CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 53 of 143
- CVE-2020-6296HIGHCVSS 8.8EG 8.82020-08-12
SAP NetWeaver (ABAP Server) and ABAP Platform, versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 753, 755, allows an attacker to inject code that can be executed by the application, leading to Code Injection. An attacker could t…
- CVE-2020-6318HIGHCVSS 7.2EG 7.22020-09-09
A Remote Code Execution vulnerability exists in the SAP NetWeaver (ABAP Server, up to release 7.40) and ABAP Platform (> release 7.40).Because of this, an attacker can exploit these products via Code Injection, and potentially enabling to …
- CVE-2020-6650HIGHCVSS 8.3EG 8.32020-03-23
UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update…
- CVE-2020-6836CRITICALCVSS 9.8EG 9.82020-01-11
grammar-parser.jison in the hot-formula-parser package before 3.0.1 for Node.js is vulnerable to arbitrary code injection. The package fails to sanitize values passed to the parse function and concatenates them in an eval call. If a value …
- CVE-2020-7012HIGHCVSS 8.8EG 8.82020-06-03
Kibana versions 6.7.0 to 6.8.8 and 7.0.0 to 7.6.2 contain a prototype pollution flaw in the Upgrade Assistant. An authenticated attacker with privileges to write to the Kibana index could insert data that would cause Kibana to execute arbi…
- CVE-2020-7013HIGHCVSS 7.2EG 7.22020-06-03
Kibana versions before 6.8.9 and 7.7.0 contain a prototype pollution flaw in TSVB. An authenticated attacker with privileges to create TSVB visualizations could insert data that would cause Kibana to execute arbitrary code. This could poss…
- CVE-2020-7205MEDIUMCVSS 6.7EG 6.72020-07-30
A potential security vulnerability has been identified in HPE Intelligent Provisioning, Service Pack for ProLiant, and HPE Scripting ToolKit. The vulnerability could be locally exploited to allow arbitrary code execution during the boot pr…
- CVE-2020-7206CRITICALCVSS 9.8EG 9.82020-07-17
HP nagios plugin for iLO (nagios-plugins-hpilo v1.50 and earlier) has a php code injection vulnerability.
- CVE-2020-7373CRITICALCVSS 9.8EG 9.82020-10-30
vBulletin 5.5.4 through 5.6.2 allows remote command execution via crafted subWidgets data in an ajax/render/widget_tabbedcontainer_tab_panel request. NOTE: this issue exists because of an incomplete fix for CVE-2019-16759. ALSO NOTE: CVE-2…
- CVE-2020-7381MEDIUMCVSS 5.8EG 5.82020-09-03
In Rapid7 Nexpose installer versions prior to 6.6.40, the Nexpose installer calls an executable which can be placed in the appropriate directory by an attacker with access to the local machine. This would prevent the installer from disting…
- CVE-2020-7472CRITICALCVSS 9.8EG 9.82020-11-12
An authorization bypass and PHP local-file-include vulnerability in the installation component of SugarCRM before 8.0, 8.0 before 8.0.7, 9.0 before 9.0.4, and 10.0 before 10.0.0 allows for unauthenticated remote code execution against a co…
- CVE-2020-7480CRITICALCVSS 9.8EG 9.82020-03-23
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists in Andover Continuum (All versions), which could cause files on the application server filesystem to be viewable when an attacker interferes with an a…
- CVE-2020-7609CRITICALCVSS 9.8EG 9.82020-04-27
node-rules including 3.0.0 and prior to 5.0.0 allows injection of arbitrary commands. The argument rules of function "fromJSON()" can be controlled by users without any sanitization.
- CVE-2020-7672HIGHCVSS 8.6EG 8.62020-06-10
mosc through 1.0.0 is vulnerable to Arbitrary Code Execution. User input provided to `properties` argument is executed by the `eval` function, resulting in code execution.
- CVE-2020-7673CRITICALCVSS 9.8EG 9.82020-06-10
node-extend through 0.2.0 is vulnerable to Arbitrary Code Execution. User input provided to the argument `A` of `extend` function`(A,B,as,isAargs)` located within `lib/extend.js` is executed by the `eval` function, resulting in code execut…
- CVE-2020-7674CRITICALCVSS 9.8EG 9.82020-06-10
access-policy through 3.1.0 is vulnerable to Arbitrary Code Execution. User input provided to the `template` function is executed by the `eval` function resulting in code execution.
- CVE-2020-7675CRITICALCVSS 9.8EG 9.82020-06-10
cd-messenger through 2.7.26 is vulnerable to Arbitrary Code Execution. User input provided to the `color` argument executed by the `eval` function resulting in code execution.
- CVE-2020-7694LOWCVSS 3.7EG 3.72020-07-27
This affects all versions of package uvicorn. The request logger provided by the package is vulnerable to ASNI escape sequence injection. Whenever any HTTP request is received, the default behaviour of uvicorn is to log its details to eith…
- CVE-2020-7710CRITICALCVSS 8.1EG 9.82020-08-21
This affects all versions of package safe-eval. It is possible for an attacker to run an arbitrary command on the host machine.
- CVE-2020-7738HIGHCVSS 8.3EG 8.32020-10-02
All versions of package shiba are vulnerable to Arbitrary Code Execution due to the default usage of the function load() of the package js-yaml instead of its secure replacement , safeLoad().
- CVE-2020-7745HIGHCVSS 7.1EG 7.12020-10-19
This affects the package MintegralAdSDK before 6.6.0.0. The SDK distributed by the company contains malicious functionality that acts as a backdoor. Mintegral and their partners (advertisers) can remotely execute arbitrary code on a user d…
- CVE-2020-7777HIGHCVSS 7.2EG 7.22020-11-23
This affects all versions of package jsen. If an attacker can control the schema file, it could run arbitrary JavaScript code on the victim machine. In the module description and README file there is no mention about the risks of untrusted…
- CVE-2020-8129CRITICALCVSS 9.8EG 9.82020-02-14
An unintended require vulnerability in script-manager npm package version 0.8.6 and earlier may allow attackers to execute arbitrary code.
- CVE-2020-8132CRITICALCVSS 9.8EG 9.82020-02-28
Lack of input validation in pdf-image npm package version <= 2.0.0 may allow an attacker to run arbitrary code if PDF file path is constructed based on untrusted user input.
- CVE-2020-8137CRITICALCVSS 9.8EG 9.82020-03-20
Code injection vulnerability in blamer 1.0.0 and earlier may result in remote code execution when the input can be controlled by an attacker.
- CVE-2020-8140MEDIUMCVSS 6.7EG 6.72020-03-20
A code injection in Nextcloud Desktop Client 2.6.2 for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES set in the environment.
- CVE-2020-8141HIGHCVSS 8.8EG 8.82020-03-15
The dot package v1.1.2 uses Function() to compile templates. This can be exploited by the attacker if they can control the given template or if they can control the value set on Object.prototype.
- CVE-2020-8149CRITICALCVSS 9.8EG 9.82020-05-15
Lack of output sanitization allowed an attack to execute arbitrary shell commands via the logkitty npm package before version 0.7.1.
- CVE-2020-8163CRITICALCVSS 8.8EG 9.02020-07-02
The is a code injection vulnerability in versions of Rails prior to 5.0.1 that wouldallow an attacker who controlled the `locals` argument of a `render` call to perform a RCE.
- CVE-2020-8180CRITICALCVSS 9.9EG 9.92020-06-08
A too lax check in Nextcloud Talk 6.0.4, 7.0.2 and 8.0.7 allowed a code injection when a not correctly sanitized talk command was added by an administrator.
- CVE-2020-8194MEDIUMCVSS 6.5EG 6.52020-07-10
Reflected code injection in Citrix ADC and Citrix Gateway versions before 13.0-58.30, 12.1-57.18, 12.0-63.21, 11.1-64.14 and 10.5-70.18 and Citrix SDWAN WAN-OP versions before 11.1.1a, 11.0.3d and 10.2.7 allows the modification of a file d…
- CVE-2020-8218CRITICALCVSS 7.2EG 9.0⚠ KEV2020-07-30
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
- CVE-2020-8224HIGHCVSS 7.8EG 7.82020-08-10
A code injection in Nextcloud Desktop Client 2.6.4 allowed to load arbitrary code when placing a malicious OpenSSL config into a fixed directory.
- CVE-2020-8243CRITICALCVSS 7.2EG 9.0⚠ KEV2020-09-30
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
- CVE-2020-8274MEDIUMCVSS 6.5EG 6.52021-01-06
Citrix Secure Mail for Android before 20.11.0 suffers from Improper Control of Generation of Code ('Code Injection') by allowing unauthenticated access to read data stored within Secure Mail. Note that a malicious app would need to be inst…
- CVE-2020-8349CRITICALCVSS 9.8EG 9.82020-10-14
An internal security review has identified an unauthenticated remote code execution vulnerability in Cloud Networking Operating System (CNOS)’ optional REST API management interface. This interface is disabled by default and not vulnerab…
- CVE-2020-8518CRITICALCVSS 9.8EG 9.82020-02-17
Horde Groupware Webmail Edition 5.2.22 allows injection of arbitrary PHP code via CSV data, leading to remote code execution.
- CVE-2020-8584CRITICALCVSS 9.8EG 9.82021-01-08
Element OS versions prior to 1.8P1 and 12.2 are susceptible to a vulnerability that could allow an unauthenticated remote attacker to perform arbitrary code execution.
- CVE-2020-8644CRITICALCVSS 9.8EG 9.8⚠ KEV2020-02-05
PlaySMS before 1.4.3 does not sanitize inputs from a malicious string.
- CVE-2020-8961CRITICALCVSS 9.8EG 9.82020-04-09
An issue was discovered in Avira Free-Antivirus before 15.0.2004.1825. The Self-Protection feature does not prohibit a write operation from an external process. Thus, code injection can be used to turn off this feature. After that, one can…
- CVE-2020-9199MEDIUMCVSS 6.8EG 6.82020-09-03
B2368-22 V100R001C00;B2368-57 V100R001C00;B2368-66 V100R001C00 have a command injection vulnerability. An attacker with high privileges may exploit this vulnerability through some operations on the LAN. Due to insufficient input validation…
- CVE-2020-9377CRITICALCVSS 8.8EG 9.0⚠ KEV2020-07-09
D-Link DIR-610 devices allow Remote Command Execution via the cmd parameter to command.php. NOTE: This vulnerability only affects products that are no longer supported by the maintainer
- CVE-2020-9406CRITICALCVSS 9.8EG 9.82020-02-26
IBL Online Weather before 4.3.5a allows unauthenticated eval injection via the queryBCP method of the Auxiliary Service.
- CVE-2020-9530MEDIUMCVSS 6.5EG 6.52020-03-06
An issue was discovered on Xiaomi MIUI V11.0.5.0.QFAEUXM devices. The export component of GetApps(com.xiaomi.mipicks) mishandles the functionality of opening other components. Attackers need to induce users to open specific web pages in a …
- CVE-2020-9664CRITICALCVSS 9.8EG 9.82020-07-22
Magento versions 1.14.4.5 and earlier, and 1.9.4.5 and earlier have a php object injection vulnerability. Successful exploitation could lead to arbitrary code execution.
- CVE-2021-1362HIGHCVSS 8.8EG 8.82021-04-08
A vulnerability in the SOAP API endpoint of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, Cisco Unity Connection, and …
- CVE-2021-1518MEDIUMCVSS 6.3EG 6.32021-07-22
A vulnerability in the REST API of Cisco Firepower Device Manager (FDM) On-Box Software could allow an authenticated, remote attacker to execute arbitrary code on the underlying operating system of an affected device. This vulnerability is…
- CVE-2021-1585HIGHCVSS 7.5EG 8.12021-07-08
A vulnerability in the Cisco Adaptive Security Device Manager (ASDM) Launcher could allow an unauthenticated, remote attacker to execute arbitrary code on a user's operating system. This vulnerability is due to a lack of proper signature v…
- CVE-2021-20187HIGHCVSS 7.2EG 7.22021-01-28
It was found in Moodle before version 3.10.1, 3.9.4, 3.8.7 and 3.5.16 that it was possible for site administrators to execute arbitrary PHP scripts via a PHP include used during Shibboleth authentication.
- CVE-2021-20623CRITICALCVSS 9.8EG 9.82021-02-05
Video Insight VMS versions prior to 7.8 allows a remote attacker to execute arbitrary code with the system user privilege by sending a specially crafted request.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →