnicodeGraphEditorControl in SolarWinds Server and Application Monitor (SAM) allow remote attackers to execute arbitrary code via a UNC path to a crafted binary.
- CVE-2015-1597MEDIUMCVSS v2 6.8EG 6.82015-03-07
The Siemens SPCanywhere application for Android does not use encryption during the loading of code, which allows man-in-the-middle attackers to execute arbitrary code by modifying the client-server data stream.
- CVE-2015-1635CRITICALCVSS 9.8EG 9.8⚠ KEV2015-04-14
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote attackers to execute arbitrary code via crafted HTTP requests, aka "HTTP.sys Remote Code Execution V…
- CVE-2015-2079CRITICALCVSS 9.9EG 9.92025-04-28
Usermin 0.980 through 1.x before 1.660 allows uconfig_save.cgi sig_file_free remote code execution because it uses the two argument (not three argument) form of Perl open.
- CVE-2015-2252HIGHCVSS 8.8EG 8.82017-06-08
Huawei OceanStor UDS devices with software before V100R002C01SPC102 might allow remote attackers to execute arbitrary code with root privileges via a crafted UDS patch with shell scripts.
- CVE-2015-3173HIGHCVSS 7.2EG 7.22022-07-06
custom-content-type-manager Wordpress plugin can be used by an administrator to achieve arbitrary PHP remote code execution.
- CVE-2015-3638HIGHCVSS 8.8EG 8.82017-07-21
phpMyBackupPro before 2.5 does not validate integer input, which allows remote authenticated users to execute arbitrary PHP code by injecting scripts via the path, filename, and period parameters to scheduled.php, and making requests to in…
- CVE-2015-3640HIGHCVSS 7.5EG 7.52017-07-21
phpMyBackupPro 2.5 and earlier does not properly escape the "." character in request parameters, which allows remote authenticated users with knowledge of a web-accessible and web-writeable directory on the target system to inject and exec…
- CVE-2015-5243CRITICALCVSS 9.8EG 9.82018-08-20
phpWhois allows remote attackers to execute arbitrary code via a crafted whois record.
- CVE-2015-5721CRITICALCVSS 9.8EG 9.82016-09-03
Malware Information Sharing Platform (MISP) before 2.3.90 allows remote attackers to conduct PHP object injection attacks via crafted serialized data, related to TemplatesController.php and populate_event_from_template_attributes.ctp.
- CVE-2015-5970MEDIUMCVSS 5.3EG 5.32016-02-18
The ChangePassword RPC method in Novell ZENworks Configuration Management (ZCM) 11.3 and 11.4 allows remote attackers to conduct XPath injection attacks, and read arbitrary text files, via a malformed query involving a system entity refere…
- CVE-2015-6531HIGHCVSS 7.8EG 7.82017-06-01
Palo Alto Networks Panorama VM Appliance with PAN-OS before 6.0.1 might allow remote attackers to execute arbitrary Python code via a crafted firmware image file.
- CVE-2015-6576HIGHCVSS 8.8EG 8.82017-10-03
Bamboo 2.2 before 5.8.5 and 5.9.x before 5.9.7 allows remote attackers with access to the Bamboo web interface to execute arbitrary Java code via an unspecified resource.
- CVE-2015-7450CRITICALCVSS 9.8EG 9.8⚠ KEV2016-01-02
Serialized-object interfaces in certain IBM analytics, business solutions, cognitive, IT infrastructure, and mobile and social products allow remote attackers to execute arbitrary commands via a crafted serialized Java object, related to t…
- CVE-2015-8351CRITICALCVSS 9.0EG 9.02017-09-11
PHP remote file inclusion vulnerability in the Gwolle Guestbook plugin before 1.5.4 for WordPress, when allow_url_include is enabled, allows remote authenticated users to execute arbitrary PHP code via a URL in the abspath parameter to fro…
- CVE-2015-8761CRITICALCVSS 9.0EG 9.02016-01-08
The Values module 7.x-1.x before 7.x-1.2 for Drupal does not properly check permissions, which allows remote administrators with the "Import value sets" permission to execute arbitrary PHP code via the exported values list in a ctools impo…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →