CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 48 of 143
- CVE-2019-13956CRITICALCVSS 9.8EG 9.82019-07-18
Discuz!ML 3.2 through 3.4 allows remote attackers to execute arbitrary PHP code via a modified language cookie, as demonstrated by changing 4gH4_0df5_language=en to 4gH4_0df5_language=en'.phpinfo().'; (if the random prefix 4gH4_0df5_ were …
- CVE-2019-14242MEDIUMCVSS 6.7EG 6.72019-07-30
An issue was discovered in Bitdefender products for Windows (Bitdefender Endpoint Security Tool versions prior to 6.6.8.115; and Bitdefender Antivirus Plus, Bitdefender Internet Security, and Bitdefender Total Security versions prior to 23…
- CVE-2019-14281CRITICALCVSS 9.8EG 9.82019-07-26
The datagrid gem 1.0.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
- CVE-2019-14282CRITICALCVSS 9.8EG 9.82019-07-26
The simple_captcha2 gem 0.2.3 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party.
- CVE-2019-14423HIGHCVSS 8.8EG 8.82019-10-17
A Remote Code Execution (RCE) issue in the addon CUx-Daemon 1.11a of the eQ-3 Homematic CCU-Firmware 2.35.16 until 2.45.6 allows remote authenticated attackers to execute system commands as root remotely via a simple HTTP request.
- CVE-2019-14746CRITICALCVSS 9.8EG 9.82019-08-07
A issue was discovered in KuaiFanCMS 5.0. It allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
- CVE-2019-14786MEDIUMCVSS 6.5EG 6.52019-08-15
The Rank Math SEO plugin 1.0.27 for WordPress allows non-admin users to reset the settings via the wp-admin/admin-post.php reset-cmb parameter.
- CVE-2019-14827MEDIUMCVSS 6.1EG 6.12021-05-17
A vulnerability was found in Moodle where javaScript injection was possible in some Mustache templates via recursive rendering from contexts. Mustache helper tags that were included in template contexts were not being escaped before that c…
- CVE-2019-14867HIGHCVSS 8.8EG 8.82019-11-27
A flaw was found in IPA, all 4.6.x versions before 4.6.7, all 4.7.x versions before 4.7.4 and all 4.8.x versions before 4.8.3, in the way the internal function ber_scanf() was used in some components of the IPA server, which parsed kerbero…
- CVE-2019-14965CRITICALCVSS 9.8EG 9.82019-08-12
An issue was discovered in Frappe Framework 10 through 12 before 12.0.4. A server side template injection (SSTI) issue exists.
- CVE-2019-15001HIGHCVSS 7.2EG 7.22019-09-19
The Jira Importers Plugin in Atlassian Jira Server and Data Cente from version with 7.0.10 before 7.6.16, from 7.7.0 before 7.13.8, from 8.0.0 before 8.1.3, from 8.2.0 before 8.2.5, from 8.3.0 before 8.3.4 and from 8.4.0 before 8.4.1 allow…
- CVE-2019-15087HIGHCVSS 7.2EG 7.22019-09-20
An issue was discovered in PRiSE adAS 1.7.0. An authenticated user can change the function used to hash passwords to any function, leading to remote code execution.
- CVE-2019-15224CRITICALCVSS 9.8EG 9.82019-08-19
The rest-client gem 1.6.10 through 1.6.13 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions <=1.6.9 and >=1.6.14 are unaffected.
- CVE-2019-15318CRITICALCVSS 9.8EG 9.82019-08-22
The yikes-inc-easy-mailchimp-extender plugin before 6.5.3 for WordPress has code injection via the admin input field.
- CVE-2019-15388HIGHCVSS 8.1EG 8.12019-11-14
The Coolpad 1851 Android device with a build fingerprint of Coolpad/android/android:8.1.0/O11019/1534834761:userdebug/release-keys contains a pre-installed platform app with a package name of com.lovelyfont.defcontainer (versionCode=7, ver…
- CVE-2019-15490CRITICALCVSS 9.8EG 9.82019-08-23
openITCOCKPIT before 3.7.1 allows code injection, aka RVID 1-445b21.
- CVE-2019-15597CRITICALCVSS 9.8EG 9.82019-12-18
A code injection exists in node-df v0.1.4 that can allow an attacker to remote code execution by unsanitized input.
- CVE-2019-15598CRITICALCVSS 9.8EG 9.82019-12-18
A Code Injection exists in treekill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
- CVE-2019-15599CRITICALCVSS 9.8EG 9.82019-12-18
A Code Injection exists in tree-kill on Windows which allows a remote code execution when an attacker is able to control the input into the command.
- CVE-2019-15642HIGHCVSS 8.8EG 8.82019-08-26
rpc.cgi in Webmin through 1.920 allows authenticated Remote Code Execution via a crafted object name because unserialise_variable makes an eval call. NOTE: the Webmin_Servers_Index documentation states "RPC can be used to run any command o…
- CVE-2019-15647HIGHCVSS 8.8EG 8.82019-08-27
The groundhogg plugin before 1.3.5 for WordPress has wp-admin/admin-ajax.php?action=bulk_action_listener remote code execution.
- CVE-2019-15746CRITICALCVSS 9.8EG 9.82019-10-07
SITOS six Build v6.2.1 allows an attacker to inject arbitrary PHP commands. As a result, an attacker can compromise the running server and execute system commands in the context of the web user.
- CVE-2019-15766HIGHCVSS 8.8EG 8.82019-10-03
The KSLABS KSWEB (aka ru.kslabs.ksweb) application 3.93 for Android allows authenticated remote code execution via a POST request to the AJAX handler with the configFile parameter set to the arbitrary file to be written to (and the config_…
- CVE-2019-1577MEDIUMCVSS 6.3EG 6.32019-07-01
Code injection vulnerability in Palo Alto Networks Traps 5.0.5 and earlier may allow an authenticated attacker to inject arbitrary JavaScript or HTML.
- CVE-2019-15813HIGHCVSS 8.8EG 8.82019-09-04
Multiple file upload restriction bypass vulnerabilities in Sentrifugo 3.2 could allow authenticated users to execute arbitrary code via a webshell.
- CVE-2019-15873HIGHCVSS 8.8EG 8.82019-09-03
The profilegrid-user-profiles-groups-and-communities plugin before 2.8.6 for WordPress has remote code execution via an wp-admin/admin-ajax.php request with the action=pm_template_preview&html=<?php substring followed by PHP code.
- CVE-2019-16108HIGHCVSS 7.5EG 7.52020-03-20
phpBB 3.2.7 allows adding an arbitrary Cascading Style Sheets (CSS) token sequence to a page through BBCode.
- CVE-2019-16113CRITICALCVSS 8.8EG 9.02019-09-08
Bludit 3.9.2 allows remote code execution via bl-kernel/ajax/upload-images.php because PHP code can be entered with a .jpg file name, and then this PHP code can write other PHP code to a ../ pathname.
- CVE-2019-16255HIGHCVSS 8.1EG 8.12019-11-26
Ruby through 2.4.7, 2.5.x through 2.5.6, and 2.6.x through 2.6.4 allows code injection if the first argument (aka the "command" argument) to Shell#[] or Shell#test in lib/shell.rb is untrusted data. An attacker can exploit this to call an …
- CVE-2019-16283HIGHCVSS 7.8EG 7.82023-06-09
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.
- CVE-2019-16645HIGHCVSS 8.6EG 8.62019-09-20
An issue was discovered in Embedthis GoAhead 2.5.0. Certain pages (such as goform/login and config/log_off_page.htm) create links containing a hostname obtained from an arbitrary HTTP Host header sent by an attacker. This could potentially…
- CVE-2019-16652HIGHCVSS 7.2EG 7.22020-04-29
The BPM component in Genius Bytes Genius Server (Genius CDDS) 3.2.2 allows remote authenticated users to execute arbitrary commands.
- CVE-2019-16759CRITICALCVSS 9.8EG 9.8⚠ KEV2019-09-24
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring request.
- CVE-2019-16774MEDIUMCVSS 4.4EG 4.42019-12-12
In phpfastcache before 5.1.3, there is a possible object injection vulnerability in cookie driver.
- CVE-2019-16885CRITICALCVSS 9.8EG 9.82019-12-03
In OkayCMS through 2.3.4, an unauthenticated attacker can achieve remote code execution by injecting a malicious PHP object via a crafted cookie. This could happen at two places: first in view/ProductsView.php using the cookie price_filter…
- CVE-2019-17107HIGHCVSS 8.8EG 8.82019-10-08
minPlayCommand.php in Centreon Web before 2.8.27 allows authenticated attackers to execute arbitrary code via the command_hostaddress parameter. NOTE: some sources have listed CVE-2019-17017 for this, but that is incorrect.
- CVE-2019-17132CRITICALCVSS 9.8EG 9.82019-10-04
vBulletin through 5.5.4 mishandles custom avatars.
- CVE-2019-17268CRITICALCVSS 9.8EG 9.82020-02-07
The omniauth-weibo-oauth2 gem 0.4.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. Versions through 0.4.5, and 0.5.1 and later, are unaffected.
- CVE-2019-17299HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by an Admin user.
- CVE-2019-17300HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Administration module by a Developer user.
- CVE-2019-17301HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by an Admin user.
- CVE-2019-17302HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the ModuleBuilder module by a Developer user.
- CVE-2019-17303HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Developer user.
- CVE-2019-17304HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by an Admin user.
- CVE-2019-17305HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the MergeRecords module by a Regular user.
- CVE-2019-17306HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Configurator module by an Admin user.
- CVE-2019-17307HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Tracker module by an Admin user.
- CVE-2019-17308HIGHCVSS 8.8EG 8.82019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Emails module by a Regular user.
- CVE-2019-17309HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the EmailMan module by an Admin user.
- CVE-2019-17310HIGHCVSS 7.2EG 7.22019-10-07
SugarCRM before 8.0.4 and 9.x before 9.0.2 allows PHP code injection in the Campaigns module by an Admin user.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →