CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 51 of 143
- CVE-2020-15591CRITICALCVSS 9.8EG 9.82022-03-17
fexsrv in F*EX (aka Frams' Fast File EXchange) before fex-20160919_2 allows eval injection (for unauthenticated remote code execution).
- CVE-2020-15817HIGHCVSS 8.8EG 8.82020-08-08
In JetBrains YouTrack before 2020.1.1331, an external user could execute commands against arbitrary issues.
- CVE-2020-15865CRITICALCVSS 9.8EG 9.82020-08-18
A Remote Code Execution vulnerability in Stimulsoft (aka Stimulsoft Reports) 2013.1.1600.0 allows an attacker to encode C# scripts as base-64 in the report XML file so that they will be compiled and executed on the server that processes th…
- CVE-2020-16147CRITICALCVSS 9.8EG 9.82020-09-24
The login page in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via Unauthenticated code injection over the network.
- CVE-2020-16148HIGHCVSS 7.2EG 7.22020-09-24
The ping page of the administration panel in Telmat AccessLog <= 6.0 (TAL_20180415) allows an attacker to get root shell access via authenticated code injection over the network.
- CVE-2020-16874HIGHCVSS 7.8EG 7.82020-09-11
<p>A remote code execution vulnerability exists in Visual Studio when it improperly handles objects in memory. An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the current user. If the cur…
- CVE-2020-16875HIGHCVSS 8.4EG 8.62020-09-11
<p>A remote code execution vulnerability exists in Microsoft Exchange server due to improper validation of cmdlet arguments.</p> <p>An attacker who successfully exploited the vulnerability could run arbitrary code in the context of the Sys…
- CVE-2020-17091HIGHCVSS 7.8EG 7.82020-11-11
Microsoft Teams Remote Code Execution Vulnerability
- CVE-2020-17132CRITICALCVSS 9.1EG 9.12020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2020-17141HIGHCVSS 8.4EG 8.42020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2020-17142CRITICALCVSS 9.1EG 9.12020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2020-17144CRITICALCVSS 8.4EG 9.0⚠ KEV2020-12-10
Microsoft Exchange Remote Code Execution Vulnerability
- CVE-2020-17148HIGHCVSS 7.8EG 7.82020-12-10
Visual Studio Code Remote Development Extension Remote Code Execution Vulnerability
- CVE-2020-17150HIGHCVSS 7.8EG 7.82020-12-10
Visual Studio Code Remote Code Execution Vulnerability
- CVE-2020-17152HIGHCVSS 8.8EG 8.82020-12-10
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
- CVE-2020-17156HIGHCVSS 7.8EG 7.82020-12-10
Visual Studio Remote Code Execution Vulnerability
- CVE-2020-17158HIGHCVSS 8.8EG 8.82020-12-10
Microsoft Dynamics 365 for Finance and Operations (on-premises) Remote Code Execution Vulnerability
- CVE-2020-17159HIGHCVSS 7.8EG 7.82020-12-10
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
- CVE-2020-17456CRITICALCVSS 9.8EG 9.82020-08-20
SEOWON INTECH SLC-130 And SLR-120S devices allow Remote Code Execution via the ipAddr parameter to the system_log.cgi page.
- CVE-2020-18172CRITICALCVSS 9.8EG 9.82021-07-26
A code injection vulnerability in the SeDebugPrivilege component of Trezor Bridge 2.0.27 allows attackers to escalate privileges.
- CVE-2020-18185CRITICALCVSS 9.8EG 9.82020-10-02
class.plx.admin.php in PluXml 5.7 allows attackers to execute arbitrary PHP code by modify the configuration file in a linux environment.
- CVE-2020-19822HIGHCVSS 7.2EG 7.22021-08-26
A remote code execution (RCE) vulnerability in template_user.php of ZZCMS version 2018 allows attackers to execute arbitrary PHP code via the "ml" and "title" parameters.
- CVE-2020-20124HIGHCVSS 8.8EG 8.82021-09-28
Wuzhi CMS v4.1.0 contains a remote code execution (RCE) vulnerability in \attachment\admin\index.php.
- CVE-2020-20298CRITICALCVSS 9.8EG 9.82020-12-18
Eval injection vulnerability in the parserCommom method in the ParserTemplate class in zzz_template.php in zzzphp 1.7.2 allows remote attackers to execute arbitrary commands.
- CVE-2020-20601CRITICALCVSS 9.8EG 9.82021-12-22
An issue in ThinkCMF X2.2.2 and below allows attackers to execute arbitrary code via a crafted packet.
- CVE-2020-20918HIGHCVSS 7.2EG 7.22023-06-20
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
- CVE-2020-21016CRITICALCVSS 9.8EG 9.82022-10-31
D-Link DIR-846 devices with firmware 100A35 allow remote attackers to execute arbitrary code as root via HNAP1/control/SetGuestWLanSettings.php.
- CVE-2020-21650HIGHCVSS 8.8EG 8.82021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the add() method.
- CVE-2020-21651CRITICALCVSS 9.8EG 9.82021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\point.php, which can be exploited via the add() method.
- CVE-2020-21652CRITICALCVSS 9.8EG 9.82021-10-06
Myucms v2.2.1 contains a remote code execution (RCE) vulnerability in the component \controller\Config.php, which can be exploited via the addqq() method.
- CVE-2020-21784CRITICALCVSS 9.8EG 9.82021-06-24
phpwcms 1.9.13 is vulnerable to Code Injection via /phpwcms/setup/setup.php.
- CVE-2020-22120HIGHCVSS 8.8EG 8.82021-08-18
A remote code execution (RCE) vulnerability in /root/run/adm.php?admin-ediy&part=exdiy of imcat v5.1 allows authenticated attackers to execute arbitrary code.
- CVE-2020-22201HIGHCVSS 8.8EG 8.82021-06-16
phpCMS 2008 sp4 allowas remote malicious users to execute arbitrary php commands via the pagesize parameter to yp/product.php.
- CVE-2020-22427HIGHCVSS 7.2EG 7.22021-02-15
NagiosXI 5.6.11 is affected by a remote code execution (RCE) vulnerability. An authenticated nagiosadmin user can inject additional commands into a request. NOTE: the vendor disputes whether the CVE and its references are actionable becaus…
- CVE-2020-22612CRITICALCVSS 9.8EG 9.82023-09-01
Installer RCE on settings file write in MyBB before 1.8.22.
- CVE-2020-22937CRITICALCVSS 9.8EG 9.82021-08-17
A remote code execution (RCE) in e/install/index.php of EmpireCMS 7.5 allows attackers to execute arbitrary PHP code via writing malicious code to the install file.
- CVE-2020-23037CRITICALCVSS 9.8EG 9.82021-10-22
Portable Ltd Playable v9.18 contains a code injection vulnerability in the filename parameter, which allows attackers to execute arbitrary web scripts or HTML via a crafted POST request.
- CVE-2020-23219HIGHCVSS 8.8EG 8.82021-07-01
Monstra CMS 3.0.4 allows attackers to execute arbitrary code via a crafted payload entered into the "Snippet content" field under the "Edit Snippet" module.
- CVE-2020-24354HIGHCVSS 8.8EG 8.82020-08-31
Zyxel VMG5313-B30B router on firmware 5.13(ABCJ.6)b3_1127, and possibly older versions of firmware are affected by shell injection.
- CVE-2020-24365HIGHCVSS 8.8EG 8.82020-09-24
An issue was discovered on Gemtek WRTM-127ACN 01.01.02.141 and WRTM-127x9 01.01.02.127 devices. The Monitor Diagnostic network page allows an authenticated attacker to execute a command directly on the target machine. Commands are executed…
- CVE-2020-24614HIGHCVSS 8.8EG 8.82020-08-25
Fossil before 2.10.2, 2.11.x before 2.11.2, and 2.12.x before 2.12.1 allows remote authenticated users to execute arbitrary code. An attacker must have check-in privileges on the repository.
- CVE-2020-24628HIGHCVSS 8.8EG 8.82020-10-02
A remote code injection vulnerability was discovered in HPE KVM IP Console Switches version(s): G2 4x1Ex32 Prior to 2.8.3.
- CVE-2020-25197CRITICALCVSS 9.8EG 9.82022-03-18
A code injection vulnerability exists in one of the webpages in GE Reason RT430, RT431 & RT434 GNSS clocks in firmware versions prior to version 08A06 that could allow an authenticated remote attacker to execute arbitrary code on the syste…
- CVE-2020-25223CRITICALCVSS 9.8EG 9.8⚠ KEV2020-09-25
A remote code execution vulnerability exists in the WebAdmin of Sophos SG UTM before v9.705 MR5, v9.607 MR7, and v9.511 MR11
- CVE-2020-25414CRITICALCVSS 9.8EG 9.82021-06-17
A local file inclusion vulnerability was discovered in the captcha function in Monstra 3.0.4 which allows remote attackers to execute arbitrary PHP code.
- CVE-2020-25538HIGHCVSS 8.8EG 8.82020-11-13
An authenticated attacker can inject malicious code into "lang" parameter in /uno/central.php file in CMSuno 1.6.2 and run this PHP code in the web page. In this way, attacker can takeover the control of the server.
- CVE-2020-25557HIGHCVSS 8.8EG 8.82020-11-13
In CMSuno 1.6.2, an attacker can inject malicious PHP code as a "username" while changing his/her username & password. After that, when attacker logs in to the application, attacker's code will be run. As a result of this vulnerability, au…
- CVE-2020-25967HIGHCVSS 8.8EG 8.82020-12-10
The member center function in fastadmin V1.0.0.20200506_beta is vulnerable to a Server-Side Template Injection (SSTI) vulnerability.
- CVE-2020-26124HIGHCVSS 8.8EG 8.92020-10-02
openmediavault before 4.1.36 and 5.x before 5.5.12 allows authenticated PHP code injection attacks, via the sortfield POST parameter of rpc.php, because json_encode_safe is not used in config/databasebackend.inc. Successful exploitation al…
- CVE-2020-26165HIGHCVSS 8.8EG 8.82020-12-31
qdPM through 9.1 allows PHP Object Injection via timeReportActions::executeExport in core/apps/qdPM/modules/timeReport/actions/actions.class.php because unserialize is used.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →