CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 61 of 143
- CVE-2022-25926HIGHCVSS 7.4EG 7.42023-01-04
Versions of the package window-control before 1.4.5 are vulnerable to Command Injection via the sendKeys function, due to improper input sanitization.
- CVE-2022-25967HIGHCVSS 8.1EG 8.12023-01-30
Versions of the package eta before 2.0.0 are vulnerable to Remote Code Execution (RCE) by overwriting template engine configuration variables with view options received from The Express render API. **Note:** This is exploitable only for u…
- CVE-2022-26112CRITICALCVSS 9.8EG 9.82022-09-23
In 0.10.0 or older versions of Apache Pinot, Pinot query endpoint and realtime ingestion layer has a vulnerability in unprotected environments due to a groovy function support. In order to avoid this, we disabled the groovy function suppor…
- CVE-2022-26174CRITICALCVSS 9.8EG 9.82022-03-21
A remote code execution (RCE) vulnerability in Beekeeper Studio v3.2.0 allows attackers to execute arbitrary code via a crafted payload injected into the display fields.
- CVE-2022-26198CRITICALCVSS 9.8EG 9.82022-03-27
Notable v1.8.4 does not filter text editing, allowing attackers to execute arbitrary code via a crafted payload injected into the Title text field.
- CVE-2022-26205CRITICALCVSS 9.8EG 9.82022-03-27
Marky commit 3686565726c65756e was discovered to contain a remote code execution (RCE) vulnerability via the Display text fields. This vulnerability allows attackers to execute arbitrary code via injection of a crafted payload.
- CVE-2022-26255CRITICALCVSS 9.8EG 9.82022-03-28
Clash for Windows v0.19.8 was discovered to allow arbitrary code execution via a crafted payload injected into the Proxies name column.
- CVE-2022-26272CRITICALCVSS 9.8EG 9.82022-03-24
A remote code execution (RCE) vulnerability in Ionize v1.0.8.1 allows attackers to execute arbitrary code via a crafted string written to the file application/config/config.php.
- CVE-2022-2636HIGHCVSS 8.5EG 8.82022-08-05
Improper Control of Generation of Code ('Code Injection') in GitHub repository hestiacp/hestiacp prior to 1.6.6.
- CVE-2022-26982HIGHCVSS 7.2EG 7.22022-04-05
SimpleMachinesForum 2.1.1 and earlier allows remote authenticated administrators to execute arbitrary code by inserting a vulnerable php code because the themes can be modified by an administrator. NOTE: the vendor's position is that admin…
- CVE-2022-27537HIGHCVSS 7.8EG 7.82023-02-01
Potential vulnerabilities have been identified in the system BIOS of certain HP PC products, which might allow arbitrary code execution, escalation of privilege, denial of service, and information disclosure. HP is releasing BIOS updates t…
- CVE-2022-27837HIGHCVSS 4.4EG 7.82022-04-11
A vulnerability using PendingIntent in Accessibility prior to version 12.5.3.2 in Android R(11.0) and 13.0.1.1 in Android S(12.0) allows attacker to access the file with system privilege.
- CVE-2022-28096HIGHCVSS 7.2EG 7.22022-05-04
Skycaiji v2.4 was discovered to contain a remote code execution (RCE) vulnerability via /SkycaijiApp/admin/controller/Develop.php.
- CVE-2022-28640HIGHCVSS 8.8EG 8.82022-09-20
A potential local adjacent arbitrary code execution vulnerability that could potentially lead to a loss of confidentiality, integrity, and availability was discovered in HPE Integrated Lights-Out 5 (iLO 5) in Version: 2.71. Hewlett Packard…
- CVE-2022-28766HIGHCVSS 3.3EG 7.32022-11-17
Windows 32-bit versions of the Zoom Client for Meetings before 5.12.6 and Zoom Rooms for Conference Room before version 5.12.6 are susceptible to a DLL injection vulnerability. A local low-privileged user could exploit this vulnerability t…
- CVE-2022-28960HIGHCVSS 8.8EG 8.82022-05-19
A PHP injection vulnerability in Spip before v3.2.8 allows attackers to execute arbitrary PHP code via the _oups parameter at /ecrire.
- CVE-2022-29078CRITICALCVSS 9.8EG 9.82022-04-25
The ejs (aka Embedded JavaScript templates) package 3.1.6 for Node.js allows server-side template injection in settings[view options][outputFunctionName]. This is parsed as an internal option, and overwrites the outputFunctionName option w…
- CVE-2022-29115HIGHCVSS 7.8EG 7.82022-05-10
Windows Fax Service Remote Code Execution Vulnerability
- CVE-2022-29171MEDIUMCVSS 6.6EG 6.62022-05-06
Sourcegraph is a fast and featureful code search and navigation engine. Versions before 3.38.0 are vulnerable to Remote Code Execution in the gitserver service. The Gitolite code host integration with Phabricator allows Sourcegraph site ad…
- CVE-2022-29216HIGHCVSS 7.8EG 7.82022-05-21
TensorFlow is an open source platform for machine learning. Prior to versions 2.9.0, 2.8.1, 2.7.2, and 2.6.4, TensorFlow's `saved_model_cli` tool is vulnerable to a code injection. This can be used to open a reverse shell. This code path w…
- CVE-2022-29221HIGHCVSS 8.8EG 8.82022-05-24
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. Prior to versions 3.1.45 and 4.1.1, template authors could inject php code by choosing a malicious {block} name or {include…
- CVE-2022-29307CRITICALCVSS 9.8EG 9.82022-05-12
IonizeCMS v1.0.8.1 was discovered to contain a command injection vulnerability via the function copy_lang_content in application/models/lang_model.php.
- CVE-2022-29813MEDIUMCVSS 6.9EG 6.92022-04-28
In JetBrains IntelliJ IDEA before 2022.1 local code execution via custom Pandoc path was possible
- CVE-2022-29814HIGHCVSS 6.9EG 7.72022-04-28
In JetBrains IntelliJ IDEA before 2022.1 local code execution via HTML descriptions in custom JSON schemas was possible
- CVE-2022-29815MEDIUMCVSS 6.9EG 6.92022-04-28
In JetBrains IntelliJ IDEA before 2022.1 local code execution via workspace settings was possible
- CVE-2022-29819HIGHCVSS 6.9EG 7.72022-04-28
In JetBrains IntelliJ IDEA before 2022.1 local code execution via links in Quick Documentation was possible
- CVE-2022-29821HIGHCVSS 6.9EG 7.72022-04-28
In JetBrains Rider before 2022.1 local code execution via links in ReSharper Quick Documentation was possible
- CVE-2022-30083CRITICALCVSS 9.8EG 9.82022-07-30
EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection. The application appears to evaluate user input as code (remote).
- CVE-2022-30141HIGHCVSS 8.1EG 8.12022-06-15
Windows Lightweight Directory Access Protocol (LDAP) Remote Code Execution Vulnerability
- CVE-2022-30145HIGHCVSS 7.5EG 7.52022-06-15
Windows Encrypting File System (EFS) Remote Code Execution Vulnerability
- CVE-2022-30175HIGHCVSS 7.8EG 7.82022-08-09
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- CVE-2022-30194HIGHCVSS 7.5EG 7.52022-08-09
Windows WebBrowser Control Remote Code Execution Vulnerability
- CVE-2022-3033HIGHCVSS 8.1EG 8.12022-12-22
If a Thunderbird user replied to a crafted HTML email containing a <code>meta</code> tag, with the <code>meta</code> tag having the <code>http-equiv="refresh"</code> attribute, and the content attribute specifying an URL, then Thunderbird …
- CVE-2022-30580HIGHCVSS 7.8EG 7.82022-08-10
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path…
- CVE-2022-30877CRITICALCVSS 9.8EG 9.82022-06-08
The keep for python, as distributed on PyPI, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.2.
- CVE-2022-31161CRITICALCVSS 10.0EG 10.02022-07-15
Roxy-WI is a Web interface for managing HAProxy, Nginx and Keepalived servers. Prior to version 6.1.1.0, the system command can be run remotely via the subprocess_execute function without processing the inputs received from the user in the…
- CVE-2022-31491CRITICALCVSS 10.0EG 10.02025-08-22
Voltronic Power ViewPower through 1.04-24215, ViewPower Pro through 2.0-22165, and PowerShield Netguard before 1.04-23292 allows a remote attacker to run arbitrary code via an unspecified web interface related to detection of a managed UPS…
- CVE-2022-31691CRITICALCVSS 9.8EG 9.82022-11-04
Spring Tools 4 for Eclipse version 4.16.0 and below as well as VSCode extensions such as Spring Boot Tools, Concourse CI Pipeline Editor, Bosh Editor and Cloudfoundry Manifest YML Support version 1.39.0 and below all use Snakeyaml library …
- CVE-2022-31860CRITICALCVSS 9.8EG 9.82022-09-06
An issue was discovered in OpenRemote through 1.0.4 allows attackers to execute arbitrary code via a crafted Groovy rule.
- CVE-2022-32054CRITICALCVSS 9.8EG 9.82022-07-07
Tenda AC10 US_AC10V1.0RTL_V15.03.06.26_multi_TD01 was discovered to contain a remote code execution (RCE) vulnerability via the lanIp parameter.
- CVE-2022-3236CRITICALCVSS 9.8EG 9.8⚠ KEV2022-09-23
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1 and older.
- CVE-2022-32409CRITICALCVSS 9.8EG 9.82022-07-14
A local file inclusion (LFI) vulnerability in the component codemirror.php of Portal do Software Publico Brasileiro i3geo v7.0.5 allows attackers to execute arbitrary PHP code via a crafted HTTP request.
- CVE-2022-32417CRITICALCVSS 9.8EG 9.82022-07-14
PbootCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the function parserIfLabel at function.php.
- CVE-2022-3242MEDIUMCVSS 6.1EG 6.12022-09-20
Code Injection in GitHub repository microweber/microweber prior to 1.3.2.
- CVE-2022-3245MEDIUMCVSS 6.1EG 6.12022-09-20
HTML injection attack is closely related to Cross-site Scripting (XSS). HTML injection uses HTML to deface the page. XSS, as the name implies, injects JavaScript into the page. Both attacks exploit insufficient validation of user input.
- CVE-2022-32897HIGHCVSS 7.8EG 7.82024-06-10
A memory corruption issue was addressed with improved validation. This issue is fixed in macOS Monterey 12.5. Processing a maliciously crafted tiff file may lead to arbitrary code execution.
- CVE-2022-32924HIGHCVSS 7.8EG 7.82022-11-01
The issue was addressed with improved memory handling. This issue is fixed in tvOS 16.1, macOS Big Sur 11.7, macOS Ventura 13, watchOS 9.1, iOS 16.1 and iPadOS 16, macOS Monterey 12.6. An app may be able to execute arbitrary code with kern…
- CVE-2022-33721MEDIUMCVSS 4.4EG 5.52022-08-05
A vulnerability using PendingIntent in DeX for PC prior to SMR Aug-2022 Release 1 allows attackers to access files with system privilege.
- CVE-2022-33725MEDIUMCVSS 4.0EG 4.02022-08-05
A vulnerability using PendingIntent in Knox VPN prior to SMR Aug-2022 Release 1 allows attackers to access content providers with system privilege.
- CVE-2022-3383HIGHCVSS 7.2EG 7.22022-11-29
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the get_option_value_from_callback function that accepts user supplied input and passes it through call_user_func()…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →