CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 56 of 143
- CVE-2021-30461CRITICALCVSS 9.8EG 9.82021-05-29
A remote code execution issue was discovered in the web UI of VoIPmonitor before 24.61. When the recheck option is used, the user-supplied SPOOLDIR value (which might contain PHP code) is injected into config/configuration.php.
- CVE-2021-3115HIGHCVSS 7.5EG 7.52021-01-26
Go before 1.14.14 and 1.15.x before 1.15.7 on Windows is vulnerable to Command Injection and remote code execution when using the "go get" command to fetch modules that make use of cgo (for example, cgo can execute a gcc program from an un…
- CVE-2021-31181HIGHCVSS 8.8EG 8.82021-05-11
Microsoft SharePoint Remote Code Execution Vulnerability
- CVE-2021-31198HIGHCVSS 7.8EG 7.82021-05-11
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2021-31630HIGHCVSS 8.8EG 8.82021-08-03
Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application.
- CVE-2021-31635CRITICALCVSS 9.8EG 9.82023-06-26
Server-Side Template Injection (SSTI) vulnerability in jFinal v.4.9.08 allows a remote attacker to execute arbitrary code via the template function.
- CVE-2021-31949HIGHCVSS 7.3EG 7.32021-06-08
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2021-32621HIGHCVSS 8.8EG 8.82021-05-28
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. In versions prior to 12.6.7 and 12.10.3, a user without Script or Programming right is able to execute script requiring privileges by …
- CVE-2021-32649HIGHCVSS 8.8EG 8.82022-01-14
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with "create, modify and delete website pages" privileges in the backend is able to …
- CVE-2021-32650HIGHCVSS 8.8EG 8.82022-01-14
October CMS is a self-hosted content management system (CMS) platform based on the Laravel PHP Framework. Prior to versions 1.0.473 and 1.1.6, an attacker with access to the backend is able to execute PHP code by using the theme import fea…
- CVE-2021-3267HIGHCVSS 7.2EG 7.22023-04-04
File Upload vulnerability found in KiteCMS v.1.1 allows a remote attacker to execute arbitrary code via the uploadFile function.
- CVE-2021-32673HIGHCVSS 8.8EG 8.82021-06-08
reg-keygen-git-hash-plugin is a reg-suit plugin to detect the snapshot key to be compare with using Git commit hash. reg-keygen-git-hash-plugin through and including 0.10.15 allow remote attackers to execute of arbitrary commands. Upgrade …
- CVE-2021-32706HIGHCVSS 7.6EG 8.42021-08-04
Pi-hole's Web interface provides a central location to manage a Pi-hole instance and review performance statistics. Prior to Pi-hole Web interface version 5.5.1, the `validDomainWildcard` preg_match filter allows a malicious character thro…
- CVE-2021-3273HIGHCVSS 7.2EG 7.22021-02-25
Nagios XI below 5.7 is affected by code injection in the /nagiosxi/admin/graphtemplates.php component. To exploit this vulnerability, someone must have an admin user account in Nagios XI's web system.
- CVE-2021-32749MEDIUMCVSS 6.1EG 6.12021-07-16
fail2ban is a daemon to ban hosts that cause multiple authentication errors. In versions 0.9.7 and prior, 0.10.0 through 0.10.6, and 0.11.0 through 0.11.2, there is a vulnerability that leads to possible remote code execution in the mailin…
- CVE-2021-32756HIGHCVSS 8.8EG 8.82021-07-21
ManageIQ is an open-source management platform. In versions prior to jansa-4, kasparov-2, and lasker-1, there is a flaw in the MiqExpression module of ManageIQ where a low privilege user could enter a crafted Ruby string which would be eva…
- CVE-2021-32809MEDIUMCVSS 4.6EG 4.62021-08-12
ckeditor is an open source WYSIWYG HTML editor with rich content support. A potential vulnerability has been discovered in CKEditor 4 [Clipboard](https://ckeditor.com/cke4/addon/clipboard) package. The vulnerability allowed to abuse paste …
- CVE-2021-32817MEDIUMCVSS 5.4EG 5.42021-05-14
express-hbs is an Express handlebars template engine. express-hbs mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure vulnerabilitie…
- CVE-2021-32820HIGHCVSS 8.6EG 8.62021-05-14
Express-handlebars is a Handlebars view engine for Express. Express-handlebars mixes pure template data with engine configuration options through the Express render API. More specifically, the layout parameter may trigger file disclosure v…
- CVE-2021-32822MEDIUMCVSS 4.0EG 4.02021-08-16
The npm hbs package is an Express view engine wrapper for Handlebars. Depending on usage, users of hbs may be vulnerable to a file disclosure vulnerability. There is currently no patch for this vulnerability. hbs mixes pure template data w…
- CVE-2021-32829CRITICALCVSS 9.6EG 9.92021-08-17
ZStack is open source IaaS(infrastructure as a service) software aiming to automate datacenters, managing resources of compute, storage, and networking all by APIs. Affected versions of ZStack REST API are vulnerable to post-authentication…
- CVE-2021-32831HIGHCVSS 7.5EG 7.52021-08-30
Total.js framework (npm package total.js) is a framework for Node.js platfrom written in pure JavaScript similar to PHP's Laravel or Python's Django or ASP.NET MVC. In total.js framework before version 3.4.9, calling the utils.set function…
- CVE-2021-32834CRITICALCVSS 8.2EG 9.92021-09-09
Eclipse Keti is a service that was designed to protect RESTfuls API using Attribute Based Access Control (ABAC). In Keti a user able to create Policy Sets can run arbitrary code by sending malicious Groovy scripts which will escape the con…
- CVE-2021-32836HIGHCVSS 7.5EG 8.12021-09-09
ZStack is open source IaaS(infrastructure as a service) software. In ZStack before versions 3.10.12 and 4.1.6 there is a pre-auth unsafe deserialization vulnerability in the REST API. An attacker in control of the request body will be able…
- CVE-2021-32924HIGHCVSS 8.8EG 8.82021-06-01
Invision Community (aka IPS Community Suite) before 4.6.0 allows eval-based PHP code injection by a moderator because the IPS\cms\modules\front\pages\_builder::previewBlock method interacts unsafely with the IPS\_Theme::runProcessFunction …
- CVE-2021-33493MEDIUMCVSS 6.0EG 6.02021-11-22
The middleware component in OX App Suite through 7.10.5 allows Code Injection via Java classes in a YAML format.
- CVE-2021-33635CRITICALCVSS 9.8EG 9.82023-10-29
When malicious images are pulled by isula pull, attackers can execute arbitrary code.
- CVE-2021-33636HIGHCVSS 8.4EG 8.42023-10-29
When the isula load command is used to load malicious images, attackers can execute arbitrary code.
- CVE-2021-33678MEDIUMCVSS 6.5EG 6.52021-07-14
A function module of SAP NetWeaver AS ABAP (Reconciliation Framework), versions - 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 75A, 75B, 75B, 75C, 75D, 75E, 75F, allows a high privileged attacker to inject code that can be execut…
- CVE-2021-33693MEDIUMCVSS 6.8EG 6.82021-09-15
SAP Cloud Connector, version - 2.0, allows an authenticated administrator to modify a configuration file to inject malicious codes that could potentially lead to OS command execution.
- CVE-2021-33816CRITICALCVSS 9.8EG 9.82021-11-10
The website builder module in Dolibarr 13.0.2 allows remote PHP code execution because of an incomplete protection mechanism in which system, exec, and shell_exec are blocked but backticks are not blocked.
- CVE-2021-33911CRITICALCVSS 9.8EG 9.82021-07-17
Zoho ManageEngine ADManager Plus before 7110 allows remote code execution.
- CVE-2021-33949CRITICALCVSS 9.8EG 9.82023-02-17
An issue in FeMiner WMS v1.1 allows attackers to execute arbitrary code via the filename parameter and the exec function.
- CVE-2021-3411MEDIUMCVSS 6.7EG 6.72021-03-09
A flaw was found in the Linux kernel in versions prior to 5.10. A violation of memory access was found while detecting a padding of int3 in the linking state. The highest threat from this vulnerability is to data confidentiality and integr…
- CVE-2021-34801MEDIUMCVSS 5.3EG 5.32021-06-16
Valine 1.4.14 allows remote attackers to cause a denial of service (application outage) by supplying a ua (aka User-Agent) value that only specifies the product and version.
- CVE-2021-34994HIGHCVSS 8.8EG 8.82022-01-13
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Commvault CommCell 11.22.22. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be …
- CVE-2021-35413HIGHCVSS 8.8EG 8.82021-12-03
A remote code execution (RCE) vulnerability in course_intro_pdf_import.php of Chamilo LMS v1.11.x allows authenticated attackers to execute arbitrary code via a crafted .htaccess file.
- CVE-2021-35514CRITICALCVSS 9.8EG 9.82021-06-28
Narou (aka Narou.rb) before 3.8.0 allows Ruby Code Injection via the title name or author name of a novel.
- CVE-2021-3583HIGHCVSS 7.1EG 7.12021-09-22
A flaw was found in Ansible, where a user's controller is vulnerable to template injection. This issue can occur through facts used in the template if the user is trying to put templates in multi-line YAML strings and the facts being handl…
- CVE-2021-3615MEDIUMCVSS 6.6EG 6.82021-08-17
A vulnerability was reported in Lenovo Smart Camera X3, X5, and C2E that could allow code execution if a specific file exists on the attached SD card. This vulnerability is the same as CNVD-2021-45262.
- CVE-2021-36394CRITICALCVSS 9.8EG 9.82023-03-06
In Moodle, a remote code execution risk was identified in the Shibboleth authentication plugin.
- CVE-2021-36424CRITICALCVSS 9.8EG 9.82023-02-03
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
- CVE-2021-3661HIGHCVSS 8.4EG 8.42022-12-12
A potential security vulnerability has been identified in certain HP Workstation BIOS (UEFI firmware) which may allow arbitrary code execution. HP is releasing firmware mitigations for the potential vulnerability.
- CVE-2021-36800HIGHCVSS 8.7EG 8.72021-08-04
Akaunting version 2.1.12 and earlier suffers from a code injection issue in the Money.php component of the application. A POST sent to /{company_id}/sales/invoices/{invoice_id} with an items[0][price] that includes a PHP callable function …
- CVE-2021-36985HIGHCVSS 7.5EG 7.52021-10-28
There is a Code injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may exhaust system resources and cause the system to restart.
- CVE-2021-37079CRITICALCVSS 9.1EG 9.12021-12-07
There is a Improper Input Validation vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to delete arbitrary file by system_app permission.
- CVE-2021-37097HIGHCVSS 7.5EG 7.52021-12-08
There is a Code Injection vulnerability in Huawei Smartphone.Successful exploitation of this vulnerability may lead to system restart.
- CVE-2021-3725HIGHCVSS 7.5EG 8.82021-11-30
Vulnerability in dirhistory plugin Description: the widgets that go back and forward in the directory history, triggered by pressing Alt-Left and Alt-Right, use functions that unsafely execute eval on directory names. If you cd into a dire…
- CVE-2021-37384CRITICALCVSS 9.8EG 9.82023-07-17
RCE (Remote Code Execution) vulnerability was found in some Furukawa ONU models, this vulnerability allows remote unauthenticated users to send arbitrary commands to the device via web interface.
- CVE-2021-37626HIGHCVSS 7.2EG 7.22021-08-11
Contao is an open source CMS that allows you to create websites and scalable web applications. In affected versions it is possible to load PHP files by entering insert tags in the Contao back end. Installations are only affected if they ha…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →