CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 41 of 143
- CVE-2015-8771CRITICALCVSS 9.8EG 9.82017-02-13
The generate_smb_nt_hash function in include/functions.inc in GOsa allows remote attackers to execute arbitrary commands via a crafted password.
- CVE-2015-9227HIGHCVSS 7.2EG 7.22017-09-11
PHP remote file inclusion vulnerability in the get_file function in upload/admin2/controller/report_logs.php in AlegroCart 1.2.8 allows remote administrators to execute arbitrary PHP code via a URL in the file_path parameter to upload/admi…
- CVE-2015-9272CRITICALCVSS 9.8EG 9.82018-10-05
The videowhisper-video-presentation plugin 3.31.17 for WordPress allows remote attackers to execute arbitrary code because vp/vw_upload.php considers a file safe when "html" are the last four characters, as demonstrated by a .phtml file co…
- CVE-2015-9298CRITICALCVSS 9.8EG 9.82019-08-13
The events-manager plugin before 5.6 for WordPress has code injection.
- CVE-2016-0033HIGHCVSS 7.5EG 7.52016-02-10
Microsoft .NET Framework 2.0 SP2, 3.5, 3.5.1, 4.5.2, 4.6, and 4.6.1 does not prevent recursive compilation of XSLT transforms, which allows remote attackers to cause a denial of service (performance degradation) via crafted XSLT data, aka …
- CVE-2016-1000003CRITICALCVSS 9.8EG 9.82016-10-07
Mirror Manager version 0.7.2 and older is vulnerable to remote code execution in the checkin code.
- CVE-2016-10072HIGHCVSS 5.3EG 7.52016-12-27
WampServer 3.0.6 has two files called 'wampmanager.exe' and 'unins000.exe' with a weak ACL for Modify. This could potentially allow an authorized but non-privileged local user to execute arbitrary code with elevated privileges on the syste…
- CVE-2016-10157CRITICALCVSS 9.8EG 9.82017-01-23
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hij…
- CVE-2016-10541CRITICALCVSS 9.8EG 9.82018-05-31
The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform code injection.
- CVE-2016-10546CRITICALCVSS 9.8EG 9.82018-05-31
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandboxed and may be used…
- CVE-2016-10548MEDIUMCVSS 6.1EG 6.12018-05-31
Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user input is passed to …
- CVE-2016-11064CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Desktop App before 3.4.0. Strings could be executed as code via injection.
- CVE-2016-1413MEDIUMCVSS 6.5EG 6.52016-05-28
The web interface in Cisco Firepower Management Center 5.4.0 through 6.0.0.1 allows remote authenticated users to modify pages by placing crafted code in a parameter value, aka Bug ID CSCuy76517.
- CVE-2016-15044CRITICALCVSS 9.3EG 9.32025-07-23
A remote code execution vulnerability exists in Kaltura versions prior to 11.1.0-2 due to unsafe deserialization of user-controlled data within the keditorservices module. An unauthenticated remote attacker can exploit this issue by sendin…
- CVE-2016-1602HIGHCVSS 7.8EG 7.82017-03-23
A code injection in the supportconfig data collection tool in supportutils in SUSE Linux Enterprise Server 12 and 12-SP1 and SUSE Linux Enterprise Desktop 12 and 12-SP1 could be used by local attackers to execute code as the user running s…
- CVE-2016-1985CRITICALCVSS 10.0EG 10.02016-01-30
HPE Operations Manager 8.x and 9.0 on Windows allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
- CVE-2016-1986CRITICALCVSS 9.8EG 9.82016-02-12
HP Continuous Delivery Automation (CDA) 1.30 allows remote attackers to execute arbitrary commands via a crafted serialized Java object, related to the Apache Commons Collections library.
- CVE-2016-2119HIGHCVSS 7.5EG 7.52016-07-07
libcli/smb/smbXcli_base.c in Samba 4.x before 4.2.14, 4.3.x before 4.3.11, and 4.4.x before 4.4.5 allows man-in-the-middle attackers to bypass a client-signing protection mechanism, and consequently spoof SMB2 and SMB3 servers, via the (1)…
- CVE-2016-2242CRITICALCVSS 9.8EG 9.82017-01-23
Exponent CMS 2.x before 2.3.7 Patch 3 allows remote attackers to execute arbitrary code via the sc parameter to install/index.php.
- CVE-2016-3153CRITICALCVSS 9.8EG 9.82016-04-08
SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to execute arbitrary PHP code by adding content, related to the filtrer_entites function.
- CVE-2016-3154CRITICALCVSS 9.8EG 9.82016-04-08
The encoder_contexte_ajax function in ecrire/inc/filtres.php in SPIP 2.x before 2.1.19, 3.0.x before 3.0.22, and 3.1.x before 3.1.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via a crafte…
- CVE-2016-4391CRITICALCVSS 9.8EG 9.82018-08-06
A remote code execution security vulnerability has been identified in all versions of the HP ArcSight WINC Connector prior to v7.3.0.
- CVE-2016-4397HIGHCVSS 7.8EG 7.82018-08-06
A local code execution security vulnerability was identified in HP Network Node Manager i (NNMi) v10.00, v10.10 and v10.20 Software.
- CVE-2016-4895HIGHCVSS 8.8EG 8.82017-04-12
SetsucoCMS all versions allows remote authenticated attackers to conduct code injection attacks via unspecified vectors.
- CVE-2016-5072HIGHCVSS 8.8EG 8.82017-04-10
OXID eShop before 2016-06-13 allows remote attackers to execute arbitrary code via a GET or POST request to the oxuser class. Fixed versions are Enterprise Edition v5.1.12, Enterprise Edition v5.2.9, Professional Edition v4.8.12, Professio…
- CVE-2016-5149HIGHCVSS 8.8EG 8.82016-09-11
The extensions subsystem in Google Chrome before 53.0.2785.89 on Windows and OS X and before 53.0.2785.92 on Linux relies on an IFRAME source URL to identify an associated extension, which allows remote attackers to conduct extension-bindi…
- CVE-2016-5402HIGHCVSS 8.8EG 8.82018-10-31
A code injection flaw was found in the way capacity and utilization imported control files are processed. A remote, authenticated attacker with access to the capacity and utilization feature could use this flaw to execute arbitrary code as…
- CVE-2016-5424HIGHCVSS 7.1EG 7.12016-12-09
PostgreSQL before 9.1.23, 9.2.x before 9.2.18, 9.3.x before 9.3.14, 9.4.x before 9.4.9, and 9.5.x before 9.5.4 might allow remote authenticated users with the CREATEDB or CREATEROLE role to gain superuser privileges via a (1) " (double quo…
- CVE-2016-5713CRITICALCVSS 9.8EG 9.82017-12-06
Versions of Puppet Agent prior to 1.6.0 included a version of the Puppet Execution Protocol (PXP) agent that passed environment variables through to Puppet runs. This could allow unauthorized code to be loaded. This bug was first introduce…
- CVE-2016-5726CRITICALCVSS 9.8EG 9.82017-02-09
Packages.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via the themechanges array parameter.
- CVE-2016-5727HIGHCVSS 8.8EG 8.82017-02-09
LogInOut.php in Simple Machines Forum (SMF) 2.1 allows remote attackers to conduct PHP object injection attacks and execute arbitrary PHP code via vectors related to variables derived from user input in a foreach loop.
- CVE-2016-5734CRITICALCVSS 9.8EG 9.82016-07-03
phpMyAdmin 4.0.x before 4.0.10.16, 4.4.x before 4.4.15.7, and 4.6.x before 4.6.3 does not properly choose delimiters to prevent use of the preg_replace e (aka eval) modifier, which might allow remote attackers to execute arbitrary PHP code…
- CVE-2016-6175CRITICALCVSS 9.8EG 9.82017-02-07
Eval injection vulnerability in php-gettext 1.0.12 and earlier allows remote attackers to execute arbitrary PHP code via a crafted plural forms header.
- CVE-2016-7102HIGHCVSS 8.4EG 8.42017-01-23
ownCloud Desktop before 2.2.3 allows local users to execute arbitrary code and possibly gain privileges via a Trojan library in a "special path" in the C: drive.
- CVE-2016-7109CRITICALCVSS 9.8EG 9.82016-09-07
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7110.
- CVE-2016-7110CRITICALCVSS 9.8EG 9.82016-09-07
Huawei Unified Maintenance Audit (UMA) before V200R001C00SPC200 allows remote attackers to execute arbitrary commands via "special characters," a different vulnerability than CVE-2016-7109.
- CVE-2016-7787MEDIUMCVSS 4.9EG 4.92016-12-23
A maliciously crafted command line for kdesu can result in the user only seeing part of the commands that will actually get executed as super user.
- CVE-2016-7954CRITICALCVSS 9.8EG 9.82016-12-22
Bundler 1.x might allow remote attackers to inject arbitrary Ruby code into an application by leveraging a gem name collision on a secondary source. NOTE: this might overlap CVE-2013-0334.
- CVE-2016-7966HIGHCVSS 7.3EG 7.32016-12-23
Through a malicious URL that contained a quote character it was possible to inject HTML code in KMail's plaintext viewer. Due to the parser used on the URL it was not possible to include the equal sign (=) or a space into the injected HTML…
- CVE-2016-7967HIGHCVSS 8.1EG 8.12016-12-23
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. Since the generated html is executed in the local file security context by default access to remote and local URLs was enabled.
- CVE-2016-7968MEDIUMCVSS 6.5EG 6.52016-12-23
KMail since version 5.3.0 used a QWebEngine based viewer that had JavaScript enabled. HTML Mail contents were not sanitized for JavaScript and included code was executed.
- CVE-2016-8020HIGHCVSS 8.0EG 8.02017-03-14
Improper control of generation of code vulnerability in Intel Security VirusScan Enterprise Linux (VSEL) 2.0.3 (and earlier) allows remote authenticated users to execute arbitrary code via a crafted HTTP request parameter.
- CVE-2016-8354HIGHCVSS 7.0EG 7.02017-02-13
An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directl…
- CVE-2016-9651HIGHCVSS 8.8EG 8.82019-01-09
A missing check for whether a property of a JS object is private in V8 in Google Chrome prior to 55.0.2883.75 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page.
- CVE-2016-9862HIGHCVSS 7.5EG 7.52016-12-11
An issue was discovered in phpMyAdmin. With a crafted login request it is possible to inject BBCode in the login page. All 4.6.x versions (prior to 4.6.5) are affected.
- CVE-2016-9949HIGHCVSS 7.8EG 7.82016-12-17
An issue was discovered in Apport before 2.20.4. In apport/ui.py, Apport reads the CrashDB field and it then evaluates the field as Python code if it begins with a "{". This allows remote attackers to execute arbitrary Python code.
- CVE-2017-0899CRITICALCVSS 9.8EG 9.82017-08-31
RubyGems version 2.6.12 and earlier is vulnerable to maliciously crafted gem specifications that include terminal escape characters. Printing the gem specification would execute terminal escape sequences.
- CVE-2017-1000196CRITICALCVSS 9.8EG 9.82017-11-17
October CMS build 412 is vulnerable to PHP code execution in the asset manager functionality resulting in site compromise and possibly other applications on the server.
- CVE-2017-1000480CRITICALCVSS 9.8EG 9.82018-01-03
Smarty 3 before 3.1.32 is vulnerable to a PHP code injection when calling fetch() or display() functions on custom resources that does not sanitize template name.
- CVE-2017-1001002CRITICALCVSS 9.8EG 9.82017-11-27
math.js before 3.17.0 had an arbitrary code execution in the JavaScript engine. Creating a typed function with JavaScript code in the name could result arbitrary execution.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →