CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 62 of 143
- CVE-2022-3384HIGHCVSS 7.2EG 7.22022-11-29
The Ultimate Member plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 2.5.0 via the populate_dropdown_options function that accepts user supplied input and passes it through call_user_func(). Thi…
- CVE-2022-3394HIGHCVSS 7.2EG 7.22022-10-25
The WP All Export Pro WordPress plugin before 1.7.9 does not limit some functionality during exports only to users with the Administrator role, allowing any logged in user which has been given privileges to perform exports to execute arbit…
- CVE-2022-3401HIGHCVSS 8.8EG 8.82022-10-28
The Bricks theme for WordPress is vulnerable to remote code execution due to the theme allowing site editors to include executable code blocks in website content in versions 1.2 to 1.5.3. This, combined with the missing authorization vulne…
- CVE-2022-3418HIGHCVSS 7.2EG 7.22022-11-07
The Import any XML or CSV File to WordPress plugin before 3.6.9 is not properly filtering which file extensions are allowed to be imported on the server, which could allow administrators in multi-site WordPress installations to upload arbi…
- CVE-2022-34456HIGHCVSS 8.8EG 8.82023-01-18
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability. An authenticated nonprivileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary OS commands on the applicati…
- CVE-2022-34625HIGHCVSS 7.2EG 7.22022-08-02
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.
- CVE-2022-34663HIGHCVSS 8.0EG 8.02022-07-12
A vulnerability has been identified in RUGGEDCOM i800, RUGGEDCOM i800NC, RUGGEDCOM i801, RUGGEDCOM i801NC, RUGGEDCOM i802, RUGGEDCOM i802NC, RUGGEDCOM i803, RUGGEDCOM i803NC, RUGGEDCOM M2100, RUGGEDCOM M2100F, RUGGEDCOM M2100NC, RUGGEDCOM …
- CVE-2022-34714HIGHCVSS 8.1EG 8.12022-08-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-34715CRITICALCVSS 9.8EG 9.82022-08-09
Windows Network File System Remote Code Execution Vulnerability
- CVE-2022-34821CRITICALCVSS 7.6EG 9.82022-07-12
A vulnerability has been identified in RUGGEDCOM RM1224 LTE(4G) EU (6GK6108-4AM00-2BA2), RUGGEDCOM RM1224 LTE(4G) NAM (6GK6108-4AM00-2DA2), SCALANCE M804PB (6GK5804-0AP00-2AA2), SCALANCE M812-1 ADSL-Router (6GK5812-1AA00-2AA2), SCALANCE M8…
- CVE-2022-35516CRITICALCVSS 9.8EG 9.82022-08-17
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
- CVE-2022-35649CRITICALCVSS 9.8EG 9.82022-07-25
The vulnerability was found in Moodle, occurs due to improper input validation when parsing PostScript code. An omitted execution parameter results in a remote code execution risk for sites running GhostScript versions older than 9.50. Suc…
- CVE-2022-35743HIGHCVSS 7.8EG 7.82023-05-31
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
- CVE-2022-35766HIGHCVSS 8.1EG 8.12022-08-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-35767HIGHCVSS 8.1EG 8.12022-08-09
Windows Secure Socket Tunneling Protocol (SSTP) Remote Code Execution Vulnerability
- CVE-2022-35772HIGHCVSS 7.2EG 7.22022-08-09
Azure Site Recovery Remote Code Execution Vulnerability
- CVE-2022-35773HIGHCVSS 7.8EG 7.82022-08-09
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- CVE-2022-35777HIGHCVSS 8.8EG 8.82022-08-09
Visual Studio Remote Code Execution Vulnerability
- CVE-2022-35779HIGHCVSS 7.8EG 7.82022-08-09
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
- CVE-2022-35835HIGHCVSS 8.8EG 8.82022-09-13
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2022-35836HIGHCVSS 8.8EG 8.82022-09-13
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2022-35847HIGHCVSS 6.3EG 8.82022-09-06
An improper neutralization of special elements used in a template engine vulnerability [CWE-1336] in FortiSOAR management interface 7.2.0, 7.0.0 through 7.0.3, 6.4.0 through 6.4.4 may allow a remote and authenticated attacker to execute ar…
- CVE-2022-35944MEDIUMCVSS 6.2EG 6.22022-10-13
October is a self-hosted Content Management System (CMS) platform based on the Laravel PHP Framework. This vulnerability only affects installations that rely on the safe mode restriction, commonly used when providing public access to the a…
- CVE-2022-36006HIGHCVSS 7.9EG 7.92022-08-15
Arvados is an open source platform for managing, processing, and sharing genomic and other large scientific and biomedical data. A remote code execution (RCE) vulnerability in the Arvados Workbench allows authenticated attackers to execute…
- CVE-2022-36036LOWCVSS 3.6EG 3.62022-08-29
mdx-mermaid provides plug and play access to Mermaid in MDX. There is a potential for an arbitrary javascript injection in versions less than 1.3.0 and 2.0.0-rc1. Modify any mermaid code blocks with arbitrary code and it will execute when …
- CVE-2022-36069HIGHCVSS 7.3EG 7.32022-09-07
Poetry is a dependency manager for Python. When handling dependencies that come from a Git repository instead of a registry, Poetry uses various commands, such as `git clone`. These commands are constructed using user input (e.g. the repos…
- CVE-2022-36099CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Wiki UI Main Wiki is software for managing subwikis on XWiki Platform, a generic wiki platform. Starting with version 5.3-milestone-2 and prior to versions 13.10.6 and 14.4, it's possible to inject arbitrary wiki syntax incl…
- CVE-2022-36100CRITICALCVSS 9.9EG 9.92022-09-08
XWiki Platform Applications Tag and XWiki Platform Tag UI are tag applications for XWiki, a generic wiki platform. Starting with version 1.7 in XWiki Platform Applications Tag and prior to 13.10.6 and 14.4 in XWiki Platform Tag UI, the tag…
- CVE-2022-36215HIGHCVSS 7.2EG 7.22022-08-17
DedeBIZ v6 was discovered to contain a remote code execution vulnerability in sys_info.php.
- CVE-2022-36216HIGHCVSS 7.2EG 7.22022-08-17
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
- CVE-2022-36231CRITICALCVSS 9.8EG 9.82023-02-23
pdf_info 0.5.3 is vulnerable to Command Execution because the Ruby code uses backticks instead of Open3.
- CVE-2022-36262CRITICALCVSS 9.8EG 9.82022-08-15
An issue was discovered in taocms 3.0.2. in the website settings that allows arbitrary php code to be injected by modifying config.php.
- CVE-2022-36386CRITICALCVSS 9.1EG 9.12022-09-21
Authenticated Arbitrary Code Execution vulnerability in Soflyy Import any XML or CSV File to WordPress plugin <= 3.6.7 at WordPress.
- CVE-2022-36756CRITICALCVSS 9.8EG 9.82022-08-28
DIR845L A1 v1.00-v1.03 is vulnerable to command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-36799HIGHCVSS 7.2EG 7.72022-08-01
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented. Affected versions of Atlassian Jira Server and Data Center allowed remote attackers with system admin…
- CVE-2022-3696HIGHCVSS 7.2EG 7.22022-12-01
A post-auth code injection vulnerability allows admins to execute code in Webadmin of Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-36963HIGHCVSS 7.2EG 8.82023-04-21
The SolarWinds Platform was susceptible to the Command Injection Vulnerability. This vulnerability allows a remote adversary with a valid SolarWinds Platform admin account to execute arbitrary commands.
- CVE-2022-37009HIGHCVSS 3.9EG 7.82022-07-28
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
- CVE-2022-37053CRITICALCVSS 9.8EG 9.82022-08-28
TRENDnet TEW733GR v1.03B01 is vulnerable to Command injection via /htdocs/upnpinc/gena.php.
- CVE-2022-3713HIGHCVSS 8.8EG 8.82022-12-01
A code injection vulnerability allows adjacent attackers to execute code in the Wifi controller of Sophos Firewall releases older than version 19.5 GA.
- CVE-2022-37155HIGHCVSS 8.8EG 8.82022-12-14
RCE in SPIP 3.1.13 through 4.1.2 allows remote authenticated users to execute arbitrary code via the _oups parameter.
- CVE-2022-3721MEDIUMCVSS 4.6EG 4.62022-11-04
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.39.
- CVE-2022-37396HIGHCVSS 4.1EG 7.82022-08-03
In JetBrains Rider before 2022.2 Trust and Open Project dialog could be bypassed, leading to local code execution
- CVE-2022-37904HIGHCVSS 6.6EG 8.82022-12-12
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underl…
- CVE-2022-37905HIGHCVSS 6.6EG 8.82022-12-12
Vulnerabilities in ArubaOS running on 7xxx series controllers exist that allows an attacker to execute arbitrary code during the boot sequence. Successful exploitation could allow an attacker to achieve permanent modification of the underl…
- CVE-2022-37933HIGHCVSS 7.3EG 7.82023-01-05
A potential security vulnerability has been identified in HPE Superdome Flex and Superdome Flex 280 servers. The vulnerability could be exploited to allow local unauthorized data injection. HPE has made the following software updates to re…
- CVE-2022-37982HIGHCVSS 8.8EG 8.82022-10-11
Microsoft WDAC OLE DB provider for SQL Server Remote Code Execution Vulnerability
- CVE-2022-38078CRITICALCVSS 9.8EG 9.82022-08-24
Movable Type XMLRPC API provided by Six Apart Ltd. contains a command injection vulnerability. Sending a specially crafted message by POST method to Movable Type XMLRPC API may allow arbitrary Perl script execution, and an arbitrary OS com…
- CVE-2022-38193CRITICALCVSS 6.1EG 9.62022-08-16
There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.
- CVE-2022-3869MEDIUMCVSS 6.1EG 6.12022-11-05
Code Injection in GitHub repository froxlor/froxlor prior to 0.10.38.2.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →