CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 58 of 143
- CVE-2021-42315HIGHCVSS 8.8EG 8.82021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2021-42574HIGHCVSS 8.3EG 8.32021-11-01
An issue was discovered in the Bidirectional Algorithm in the Unicode Specification through 14.0. It permits the visual reordering of characters via control sequences, which can be used to craft source code that renders different logic tha…
- CVE-2021-42651HIGHCVSS 8.8EG 8.82022-05-11
A Server Side Template Injection (SSTI) vulnerability in Pentest-Collaboration-Framework v1.0.8 allows an authenticated remote attacker to execute arbitrary code through /project/PROJECTNAME/reports/.
- CVE-2021-42694HIGHCVSS 8.3EG 8.32021-11-01
An issue was discovered in the character definitions of the Unicode Specification through 14.0. The specification allows an adversary to produce source code identifiers such as function names using homoglyphs that render visually identical…
- CVE-2021-42754LOWCVSS 3.2EG 3.22021-11-02
An improper control of generation of code vulnerability [CWE-94] in FortiClientMacOS versions 7.0.0 and below and 6.4.5 and below may allow an authenticated attacker to hijack the MacOS camera without the user permission via the malicious …
- CVE-2021-43097HIGHCVSS 7.2EG 7.22022-03-28
A Server-side Template Injection (SSTI) vulnerability exists in bbs 5.3 in TemplateManageAction.javawhich could let a malicoius user execute arbitrary code.
- CVE-2021-4315MEDIUMCVSS 5.5EG 5.52023-01-28
A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical. This vulnerability affects unknown code of the file psiturk/experiment.py. The manipulation of the argument mode leads to improper neutralization of s…
- CVE-2021-43208HIGHCVSS 7.8EG 7.82021-11-10
3D Viewer Remote Code Execution Vulnerability
- CVE-2021-43214CRITICALCVSS 7.8EG 9.82021-12-15
Web Media Extensions Remote Code Execution Vulnerability
- CVE-2021-43215CRITICALCVSS 9.8EG 9.82021-12-15
iSNS Server Memory Corruption Vulnerability Can Lead to Remote Code Execution
- CVE-2021-43217CRITICALCVSS 8.1EG 9.82021-12-15
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
- CVE-2021-43221MEDIUMCVSS 4.2EG 4.22021-11-24
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
- CVE-2021-43225CRITICALCVSS 7.5EG 9.82021-12-15
Bot Framework SDK Remote Code Execution Vulnerability
- CVE-2021-43232HIGHCVSS 7.8EG 7.82021-12-15
Windows Event Tracing Remote Code Execution Vulnerability
- CVE-2021-43233HIGHCVSS 7.5EG 7.52021-12-15
Remote Desktop Client Remote Code Execution Vulnerability
- CVE-2021-43269HIGHCVSS 8.8EG 8.82022-01-20
In Code42 app before 8.8.0, eval injection allows an attacker to change a device’s proxy configuration to use a malicious proxy auto-config (PAC) file, leading to arbitrary code execution. This affects Incydr Basic, Advanced, and Gov F1;…
- CVE-2021-43281HIGHCVSS 7.2EG 7.22021-11-04
MyBB before 1.8.29 allows Remote Code Injection by an admin with the "Can manage settings?" permission. The Admin CP's Settings management module does not validate setting types correctly on insertion and update, making it possible to add …
- CVE-2021-43466CRITICALCVSS 9.8EG 9.82021-11-09
In the thymeleaf-spring5:3.0.12 component, thymeleaf combined with specific scenarios in template injection may lead to remote code execution.
- CVE-2021-43811HIGHCVSS 7.8EG 7.82021-12-08
Sockeye is an open-source sequence-to-sequence framework for Neural Machine Translation built on PyTorch. Sockeye uses YAML to store model and data configurations on disk. Versions below 2.3.24 use unsafe YAML loading, which can be made to…
- CVE-2021-43837HIGHCVSS 8.4EG 8.42021-12-16
vault-cli is a configurable command-line interface tool (and python library) to interact with Hashicorp Vault. In versions before 3.0.0 vault-cli features the ability for rendering templated values. When a secret starts with the prefix `!t…
- CVE-2021-43882CRITICALCVSS 9.0EG 9.82021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2021-43889HIGHCVSS 7.2EG 7.22021-12-15
Microsoft Defender for IoT Remote Code Execution Vulnerability
- CVE-2021-43891HIGHCVSS 7.8EG 7.82021-12-15
Visual Studio Code Remote Code Execution Vulnerability
- CVE-2021-43899CRITICALCVSS 9.8EG 9.82021-12-15
Microsoft 4K Wireless Display Adapter Remote Code Execution Vulnerability
- CVE-2021-43944HIGHCVSS 7.2EG 7.22022-03-08
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system admin…
- CVE-2021-44231CRITICALCVSS 9.8EG 9.82021-12-14
Internally used text extraction reports allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application.
- CVE-2021-44235MEDIUMCVSS 6.7EG 6.72021-12-14
Two methods of a utility class in SAP NetWeaver AS ABAP - versions 700, 701, 702, 710, 711, 730, 731, 740, 750, 751, 752, 753, 754, 755, 756, allow an attacker with high privileges and has direct access to SAP System, to inject code when e…
- CVE-2021-44238HIGHCVSS 7.2EG 7.22022-03-01
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE) via /aya/module/admin/ust_tab_e.inc.php,
- CVE-2021-4434CRITICALCVSS 10.0EG 10.02024-01-17
The Social Warfare plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 3.5.2 via the 'swp_url' parameter. This allows attackers to execute code on the server.
- CVE-2021-44521CRITICALCVSS 9.1EG 9.12022-02-11
When running Apache Cassandra with the following configuration: enable_user_defined_functions: true enable_scripted_user_defined_functions: true enable_user_defined_functions_threads: false it is possible for an attacker to execute arbitra…
- CVE-2021-44529CRITICALCVSS 9.8EG 9.8⚠ KEV2021-12-08
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).
- CVE-2021-44618CRITICALCVSS 9.8EG 9.82022-03-11
A Server-side Template Injection (SSTI) vulnerability exists in Nystudio107 Seomatic 3.4.12 in src/helpers/UrlHelper.php via the host header.
- CVE-2021-44657HIGHCVSS 8.8EG 8.82021-12-15
In StackStorm versions prior to 3.6.0, the jinja interpreter was not run in sandbox mode and thus allows execution of unsafe system commands. Jinja does not enable sandboxed mode by default due to backwards compatibility. Stackstorm now se…
- CVE-2021-44734CRITICALCVSS 9.8EG 9.82022-01-20
Embedded web server input sanitization vulnerability in Lexmark devices through 2021-12-07, which can which can lead to remote code execution on the device.
- CVE-2021-44978CRITICALCVSS 9.8EG 9.82022-02-04
iCMS <= 8.0.0 allows users to add and render a comtom template, which has a SSTI vulnerability which causes remote code execution.
- CVE-2021-45029CRITICALCVSS 9.8EG 9.82022-01-25
Groovy Code Injection & SpEL Injection which lead to Remote Code Execution. This issue affected Apache ShenYu 2.4.0 and 2.4.1.
- CVE-2021-45655MEDIUMCVSS 6.9EG 6.92021-12-26
NETGEAR R6400 devices before 1.0.1.70 are affected by server-side injection.
- CVE-2021-45656HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, …
- CVE-2021-45657HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects D6200 before 1.1.00.38, D7000 before 1.0.1.78, R6020 before 1.0.0.48, R6080 before 1.0.0.48, R6050 before 1.0.1.26, JR6150 before 1.0.1.26, R6120 before 1.0.0.66, …
- CVE-2021-45659HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45660HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45661HIGHCVSS 7.1EG 7.82021-12-26
Certain NETGEAR devices are affected by server-side injection. This affects RBK40 before 2.5.1.16, RBR40 before 2.5.1.16, RBS40 before 2.5.1.16, RBK20 before 2.5.1.16, RBR20 before 2.5.1.16, RBS20 before 2.5.1.16, RBK50 before 2.5.1.16, RB…
- CVE-2021-45806HIGHCVSS 8.8EG 8.82022-01-13
jpress v4.2.0 admin panel provides a function through which attackers can modify the template and inject some malicious code.
- CVE-2021-45983CRITICALCVSS 9.8EG 9.82022-06-02
NetScout nGeniusONE 6.3.2 allows Java RMI Code Execution.
- CVE-2021-46063CRITICALCVSS 9.1EG 9.12022-02-18
MCMS v5.2.5 was discovered to contain a Server Side Template Injection (SSTI) vulnerability via the Template Management module.
- CVE-2021-46114HIGHCVSS 8.8EG 8.82022-01-26
jpress v 4.2.0 is vulnerable to RCE via io.jpress.module.product.ProductNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
- CVE-2021-46117HIGHCVSS 7.2EG 7.22022-01-26
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.page.PageNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
- CVE-2021-46118HIGHCVSS 7.2EG 7.22022-01-26
jpress 4.2.0 is vulnerable to remote code execution via io.jpress.module.article.kit.ArticleNotifyKit#doSendEmail. The admin panel provides a function through which attackers can edit the email templates and inject some malicious code.
- CVE-2021-46362CRITICALCVSS 9.8EG 9.82022-02-11
A Server-Side Template Injection (SSTI) vulnerability in the Registration and Forgotten Password forms of Magnolia v6.2.3 and below allows attackers to execute arbitrary code via a crafted payload entered into the fullname parameter.
- CVE-2021-47735HIGHCVSS 8.8EG 8.82025-12-23
CMSimple 5.4 contains an authenticated remote code execution vulnerability that allows logged-in attackers to inject malicious PHP code into template files. Attackers can exploit the template editing functionality by crafting a reverse she…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →