CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 52 of 143
- CVE-2020-26540HIGHCVSS 7.5EG 7.52020-10-02
An issue was discovered in Foxit Reader and PhantomPDF before 4.1 on macOS. Because the Hardened Runtime protection mechanism is not applied to code signing, code injection (or an information leak) can occur.
- CVE-2020-26808HIGHCVSS 7.2EG 7.22020-11-10
SAP AS ABAP(DMIS), versions - 2011_1_620, 2011_1_640, 2011_1_700, 2011_1_710, 2011_1_730, 2011_1_731, 2011_1_752, 2020 and SAP S4 HANA(DMIS), versions - 101, 102, 103, 104, 105, allows an authenticated attacker to inject arbitrary code int…
- CVE-2020-27192HIGHCVSS 7.8EG 7.82020-11-17
BinaryNights ForkLift 3.4 was compiled with the com.apple.security.cs.disable-library-validation flag enabled which allowed a local attacker to inject code into ForkLift. This would allow the attacker to run malicious code with escalated p…
- CVE-2020-28366HIGHCVSS 7.5EG 7.52020-11-18
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via a malicious unquoted symbol name in a linked object file.
- CVE-2020-28367HIGHCVSS 7.5EG 7.52020-11-18
Code injection in the go command with cgo before Go 1.14.12 and Go 1.15.5 allows arbitrary code execution at build time via malicious gcc flags specified via a #cgo directive.
- CVE-2020-28419HIGHCVSS 8.8EG 8.82021-11-09
During installation with certain driver software or application packages an arbitrary code execution could occur.
- CVE-2020-28450HIGHCVSS 8.6EG 8.62021-02-04
This affects all versions of package decal. The vulnerability is in the extend function.
- CVE-2020-28464CRITICALCVSS 9.8EG 9.82021-01-04
This affects the package djv before 2.1.4. By controlling the schema file, an attacker can run arbitrary JavaScript code on the victim machine.
- CVE-2020-28502HIGHCVSS 8.1EG 8.12021-03-05
This affects the package xmlhttprequest before 1.7.0; all versions of package xmlhttprequest-ssl. Provided requests are sent synchronously (async=False on xhr.open), malicious user input flowing into xhr.send could result in arbitrary code…
- CVE-2020-28695HIGHCVSS 8.8EG 8.82021-03-26
Askey Fiber Router RTF3505VW-N1 BR_SV_g000_R3505VWN1001_s32_7 devices allow Remote Code Execution and retrieval of admin credentials to log into the Dashboard or login via SSH, leading to code execution as root.
- CVE-2020-28870CRITICALCVSS 9.8EG 9.82021-02-10
In InoERP 0.7.2, an unauthorized attacker can execute arbitrary code on the server side due to lack of validations in /modules/sys/form_personalization/json_fp.php.
- CVE-2020-28905HIGHCVSS 8.8EG 8.82021-05-24
Improper Input Validation in Nagios Fusion 4.1.8 and earlier allows an authenticated attacker to execute remote code via table pagination.
- CVE-2020-29007CRITICALCVSS 9.8EG 9.82023-04-15
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable. This allows any user with an ability to edit articles (potentially including unauthenticat…
- CVE-2020-3416MEDIUMCVSS 6.7EG 6.72020-09-24
Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenti…
- CVE-2020-35121HIGHCVSS 8.8EG 8.82020-12-15
An issue was discovered in the Keysight Database Connector plugin before 1.5.0 for Confluence. A malicious user could insert arbitrary JavaScript into saved macro parameters that would execute when a user viewed a page with that instance o…
- CVE-2020-3513MEDIUMCVSS 6.7EG 6.72020-09-24
Multiple vulnerabilities in the initialization routines that are executed during bootup of Cisco IOS XE Software for Cisco ASR 900 Series Aggregation Services Routers with a Route Switch Processor 3 (RSP3) installed could allow an authenti…
- CVE-2020-35131CRITICALCVSS 9.8EG 9.82021-01-08
Cockpit before 0.6.1 allows an attacker to inject custom PHP code and achieve Remote Command Execution via registerCriteriaFunction in lib/MongoLite/Database.php, as demonstrated by values in JSON data to the /auth/check or /auth/requestre…
- CVE-2020-35339CRITICALCVSS 9.8EG 9.82021-02-17
In 74cms version 5.0.1, there is a remote code execution vulnerability in /Application/Admin/Controller/ConfigController.class.php and /ThinkPHP/Common/functions.php where attackers can obtain server permissions and control the server.
- CVE-2020-35370HIGHCVSS 8.8EG 8.82020-12-23
A RCE vulnerability exists in Raysync below 3.3.3.8. An unauthenticated unauthorized attacker sending a specifically crafted request to override the specific file in server with malicious content can login as "admin", then to modify specif…
- CVE-2020-35458CRITICALCVSS 9.8EG 9.82021-01-12
An issue was discovered in ClusterLabs Hawk 2.x through 2.3.0-x. There is a Ruby shell code injection issue via the hawk_remember_me_id parameter in the login_from_cookie cookie. The user logout routine could be used by unauthenticated rem…
- CVE-2020-35734HIGHCVSS 7.2EG 7.22021-02-15
Sruu.pl in Batflat 1.3.6 allows an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Users tab. To exploit this, one must login to the administration panel and edit an arbitra…
- CVE-2020-35754HIGHCVSS 7.2EG 7.22021-01-28
OpenSolution Quick.CMS < 6.7 and Quick.Cart < 6.7 allow an authenticated user to perform code injection (and consequently Remote Code Execution) via the input fields of the Language tab.
- CVE-2020-36655HIGHCVSS 8.8EG 8.82023-01-21
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field. The attacker can embed arbitrary PHP code into the model file.
- CVE-2020-36708CRITICALCVSS 9.8EG 9.82023-06-07
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5…
- CVE-2020-36767HIGHCVSS 7.5EG 7.52023-10-30
tinyfiledialogs (aka tiny file dialogs) before 3.8.0 allows shell metacharacters in titles, messages, and other input data.
- CVE-2020-36870CRITICALCVSS 9.2EG 9.22025-11-07
Various Ruijie Gateway EG and NBR models firmware versions 11.1(6)B9P1 < 11.9(4)B12P1 contain a code execution vulnerability in the EWEB management system that can be abused via front-end functionality. Attackers can exploit front-end code…
- CVE-2020-36875CRITICALCVSS 9.3EG 9.32026-01-09
AccessAlly WordPress plugin versions prior to 3.3.2 contain an unauthenticated arbitrary PHP code execution vulnerability in the Login Widget. The plugin processes the login_error parameter as PHP code, allowing an attacker to supply and …
- CVE-2020-37052CRITICALCVSS 9.8EG 9.82026-01-30
AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam end…
- CVE-2020-37137MEDIUMCVSS 6.1EG 6.12026-02-05
PHP-Fusion 9.03.50 contains a remote code execution vulnerability in the 'add_panel_form()' function that allows attackers to execute arbitrary code through an eval() function with unsanitized POST data. Attackers can exploit the vulnerabi…
- CVE-2020-37167CRITICALCVSS 8.4EG 9.82026-02-12
ClamAV versions prior to 0.103.0-rc contain a vulnerability in function name processing through the ClamBC bytecode interpreter that allows attackers to manipulate bytecode function names. Attackers can exploit the weak input validation i…
- CVE-2020-37178HIGHCVSS 7.5EG 7.52026-02-11
KeePass Password Safe versions before 2.44 contain a denial of service vulnerability in the help system's HTML handling. Attackers can trigger the vulnerability by dragging and dropping malicious HTML files into the help area, potentially …
- CVE-2020-37186CRITICALCVSS 9.8EG 9.82026-02-11
Chevereto 3.13.4 Core contains a remote code execution vulnerability that allows attackers to inject malicious code during database configuration installation. Attackers can manipulate the database table prefix parameter to write a PHP she…
- CVE-2020-4520HIGHCVSS 8.8EG 8.82021-06-01
IBM Cognos Analytics 11.0 and 11.1 could allow a remote attacker to inject malicious HTML code that when viewed by the authenticated victim would execute the code. IBM X-Force ID: 182395.
- CVE-2020-5203CRITICALCVSS 9.8EG 9.82020-03-11
In Fat-Free Framework 3.7.1, attackers can achieve arbitrary code execution if developers choose to pass user controlled input (e.g., $_REQUEST, $_GET, or $_POST) to the framework's Clear method.
- CVE-2020-5258HIGHCVSS 7.7EG 7.72020-03-10
In affected versions of dojo (NPM package), the deepCopy method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. A…
- CVE-2020-5259HIGHCVSS 7.7EG 7.72020-03-10
In affected versions of dojox (NPM package), the jqMix method is vulnerable to Prototype Pollution. Prototype Pollution refers to the ability to inject properties into existing JavaScript language construct prototypes, such as objects. An …
- CVE-2020-5529HIGHCVSS 8.1EG 8.12020-02-11
HtmlUnit prior to 2.37.0 contains code execution vulnerabilities. HtmlUnit initializes Rhino engine improperly, hence a malicious JavScript code can execute arbitrary Java code on the application. Moreover, when embedded in Android applica…
- CVE-2020-5553CRITICALCVSS 9.8EG 9.82020-03-25
mailform version 1.04 allows remote attackers to execute arbitrary PHP code via unspecified vectors.
- CVE-2020-5558HIGHCVSS 8.8EG 8.82020-03-25
CuteNews 2.0.1 allows remote authenticated attackers to execute arbitrary PHP code via unspecified vectors.
- CVE-2020-5593HIGHCVSS 8.8EG 8.82020-06-11
Zenphoto versions prior to 1.5.7 allows an attacker to conduct PHP code injection attacks by leading a user to upload a specially crafted .zip file.
- CVE-2020-5739HIGHCVSS 8.8EG 8.82020-04-14
Grandstream GXP1600 series firmware 1.0.4.152 and below is vulnerable to authenticated remote command execution when an attacker adds an OpenVPN up script to the phone's VPN settings via the "Additional Settings" field in the web interface…
- CVE-2020-5847CRITICALCVSS 9.8EG 9.8⚠ KEV2020-03-16
Unraid through 6.8.0 allows Remote Code Execution.
- CVE-2020-5902CRITICALCVSS 9.8EG 9.8⚠ KEV2020-07-01
In BIG-IP versions 15.0.0-15.1.0.3, 14.1.0-14.1.2.5, 13.1.0-13.1.3.3, 12.1.0-12.1.5.1, and 11.6.1-11.6.5.1, the Traffic Management User Interface (TMUI), also referred to as the Configuration utility, has a Remote Code Execution (RCE) vuln…
- CVE-2020-6143CRITICALCVSS 9.8EG 9.82020-09-01
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The password variable which is set at line 122 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An …
- CVE-2020-6144CRITICALCVSS 9.8EG 9.82020-09-01
A remote code execution vulnerability exists in the install functionality of OS4Ed openSIS 7.4. The username variable which is set at line 121 in install/Step5.php allows for injection of PHP code into the Data.php file that it writes. An …
- CVE-2020-6208HIGHCVSS 8.2EG 8.22020-03-10
SAP Business Objects Business Intelligence Platform (Crystal Reports), versions- 4.1, 4.2, allows an attacker with basic authorization to inject code that can be executed by the application and thus allowing the attacker to control the beh…
- CVE-2020-6230HIGHCVSS 7.2EG 7.22020-04-14
SAP OrientDB, version 3.0, allows an authenticated attacker with script execute/write permissions to inject code that can be executed by the application and lead to Code Injection. An attacker could thereby control the behavior of the appl…
- CVE-2020-6243HIGHCVSS 8.8EG 8.82020-05-12
Under certain conditions, SAP Adaptive Server Enterprise (XP Server on Windows Platform), versions 15.7, 16.0, does not perform the necessary checks for an authenticated user while executing the extended stored procedure, allowing an attac…
- CVE-2020-6248HIGHCVSS 7.2EG 7.22020-05-12
SAP Adaptive Server Enterprise (Backup Server), version 16.0, does not perform the necessary validation checks for an authenticated user while executing DUMP or LOAD command allowing arbitrary code execution or Code Injection.
- CVE-2020-6262HIGHCVSS 8.8EG 8.82020-05-12
Service Data Download in SAP Application Server ABAP (ST-PI, before versions 2008_1_46C, 2008_1_620, 2008_1_640, 2008_1_700, 2008_1_710, 740) allows an attacker to inject code that can be executed by the application. An attacker could ther…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →