CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 64 of 143
- CVE-2022-44088CRITICALCVSS 9.8EG 9.82022-11-10
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component INPUT_ISDESCRIPTION.
- CVE-2022-44089CRITICALCVSS 9.8EG 9.82022-11-10
ESPCMS P8.21120101 was discovered to contain a remote code execution (RCE) vulnerability in the component IS_GETCACHE.
- CVE-2022-44262CRITICALCVSS 9.8EG 9.82022-12-01
ff4j 1.8.1 is vulnerable to Remote Code Execution (RCE).
- CVE-2022-44533HIGHCVSS 7.2EG 7.22022-12-12
A vulnerability in the Aruba EdgeConnect Enterprise web management interface allows remote authenticated users to run arbitrary commands on the underlying host. A successful exploit could allow an attacker to execute arbitrary commands as …
- CVE-2022-4455MEDIUMCVSS 3.5EG 6.12022-12-13
A vulnerability was identified in sproctor php-calendar up to 2.0.13. This impacts an unknown function of the file index.php. Such manipulation of the argument $_SERVER['PHP_SELF'] leads to cross site scripting. The attack may be launched …
- CVE-2022-44702HIGHCVSS 7.8EG 7.82022-12-13
Windows Terminal Remote Code Execution Vulnerability
- CVE-2022-44794HIGHCVSS 8.8EG 8.82022-11-07
An issue was discovered in Object First Ootbi BETA build 1.0.7.712. Management protocol has a flow which allows a remote attacker to execute arbitrary Bash code with root privileges. The command that sets the hostname doesn't validate inpu…
- CVE-2022-45132CRITICALCVSS 9.8EG 9.82022-11-18
In Linaro Automated Validation Architecture (LAVA) before 2022.11.1, remote code execution can be achieved through user-submitted Jinja2 template. The REST API endpoint for validating device configuration files in lava-server loads input a…
- CVE-2022-45177HIGHCVSS 7.5EG 7.52024-02-21
An issue was discovered in LIVEBOX Collaboration vDesk through v031. An Observable Response Discrepancy can occur under the /api/v1/vdeskintegration/user/isenableuser endpoint, the /api/v1/sharedsearch?search={NAME]+{SURNAME] endpoint, and…
- CVE-2022-45550CRITICALCVSS 9.8EG 9.82022-12-07
AyaCMS 3.1.2 is vulnerable to Remote Code Execution (RCE).
- CVE-2022-45553CRITICALCVSS 9.8EG 9.82023-03-03
An issue discovered in Shenzhen Zhibotong Electronics WBT WE1626 Router v 21.06.18 allows attacker to execute arbitrary commands via serial connection to the UART port.
- CVE-2022-45699CRITICALCVSS 9.8EG 9.82023-02-10
Command injection in the administration interface in APSystems ECU-R version 5203 allows a remote unauthenticated attacker to execute arbitrary commands as root using the timezone parameter.
- CVE-2022-45907CRITICALCVSS 9.8EG 9.82022-11-26
In PyTorch before trunk/89695, torch.jit.annotations.parse_type_line can cause arbitrary code execution because eval is used unsafely.
- CVE-2022-45908CRITICALCVSS 9.8EG 9.82022-11-26
In PaddlePaddle before 2.4, paddle.audio.functional.get_window is vulnerable to code injection because it calls eval on a user-supplied winstr. This may lead to arbitrary code execution.
- CVE-2022-45928HIGHCVSS 8.8EG 8.82023-01-18
A remote OScript execution issue was discovered in OpenText Content Suite Platform 22.1 (16.2.19.1803). Multiple endpoints allow the user to pass the parameter htmlFile, which is included in the HTML output rendering pipeline of a request.…
- CVE-2022-45942HIGHCVSS 8.8EG 8.82022-12-20
A Remote Code Execution (RCE) vulnerability was found in includes/baijiacms/common.inc.php in baijiacms v4.
- CVE-2022-46070HIGHCVSS 7.5EG 7.52024-03-11
GV-ASManager V6.0.1.0 contains a Local File Inclusion vulnerability in GeoWebServer via Path.
- CVE-2022-46101HIGHCVSS 8.8EG 8.82022-12-22
AyaCMS v3.1.2 was found to have a code flaw in the ust_sql.inc.php file, which allows attackers to cause command execution by inserting malicious code.
- CVE-2022-46157HIGHCVSS 8.8EG 8.82022-12-09
Akeneo PIM is an open source Product Information Management (PIM). Akeneo PIM Community Edition versions before v5.0.119 and v6.0.53 allows remote authenticated users to execute arbitrary PHP code on the server by uploading a crafted image…
- CVE-2022-46161CRITICALCVSS 10.0EG 10.02022-12-06
pdfmake is an open source client/server side PDF printing in pure JavaScript. In versions up to and including 0.2.5 pdfmake contains an unsafe evaluation of user controlled input. Users of pdfmake are thus subject to arbitrary code executi…
- CVE-2022-46166HIGHCVSS 8.0EG 8.02022-12-09
Spring boot admins is an open source administrative user interface for management of spring boot applications. All users who run Spring Boot Admin Server, having enabled Notifiers (e.g. Teams-Notifier) and write access to environment varia…
- CVE-2022-46333HIGHCVSS 7.2EG 7.22022-12-06
The admin user interface in Proofpoint Enterprise Protection (PPS/PoD) contains a command injection vulnerability that enables an admin to execute commands beyond their allowed scope. This affects all versions 8.19.0 and below.
- CVE-2022-46648HIGHCVSS 8.0EG 8.02023-01-17
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from …
- CVE-2022-46742CRITICALCVSS 10.0EG 10.02022-12-07
Code injection in paddle.audio.functional.get_window in PaddlePaddle 2.4.0-rc0 allows arbitrary code execution.
- CVE-2022-46836CRITICALCVSS 9.1EG 9.12023-02-20
PHP code injection in watolib auth.php and hosttags.php in Tribe29's Checkmk <= 2.1.0p10, Checkmk <= 2.0.0p27, and Checkmk <= 1.6.0p29 allows an attacker to inject and execute PHP code which will be executed upon request of the vulnerable …
- CVE-2022-46874HIGHCVSS 8.8EG 8.82022-12-22
A file with a long filename could have had its filename truncated to remove the valid extension, leaving a malicious extension in its place. This could potentially led to user confusion and the execution of malicious code.<br/>*Note*: This…
- CVE-2022-47129CRITICALCVSS 9.8EG 9.82023-05-11
PHPOK v6.3 was discovered to contain a remote code execution (RCE) vulnerability.
- CVE-2022-47318HIGHCVSS 8.0EG 8.02023-01-17
ruby-git versions prior to v1.13.0 allows a remote authenticated attacker to execute an arbitrary ruby code by having a user to load a repository containing a specially crafted filename to the product. This vulnerability is different from …
- CVE-2022-47879HIGHCVSS 7.5EG 7.52023-05-12
A Remote Code Execution (RCE) vulnerability in /be/rpc.php in Jedox 2020.2.5 allows remote authenticated users to load arbitrary PHP classes from the 'rtn' directory and execute its methods. NOTE: The vendor states that the vulnerability a…
- CVE-2022-47896HIGHCVSS 5.0EG 7.82022-12-22
In JetBrains IntelliJ IDEA before 2022.3.1 code Templates were vulnerable to SSTI attacks.
- CVE-2022-48093HIGHCVSS 7.2EG 7.22023-02-01
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
- CVE-2022-48116HIGHCVSS 7.2EG 7.22023-01-27
AyaCMS v3.1.2 was discovered to contain a remote code execution (RCE) vulnerability via the component /admin/tpl_edit.inc.php.
- CVE-2022-48175CRITICALCVSS 9.8EG 9.82023-01-30
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
- CVE-2022-48198CRITICALCVSS 9.8EG 9.82023-01-01
The ntpd_driver component before 1.3.0 and 2.x before 2.2.0 for Robot Operating System (ROS) allows attackers, who control the source code of a different node in the same ROS application, to change a robot's behavior. This occurs because a…
- CVE-2022-50806HIGHCVSS 7.2EG 8.82026-01-13
4images 1.9 contains a remote command execution vulnerability that allows authenticated administrators to inject reverse shell code through template editing functionality. Attackers can save malicious code in the template and execute arbit…
- CVE-2022-50898HIGHCVSS 8.8EG 8.82026-01-13
NanoCMS 0.4 contains an authenticated file upload vulnerability that allows remote code execution through unvalidated page content creation. Authenticated attackers can upload PHP files with arbitrary code to the server's pages directory b…
- CVE-2022-50944HIGHCVSS 8.8EG 8.82026-05-10
Aero CMS 0.0.1 contains a PHP code injection vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious files through the image parameter. Attackers can upload PHP files with embedded code to the…
- CVE-2022-50972CRITICALCVSS 9.8EG 9.82026-06-20
WooCommerce 7.1.0 contains a remote code execution vulnerability that allows attackers to execute arbitrary PHP code by injecting shell commands through the product-type parameter. Attackers can send requests to the class-wc-meta-box-produ…
- CVE-2023-0022CRITICALCVSS 9.9EG 9.92023-01-10
SAP BusinessObjects Business Intelligence Analysis edition for OLAP allows an authenticated attacker to inject malicious code that can be executed by the application over the network. On successful exploitation, an attacker can perform ope…
- CVE-2023-0048HIGHCVSS 8.8EG 8.82023-01-04
Code Injection in GitHub repository lirantal/daloradius prior to master-branch.
- CVE-2023-0089HIGHCVSS 8.8EG 8.82023-03-08
The webutils in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows an authenticated user to execute remote code through 'eval injection'. This affects all versions 8.20.0 and below.
- CVE-2023-0090CRITICALCVSS 9.8EG 9.82023-03-08
The webservices in Proofpoint Enterprise Protection (PPS/POD) contain a vulnerability that allows for an anonymous user to execute remote code through 'eval injection'. Exploitation requires network access to the webservices API, but such…
- CVE-2023-0297CRITICALCVSS 9.8EG 9.82023-01-14
Code Injection in GitHub repository pyload/pyload prior to 0.5.0b3.dev31.
- CVE-2023-0351HIGHCVSS 8.8EG 8.82023-03-13
The Akuvox E11 web server backend library allows command injection in the device phone-book contacts functionality. This could allow an attacker to upload files with executable command instructions.
- CVE-2023-0462HIGHCVSS 8.0EG 8.02023-09-20
An arbitrary code execution flaw was found in Foreman. This issue may allow an admin user to execute arbitrary code on the underlying operating system by setting global parameters with a YAML payload.
- CVE-2023-0575CRITICALCVSS 7.2EG 9.82023-02-09
External Control of Critical State Data, Improper Control of Generation of Code ('Code Injection') vulnerability in YugaByte, Inc. Yugabyte DB on Windows, Linux, MacOS, iOS (DevopsBase.Java:execCommand, TableManager.Java:runCommand modules…
- CVE-2023-0598CRITICALCVSS 7.8EG 9.82023-03-16
GE Digital Proficy iFIX 2022, GE Digital Proficy iFIX v6.1, and GE Digital Proficy iFIX v6.5 are vulnerable to code injection, which may allow an attacker to insert malicious configuration files in the expected web server execution path a…
- CVE-2023-0625CRITICALCVSS 8.0EG 9.82023-09-25
Docker Desktop before 4.12.0 is vulnerable to RCE via a crafted extension description or changelog. This issue affects Docker Desktop: before 4.12.0.
- CVE-2023-0626CRITICALCVSS 8.0EG 9.82023-09-25
Docker Desktop before 4.12.0 is vulnerable to RCE via query parameters in message-box route. This issue affects Docker Desktop: before 4.12.0.
- CVE-2023-0671HIGHCVSS 8.8EG 8.82023-02-04
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.10.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →