CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 49 of 143
- CVE-2019-17408CRITICALCVSS 9.8EG 9.82019-10-14
parserIfLabel in inc/zzz_template.php in ZZZCMS zzzphp 1.7.3 allows remote attackers to execute arbitrary code because the danger_key function can be bypassed via manipulations such as strtr.
- CVE-2019-17526CRITICALCVSS 9.8EG 9.82019-10-18
An issue was discovered in SageMath Sage Cell Server through 2019-10-05. Python Code Injection can occur in the context of an internet facing web application. Malicious actors can execute arbitrary commands on the underlying operating syst…
- CVE-2019-17575HIGHCVSS 7.2EG 7.22019-10-14
A file-rename filter bypass exists in admin/media/rename.php in WBCE CMS 1.4.0 and earlier. This can be exploited by an authenticated user with admin privileges to rename a media filename and extension. (For example: place PHP code in a .j…
- CVE-2019-17613CRITICALCVSS 9.8EG 9.82019-10-15
qibosoft 7 allows remote code execution because do/jf.php makes eval calls. The attacker can use the Point Introduction Management feature to supply PHP code to be evaluated. Alternatively, the attacker can access admin/index.php?lfj=jfadm…
- CVE-2019-18582HIGHCVSS 7.2EG 7.22020-03-18
Dell EMC Data Protection Advisor versions 6.3, 6.4, 6.5, 18.2 versions prior to patch 83, and 19.1 versions prior to patch 71 contain a server-side template injection vulnerability in the REST API. A remote authenticated malicious user wit…
- CVE-2019-18792CRITICALCVSS 9.1EG 9.12020-01-06
An issue was discovered in Suricata 5.0.0. It is possible to bypass/evade any tcp based signature by overlapping a TCP segment with a fake FIN packet. The fake FIN packet is injected just before the PUSH ACK packet we want to bypass. The P…
- CVE-2019-18889CRITICALCVSS 9.8EG 9.82019-11-21
An issue was discovered in Symfony 3.4.0 through 3.4.34, 4.2.0 through 4.2.11, and 4.3.0 through 4.3.7. Serializing certain cache adapter interfaces could result in remote code injection. This is related to symfony/cache.
- CVE-2019-19010CRITICALCVSS 9.8EG 9.82019-11-16
Eval injection in the Math plugin of Limnoria (before 2019.11.09) and Supybot (through 2018-05-09) allows remote unprivileged attackers to disclose information or possibly have unspecified other impact via the calc and icalc IRC commands.
- CVE-2019-19089MEDIUMCVSS 6.1EG 6.12020-04-02
For ABB eSOMS versions 4.0 to 6.0.3, the X-Content-Type-Options Header is missing in the HTTP response, potentially causing the response body to be interpreted and displayed as different content type other than declared. A possible attack …
- CVE-2019-19208CRITICALCVSS 9.8EG 9.82020-03-16
Codiad Web IDE through 2.8.4 allows PHP Code injection.
- CVE-2019-19502CRITICALCVSS 9.8EG 9.82019-12-02
Code injection in pluginconfig.php in Image Uploader and Browser for CKEditor before 4.1.9 allows remote authenticated users to execute arbitrary PHP code.
- CVE-2019-19909HIGHCVSS 8.8EG 8.82019-12-19
An issue was discovered in Public Knowledge Project (PKP) pkp-lib before 3.1.2-2, as used in Open Journal Systems (OJS) before 3.1.2-2. Code injection can occur in the OJS report generator if an authenticated Journal Manager user visits a …
- CVE-2019-20002HIGHCVSS 7.8EG 7.82020-04-27
Formula Injection exists in the export feature in SolarWinds WebHelpDesk 12.7.1 via a value (provided by a low-privileged user in the Subject field of a help request form) that is mishandled in a TicketActions/view?tab=group TSV export by …
- CVE-2019-20155HIGHCVSS 8.8EG 8.82020-01-05
An issue was discovered in report_edit.jsp in Determine (formerly Selectica) Contract Lifecycle Management (CLM) v5.4. Any authenticated user may execute Groovy code when generating a report, resulting in arbitrary code execution on the un…
- CVE-2019-20343CRITICALCVSS 9.8EG 9.82020-01-06
The MojoHaus Exec Maven plugin 1.1.1 for Maven allows code execution via a crafted XML document because a configuration element (within a plugin element) can specify an arbitrary program in an executable element (and can also specify arbit…
- CVE-2019-20530CRITICALCVSS 9.8EG 9.82020-03-24
An issue was discovered on Samsung mobile devices with N(7.1), O(8.x), P(9.0), and Q(10.0) software. Arbitrary code execution is possible on the lock screen. The Samsung ID is SVE-2019-15266 (December 2019).
- CVE-2019-20856CRITICALCVSS 9.8EG 9.82020-06-19
An issue was discovered in Mattermost Desktop App before 4.3.0 on macOS. It allows dylib injection.
- CVE-2019-20920HIGHCVSS 8.1EG 8.12020-09-30
Handlebars before 3.0.8 and 4.x before 4.5.3 is vulnerable to Arbitrary Code Execution. The lookup helper fails to properly validate templates, allowing attackers to submit templates that execute arbitrary JavaScript. This can be used to r…
- CVE-2019-2390HIGHCVSS 8.2EG 8.22019-08-30
An unprivileged user or program on Microsoft Windows which can create OpenSSL configuration files in a fixed location may cause utility programs shipped with MongoDB server to run attacker defined code as the user running the utility. This…
- CVE-2019-25022CRITICALCVSS 9.8EG 9.82021-02-27
An issue was discovered in Scytl sVote 2.1. An attacker can inject code that gets executed by creating an election-event and injecting a payload over an event alias, because the application calls Runtime.getRuntime().exec() without validat…
- CVE-2019-25262LOWCVSS 3.5EG 3.52025-12-31
A security vulnerability has been detected in elinicksic Razgover up to db37dfc5c82f023a40f2f7834ded6633fb2b5262. This affects an unknown part of the file Chattify/send.php of the component Chat Message Handler. Such manipulation of the ar…
- CVE-2019-25468CRITICALCVSS 9.8EG 9.82026-03-11
NetGain EM Plus 10.1.68 contains a remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands by submitting malicious parameters to the script_test.jsp endpoint. Attackers can send POST r…
- CVE-2019-3427HIGHCVSS 7.2EG 7.22019-11-22
The version V6.01.03.01 of ZTE ZXCDN IAMWEB product is impacted by a code injection vulnerability. An attacker could exploit the vulnerability to inject malicious code into the management page, resulting in users’ information leakage.
- CVE-2019-3493HIGHCVSS 8.8EG 8.82019-04-29
A potential security vulnerability has been identified in Micro Focus Network Automation Software 9.20, 9.21, 10.00, 10.10, 10.20, 10.30, 10.40, 10.50, 2018.05, 2018.08, 2018.11, and Micro Focus Network Operations Management (NOM) all vers…
- CVE-2019-3575HIGHCVSS 7.8EG 7.82019-01-03
Sqla_yaml_fixtures 0.9.1 allows local users to execute arbitrary python code via the fixture_text argument in sqla_yaml_fixtures.load.
- CVE-2019-3652MEDIUMCVSS 5.0EG 5.32019-10-09
Code Injection vulnerability in EPSetup.exe in McAfee Endpoint Security (ENS) Prior to 10.6.1 October 2019 Update allows local user to get their malicious code installed by the ENS installer via code injection into EPSetup.exe by an attack…
- CVE-2019-3665MEDIUMCVSS 6.5EG 6.52019-12-03
Code Injection vulnerability in the web interface in McAfee Web Advisor (WA) prior to 4.1.1.48 allows remote unauthenticated attacker to allow the browser to render a website which Web Advisor would normally have blocked via a carefully cr…
- CVE-2019-3695HIGHCVSS 8.4EG 8.42020-03-03
A Improper Control of Generation of Code vulnerability in the packaging of pcp of SUSE Linux Enterprise High Performance Computing 15-ESPOS, SUSE Linux Enterprise High Performance Computing 15-LTSS, SUSE Linux Enterprise Module for Develop…
- CVE-2019-3759MEDIUMCVSS 6.4EG 6.42019-09-11
The RSA Identity Governance and Lifecycle software and RSA Via Lifecycle and Governance products prior to 7.1.0 P08 contain a code injection vulnerability. A remote authenticated malicious user could potentially exploit this vulnerability …
- CVE-2019-4000HIGHCVSS 7.8EG 7.82020-02-25
Improper neutralization of directives in dynamically evaluated code in Druva inSync Mac OS Client 6.5.0 allows a local, authenticated attacker to execute arbitrary Python expressions with root privileges.
- CVE-2019-4038MEDIUMCVSS 6.2EG 6.22019-02-04
IBM Security Identity Manager 6.0 and 7.0 could allow an attacker to create unexpected control flow paths through the application, potentially bypassing security checks. Exploitation of this weakness can result in a limited form of code in…
- CVE-2019-4716CRITICALCVSS 9.8EG 9.8⚠ KEV2019-12-18
IBM Planning Analytics 2.0.0 through 2.0.8 is vulnerable to a configuration overwrite that allows an unauthenticated user to login as "admin", and then execute code as root or SYSTEM via TM1 scripting. IBM X-Force ID: 172094.
- CVE-2019-5413CRITICALCVSS 9.8EG 9.82019-03-21
An attacker can use the format parameter to inject arbitrary commands in the npm package morgan < 1.9.1.
- CVE-2019-5443HIGHCVSS 7.8EG 7.82019-07-02
A non-privileged user or program can put code and a config file in a known non-privileged path (under C:/usr/local/) that will make curl <= 7.65.1 automatically run the code (as an openssl "engine") on invocation. If that curl is invoked b…
- CVE-2019-5509CRITICALCVSS 9.8EG 9.82019-11-21
ONTAP Select Deploy administration utility versions 2.11.2 through 2.12.2 are susceptible to a code injection vulnerability which when successfully exploited could allow an unauthenticated remote attacker to enable and use a privileged use…
- CVE-2019-5997CRITICALCVSS 9.8EG 9.82020-05-20
Video Insight VMS versions prior to 7.6.1 allow remote attackers to conduct code injection attacks via unspecified vectors.
- CVE-2019-6713CRITICALCVSS 9.8EG 9.82019-01-23
app\admin\controller\RouteController.php in ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code by using vectors involving portal/List/index and list/:id to inject this code into data\conf\route.php, as demonstrated b…
- CVE-2019-6816CRITICALCVSS 9.1EG 9.12019-05-22
In Modicon Quantum all firmware versions, a CWE-94: Code Injection vulnerability could cause an unauthorized firmware modification with possible Denial of Service when using Modbus protocol.
- CVE-2019-6823CRITICALCVSS 9.8EG 9.82019-07-15
A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to ver…
- CVE-2019-7177HIGHCVSS 7.2EG 7.22020-09-25
Pexip Infinity before 20.1 allows Code Injection onto nodes via an admin.
- CVE-2019-7486HIGHCVSS 8.8EG 8.82019-12-19
Code injection in SonicWall SMA100 allows an authenticated user to execute arbitrary code in viewcacert CGI script. This vulnerability impacted SMA100 version 9.0.0.4 and earlier.
- CVE-2019-7539CRITICALCVSS 8.8EG 9.62019-03-21
A code injection issue was discovered in ipycache through 2016-05-31.
- CVE-2019-7580HIGHCVSS 8.8EG 8.82019-02-07
ThinkCMF 5.0.190111 allows remote attackers to execute arbitrary PHP code via the portal/admin_category/addpost.html alias parameter because the mishandling of a single quote character allows data/conf/route.php injection.
- CVE-2019-7609CRITICALCVSS 10.0EG 10.0⚠ KEV2019-03-25
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer. An attacker with access to the Timelion application could send a request that will attempt to execute javascript code. This could …
- CVE-2019-7610CRITICALCVSS 9.0EG 9.02019-03-25
Kibana versions before 6.6.1 contain an arbitrary code execution flaw in the security audit logger. If a Kibana instance has the setting xpack.security.audit.enabled set to true, an attacker could send a request that will attempt to execut…
- CVE-2019-7692CRITICALCVSS 9.8EG 9.82019-02-10
install/install.php in CIM 0.9.3 allows remote attackers to execute arbitrary PHP code via a crafted prefix value because of configuration file mishandling in the N=83 case, as demonstrated by a call to the PHP fputs function that creates …
- CVE-2019-7719CRITICALCVSS 9.8EG 9.82019-02-11
Nibbleblog 4.0.5 allows eval injection by placing PHP code in the install.php username parameter and then making a content/private/shadow.php request.
- CVE-2019-7720CRITICALCVSS 9.8EG 9.82019-02-11
taocms through 2014-05-24 allows eval injection by placing PHP code in the install.php db_name parameter and then making a config.php request.
- CVE-2019-7871HIGHCVSS 8.8EG 8.82019-08-02
A security bypass exists in Magento 2.1 prior to 2.1.18, Magento 2.2 prior to 2.2.9, Magento 2.3 prior to 2.3.2 that could be abused to execute arbitrary PHP code. An authenticated user can bypass security protections that prevent arbitrar…
- CVE-2019-8324HIGHCVSS 8.8EG 8.82019-06-17
An issue was discovered in RubyGems 2.6 and later through 3.0.2. A crafted gem with a multi-line name is not handled correctly. Therefore, an attacker could inject arbitrary code to the stub line of gemspec, which is eval-ed by code in ens…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →