CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 59 of 143
- CVE-2021-47736HIGHCVSS 7.2EG 8.82025-12-23
CMSimple_XH 1.7.4 contains an authenticated remote code execution vulnerability in the content editing functionality that allows administrative users to upload malicious PHP files. Attackers with valid credentials can exploit the CSRF toke…
- CVE-2021-47770HIGHCVSS 8.8EG 8.82026-01-21
OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with …
- CVE-2021-47778HIGHCVSS 8.6EG 8.62026-01-21
GetSimple CMS My SMTP Contact Plugin 1.1.2 contains a PHP code injection vulnerability. An authenticated administrator can inject arbitrary PHP code through plugin configuration parameters, leading to remote code execution on the server.
- CVE-2021-47935HIGHCVSS 8.8EG 8.82026-05-10
Sentry 8.2.0 contains a remote code execution vulnerability that allows authenticated superusers to execute arbitrary commands by injecting malicious pickle-serialized objects through the audit log entry data parameter. Attackers can submi…
- CVE-2021-47938HIGHCVSS 8.8EG 8.82026-05-10
ImpressCMS 1.4.2 contains a remote code execution vulnerability in the autotasks administrative interface that allows authenticated attackers to execute arbitrary PHP code by injecting malicious code into the sat_code parameter. Attackers …
- CVE-2021-47939HIGHCVSS 8.8EG 8.82026-05-10
Evolution CMS 3.1.6 contains a remote code execution vulnerability that allows authenticated users with module creation permissions to execute arbitrary system commands by injecting PHP code into module parameters. Attackers can send POST …
- CVE-2021-47952CRITICALCVSS 9.8EG 9.82026-05-16
python jsonpickle 2.0.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary Python commands by deserializing malicious JSON payloads containing py/repr objects. Attackers can craft JSON strings with py…
- CVE-2021-47964HIGHCVSS 8.8EG 8.82026-05-15
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager. Attackers can upload a crafted ZIP fil…
- CVE-2022-0130HIGHCVSS 8.1EG 8.12022-01-14
Tenable.sc versions 5.14.0 through 5.19.1 were found to contain a remote code execution vulnerability which could allow a remote, unauthenticated attacker to execute code under special circumstances. An attacker would first have to stage a…
- CVE-2022-0323HIGHCVSS 8.8EG 8.82022-01-21
Improper Neutralization of Special Elements Used in a Template Engine in Packagist mustache/mustache prior to 2.14.1.
- CVE-2022-0354HIGHCVSS 7.8EG 7.82022-04-22
A vulnerability was reported in Lenovo System Update that could allow a local user with interactive system access the ability to execute code with elevated privileges only during the installation of a System Update package released before …
- CVE-2022-0440HIGHCVSS 7.2EG 7.22022-03-07
The Catch Themes Demo Import WordPress plugin before 2.1.1 does not validate one of the file to be imported, which could allow high privivilege admin to upload an arbitrary PHP file and gain RCE even in the case of an hardened blog (ie DIS…
- CVE-2022-0578MEDIUMCVSS 6.5EG 6.52022-05-16
Code Injection in GitHub repository publify/publify prior to 9.2.8.
- CVE-2022-0661HIGHCVSS 7.2EG 7.52022-04-18
The Ad Injection WordPress plugin through 1.2.0.19 does not properly sanitize the body of the adverts injected into the pages, allowing a high privileged user (Admin+) to inject arbitrary HTML or javascript even with unfiltered_html disall…
- CVE-2022-0687HIGHCVSS 8.8EG 8.82022-03-21
The Amelia WordPress plugin before 1.0.47 stores image blobs into actual files whose extension is controlled by the user, which may lead to PHP backdoors being uploaded onto the site. This vulnerability can be exploited by logged-in users …
- CVE-2022-0811HIGHCVSS 8.8EG 8.82022-03-16
A flaw was found in CRI-O in the way it set kernel options for a pod. This issue allows anyone with rights to deploy a pod on a Kubernetes cluster that uses the CRI-O runtime to achieve a container escape and arbitrary code execution as ro…
- CVE-2022-0819HIGHCVSS 8.8EG 8.82022-03-02
Code Injection in GitHub repository dolibarr/dolibarr prior to 15.0.1.
- CVE-2022-0845CRITICALCVSS 9.8EG 9.82022-03-05
Code Injection in GitHub repository pytorchlightning/pytorch-lightning prior to 1.6.0.
- CVE-2022-0863HIGHCVSS 7.2EG 7.22022-06-13
The WP SVG Icons WordPress plugin through 3.2.3 does not properly validate uploaded custom icon packs, allowing an high privileged user like an admin to upload a zip file containing malicious php code, leading to remote code execution.
- CVE-2022-0885CRITICALCVSS 9.8EG 9.82022-06-13
The Member Hero WordPress plugin through 1.0.9 lacks authorization checks, and does not validate the a request parameter in an AJAX action, allowing unauthenticated users to call arbitrary PHP functions with no arguments.
- CVE-2022-0896HIGHCVSS 8.8EG 8.82022-03-09
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository microweber/microweber prior to 1.3.
- CVE-2022-0921MEDIUMCVSS 6.7EG 6.72022-03-11
Abusing Backup/Restore feature to achieve Remote Code Execution in GitHub repository microweber/microweber prior to 1.2.12.
- CVE-2022-0944HIGHCVSS 7.2EG 7.22022-03-15
Template injection in connection test endpoint leads to RCE in GitHub repository sqlpad/sqlpad prior to 6.10.1.
- CVE-2022-1159HIGHCVSS 7.7EG 7.72022-04-01
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.
- CVE-2022-1517CRITICALCVSS 10.0EG 10.02022-06-24
LRM utilizes elevated privileges. An unauthenticated malicious actor can upload and execute code remotely at the operating system level, which can allow an attacker to change settings, configurations, software, or access sensitive data on …
- CVE-2022-1575CRITICALCVSS 9.6EG 9.62022-05-05
Arbitrary Code Execution through Sanitizer Bypass in GitHub repository jgraph/drawio prior to 18.0.0. - Arbitrary (remote) code execution in the desktop app. - Stored XSS in the web app.
- CVE-2022-1609CRITICALCVSS 9.8EG 9.82024-01-16
The School Management WordPress plugin before 9.9.7 contains an obfuscated backdoor injected in it's license checking code that registers a REST API handler, allowing an unauthenticated attacker to execute arbitrary PHP code on the site.
- CVE-2022-2014MEDIUMCVSS 5.4EG 5.42022-06-09
Code Injection in GitHub repository jgraph/drawio prior to 19.0.2.
- CVE-2022-2054HIGHCVSS 8.4EG 8.42022-06-12
Code Injection in GitHub repository nuitka/nuitka prior to 0.9.
- CVE-2022-20686MEDIUMCVSS 5.3EG 5.32022-12-12
Multiple vulnerabilities in the Link Layer Discovery Protocol (LLDP) functionality of Cisco ATA 190 Series Analog Telephone Adapter firmware could allow an unauthenticated, remote attacker to execute arbitrary code on an affected device an…
- CVE-2022-2073HIGHCVSS 7.2EG 7.22022-06-29
Code Injection in GitHub repository getgrav/grav prior to 1.7.34.
- CVE-2022-21122CRITICALCVSS 9.0EG 9.02022-06-08
The package metacalc before 0.0.2 are vulnerable to Arbitrary Code Execution when it exposes JavaScript's Math class to the v8 context. As the Math class is exposed to user-land, it can be used to get access to JavaScript's Function constr…
- CVE-2022-21167HIGHCVSS 7.5EG 7.52022-05-01
All versions of package masuit.tools.core are vulnerable to Arbitrary Code Execution via the ReceiveVarData<T> function in the SocketClient.cs component. The socket client in the package can pass in the payload via the user-controllable in…
- CVE-2022-21686CRITICALCVSS 9.0EG 9.02022-01-26
PrestaShop is an Open Source e-commerce platform. Starting with version 1.7.0.0 and ending with version 1.7.8.3, an attacker is able to inject twig code inside the back office when using the legacy layout. The problem is fixed in version 1…
- CVE-2022-21797HIGHCVSS 7.3EG 7.32022-09-26
The package joblib from 0 and before 1.2.0 are vulnerable to Arbitrary Code Execution via the pre_dispatch flag in Parallel() class due to the eval() statement.
- CVE-2022-21831CRITICALCVSS 9.8EG 9.82022-05-26
A code injection vulnerability exists in the Active Storage >= v5.2.0 that could allow an attacker to execute code via image_processing arguments.
- CVE-2022-21837HIGHCVSS 8.3EG 8.82022-01-11
Microsoft SharePoint Server Remote Code Execution Vulnerability
- CVE-2022-21842HIGHCVSS 7.8EG 7.82022-01-11
Microsoft Word Remote Code Execution Vulnerability
- CVE-2022-21846CRITICALCVSS 9.0EG 9.02022-01-11
Microsoft Exchange Server Remote Code Execution Vulnerability
- CVE-2022-21874CRITICALCVSS 7.8EG 9.82022-01-11
Windows Security Center API Remote Code Execution Vulnerability
- CVE-2022-21878HIGHCVSS 7.8EG 7.82022-01-11
Windows Geolocation Service Remote Code Execution Vulnerability
- CVE-2022-21917HIGHCVSS 7.8EG 7.82022-01-11
HEVC Video Extensions Remote Code Execution Vulnerability
- CVE-2022-21928MEDIUMCVSS 6.3EG 6.42022-01-11
Windows Resilient File System (ReFS) Remote Code Execution Vulnerability
- CVE-2022-22027HIGHCVSS 7.8EG 7.82022-07-12
Windows Fax Service Remote Code Execution Vulnerability
- CVE-2022-22029HIGHCVSS 8.1EG 8.12022-07-12
Windows Network File System Remote Code Execution Vulnerability
- CVE-2022-22038HIGHCVSS 8.1EG 8.12022-07-12
Remote Procedure Call Runtime Remote Code Execution Vulnerability
- CVE-2022-22039HIGHCVSS 7.5EG 7.52022-07-12
Windows Network File System Remote Code Execution Vulnerability
- CVE-2022-22270MEDIUMCVSS 4.4EG 4.42022-01-10
An implicit Intent hijacking vulnerability in Dialer prior to SMR Jan-2022 Release 1 allows unprivileged applications to access contact information.
- CVE-2022-22285MEDIUMCVSS 4.4EG 4.42022-01-10
A vulnerability using PendingIntent in Reminder prior to version 12.2.05.0 in Android R(11.0) and 12.3.02.1000 in Android S(12.0) allows attackers to execute privileged action by hijacking and modifying the intent.
- CVE-2022-22286MEDIUMCVSS 4.4EG 4.42022-01-10
A vulnerability using PendingIntent in Bixby Routines prior to version 3.1.21.8 in Android R(11.0) and 2.6.30.5 in Android Q(10.0) allows attackers to execute privileged action by hijacking and modifying the intent.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →