CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 55 of 143
- CVE-2021-24942HIGHCVSS 7.2EG 7.22022-12-26
The Menu Item Visibility Control WordPress plugin through 0.5 doesn't sanitize and validate the "Visibility logic" option for WordPress menu items, which could allow highly privileged users to execute arbitrary PHP code even in a hardened …
- CVE-2021-25003CRITICALCVSS 9.8EG 9.82022-03-14
The WPCargo Track & Trace WordPress plugin before 6.9.0 contains a file which could allow unauthenticated attackers to write a PHP file anywhere on the web server, leading to RCE
- CVE-2021-25251HIGHCVSS 7.2EG 7.22021-02-10
The Trend Micro Security 2020 and 2021 families of consumer products are vulnerable to a code injection vulnerability which could allow an attacker to disable the program's password protection and disable protection. An attacker must alrea…
- CVE-2021-25264MEDIUMCVSS 6.7EG 6.72021-05-17
In multiple versions of Sophos Endpoint products for MacOS, a local attacker could execute arbitrary code with administrator privileges.
- CVE-2021-25283CRITICALCVSS 9.8EG 9.82021-02-27
An issue was discovered in through SaltStack Salt before 3002.5. The jinja renderer does not protect against server side template injection attacks.
- CVE-2021-25393MEDIUMCVSS 6.6EG 6.62021-06-11
Improper sanitization of incoming intent in SecSettings prior to SMR MAY-2021 Release 1 allows local attackers to get permissions to access system uid data.
- CVE-2021-25411MEDIUMCVSS 4.4EG 4.42021-06-11
Improper address validation vulnerability in RKP api prior to SMR JUN-2021 Release 1 allows root privileged local attackers to write read-only kernel memory.
- CVE-2021-25415MEDIUMCVSS 5.5EG 5.52021-06-11
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to remap EL2 memory as writable.
- CVE-2021-25416MEDIUMCVSS 6.5EG 6.52021-06-11
Assuming EL1 is compromised, an improper address validation in RKP prior to SMR JUN-2021 Release 1 allows local attackers to create executable kernel page outside code area.
- CVE-2021-25470HIGHCVSS 7.9EG 7.92021-10-06
An improper caller check logic of SMC call in TEEGRIS secure OS prior to SMR Oct-2021 Release 1 can be used to compromise TEE.
- CVE-2021-25654HIGHCVSS 6.2EG 7.82021-06-25
An arbitrary code execution vulnerability was discovered in Avaya Aura Device Services that may potentially allow a local user to execute specially crafted scripts. Affects 7.0 through 8.1.4.0 versions of Avaya Aura Device Services.
- CVE-2021-25770CRITICALCVSS 9.8EG 9.82021-02-03
In JetBrains YouTrack before 2020.5.3123, server-side template injection (SSTI) was possible, which could lead to code execution.
- CVE-2021-25808HIGHCVSS 7.8EG 7.82021-07-23
A code injection vulnerability in backup/plugin.php of Bludit 3.13.1 allows attackers to execute arbitrary code via a crafted ZIP file.
- CVE-2021-25877HIGHCVSS 7.2EG 7.22021-11-01
AVideo/YouPHPTube 10.0 and prior is affected by Insecure file write. An administrator privileged user is able to write files on filesystem using flag and code variables in file save.php.
- CVE-2021-26120CRITICALCVSS 9.8EG 9.82021-02-22
Smarty before 3.1.39 allows code injection via an unexpected function name after a {function name= substring.
- CVE-2021-26277CRITICALCVSS 5.6EG 9.82023-02-17
The framework service handles pendingIntent incorrectly, allowing a malicious application with certain privileges to perform privileged actions.
- CVE-2021-26551HIGHCVSS 8.8EG 8.82021-02-09
An issue was discovered in SmartFoxServer 2.17.0. An attacker can execute arbitrary Python code, and bypass the javashell.py protection mechanism, by creating /config/ConsoleModuleUnlock.txt and editing /config/admin/admintool.xml to enabl…
- CVE-2021-26622CRITICALCVSS 9.6EG 10.02022-03-25
An remote code execution vulnerability due to SSTI vulnerability and insufficient file name parameter validation was discovered in Genian NAC. Remote attackers are able to execute arbitrary malicious code with SYSTEM privileges on all conn…
- CVE-2021-26727CRITICALCVSS 10.0EG 10.02022-10-24
Multiple command injections and stack-based buffer overflows vulnerabilities in the SubNet_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue …
- CVE-2021-26728CRITICALCVSS 10.0EG 10.02022-10-24
Command injection and stack-based buffer overflow vulnerabilities in the KillDupUsr_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue affects: Lanner…
- CVE-2021-26729CRITICALCVSS 10.0EG 10.02022-10-24
Command injection and multiple stack-based buffer overflows vulnerabilities in the Login_handler_func function of spx_restservice allow an attacker to execute arbitrary code with the same privileges as the server user (root). This issue af…
- CVE-2021-26731CRITICALCVSS 9.1EG 9.82022-10-24
Command injection and multiple stack-based buffer overflows vulnerabilities in the modifyUserb_func function of spx_restservice allow an authenticated attacker to execute arbitrary code with the same privileges as the server user (root). T…
- CVE-2021-26753CRITICALCVSS 9.9EG 9.92021-02-12
NeDi 1.9C allows an authenticated user to inject PHP code in the System Files function on the endpoint /System-Files.php via the txt HTTP POST parameter. This allows an attacker to obtain access to the operating system where NeDi is instal…
- CVE-2021-26810CRITICALCVSS 9.8EG 9.82021-03-30
D-link DIR-816 A2 v1.10 is affected by a remote code injection vulnerability. An HTTP request parameter can be used in command string construction in the handler function of the /goform/dir_setWanWifi, which can lead to command injection v…
- CVE-2021-26876HIGHCVSS 8.8EG 8.82021-03-11
OpenType Font Parsing Remote Code Execution Vulnerability
- CVE-2021-26877CRITICALCVSS 9.8EG 9.82021-03-11
Windows DNS Server Remote Code Execution Vulnerability
- CVE-2021-26890HIGHCVSS 7.8EG 7.82021-03-11
Application Virtualization Remote Code Execution Vulnerability
- CVE-2021-27230HIGHCVSS 8.8EG 8.82021-03-15
ExpressionEngine before 5.4.2 and 6.x before 6.0.3 allows PHP Code Injection by certain authenticated users who can leverage Translate::save() to write to an _lang.php file under the system/user/language directory.
- CVE-2021-27236CRITICALCVSS 9.8EG 9.82021-02-16
An issue was discovered in Mutare Voice (EVM) 3.x before 3.3.8. getfile.asp allows Unauthenticated Local File Inclusion, which can be leveraged to achieve Remote Code Execution.
- CVE-2021-27438HIGHCVSS 8.8EG 8.82021-03-25
The software contains a hard-coded password it uses for its own inbound authentication or for outbound communication to external components on the Reason DR60 (all firmware versions prior to 02A04.1).
- CVE-2021-27446CRITICALCVSS 10.0EG 10.02022-05-16
The Weintek cMT product line is vulnerable to code injection, which may allow an unauthenticated remote attacker to execute commands with root privileges on the operation system.
- CVE-2021-27602CRITICALCVSS 9.9EG 9.92021-04-13
SAP Commerce, versions - 1808, 1811, 1905, 2005, 2011, Backoffice application allows certain authorized users to create source rules which are translated to drools rule when published to certain modules within the application. An attacker …
- CVE-2021-27611MEDIUMCVSS 6.7EG 6.72021-05-11
SAP NetWeaver AS ABAP, versions - 700, 701, 702, 730, 731, allow a high privileged attacker to inject malicious code by executing an ABAP report when the attacker has access to the local SAP system. The attacker could then get access to da…
- CVE-2021-27811HIGHCVSS 7.2EG 7.22021-05-21
A code injection vulnerability has been discovered in the Upgrade function of QibosoftX1 v1.0. An attacker is able execute arbitrary PHP code via exploitation of client_upgrade_edition.php and Upgrade.php.
- CVE-2021-27928HIGHCVSS 7.2EG 7.52021-03-19
A remote code execution issue was discovered in MariaDB 10.2 before 10.2.37, 10.3 before 10.3.28, 10.4 before 10.4.18, and 10.5 before 10.5.9; Percona Server through 2021-03-03; and the wsrep patch through 2021-03-03 for MySQL. An untruste…
- CVE-2021-28953HIGHCVSS 7.8EG 7.82021-03-21
The unofficial C/C++ Advanced Lint extension before 1.9.0 for Visual Studio Code allows attackers to execute arbitrary binaries if the user opens a crafted repository.
- CVE-2021-28954HIGHCVSS 7.8EG 7.82021-03-21
In Chris Walz bit before 1.0.5 on Windows, attackers can run arbitrary code via a .exe file in a crafted repository.
- CVE-2021-29113MEDIUMCVSS 4.7EG 4.72021-12-07
A remote file inclusion vulnerability in the ArcGIS Server help documentation may allow a remote, unauthenticated attacker to inject attacker supplied html into a page.
- CVE-2021-29214HIGHCVSS 7.2EG 7.22021-12-10
A security vulnerability has been identified in HPE StoreServ Management Console (SSMC). An authenticated SSMC administrator could exploit the vulnerability to inject code and elevate their privilege in SSMC. The scope of this vulnerabilit…
- CVE-2021-29440HIGHCVSS 8.4EG 8.42021-04-13
Grav is a file based Web-platform. Twig processing of static pages can be enabled in the front matter by any administrative user allowed to create or edit pages. As the Twig processor runs unsandboxed, this behavior can be used to gain arb…
- CVE-2021-29461HIGHCVSS 8.1EG 8.12021-04-20
Discord Recon Server is a bot that allows one to do one's reconnaissance process from one's Discord. A vulnerability in Discord Recon Server prior to 0.0.3 could be exploited to read internal files from the system and write files into the …
- CVE-2021-29465HIGHCVSS 8.3EG 8.32021-04-22
Discord-Recon is a bot for the Discord chat service. Versions of Discord-Recon 0.0.3 and prior contain a vulnerability in which a remote attacker is able to overwrite any file on the system with the command results. This can result in remo…
- CVE-2021-29472HIGHCVSS 8.8EG 8.82021-04-27
Composer is a dependency manager for PHP. URLs for Mercurial repositories in the root composer.json and package source download URLs are not sanitized correctly. Specifically crafted URL values allow code to be executed in the HgDriver if …
- CVE-2021-29475CRITICALCVSS 10.0EG 10.02021-04-26
HedgeDoc (formerly known as CodiMD) is an open-source collaborative markdown editor. An attacker is able to receive arbitrary files from the file system when exporting a note to PDF. Since the code injection has to take place as note conte…
- CVE-2021-29493MEDIUMCVSS 6.5EG 6.52021-05-06
Kennnyshiwa-cogs contains cogs for Red Discordbot. An RCE exploit has been found in the Tickets module of kennnyshiwa-cogs. This exploit allows discord users to craft a message that can reveal sensitive and harmful information. Users can u…
- CVE-2021-29502HIGHCVSS 7.3EG 7.32021-05-10
WarnSystem is a cog (plugin) for the Red discord bot. A vulnerability has been found in the code that allows any user to access sensible informations by setting up a specific template which is not properly sanitized. The problem has been p…
- CVE-2021-29505HIGHCVSS 7.5EG 8.82021-05-28
XStream is software for serializing Java objects to XML and back again. A vulnerability in XStream versions prior to 1.4.17 may allow a remote attacker has sufficient rights to execute commands of the host only by manipulating the processe…
- CVE-2021-29679HIGHCVSS 8.8EG 8.82021-10-15
IBM Cognos Analytics 11.1.7 and 11.2.0 could allow an authenticated user to execute code remotely due to incorrectly neutralizaing user-contrlled input that could be interpreted a a server-side include (SSI) directive. IBM X-Force ID: 1999…
- CVE-2021-29772CRITICALCVSS 9.8EG 9.82021-08-26
IBM API Connect 5.0.0.0 through 5.0.8.11 could allow a user to potentially inject code due to unsanitized user input. IBM X-Force ID: 202774.
- CVE-2021-30005HIGHCVSS 7.8EG 7.82021-05-11
In JetBrains PyCharm before 2020.3.4, local code execution was possible because of insufficient checks when getting the project from VCS.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →