CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,123 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 65 of 143
- CVE-2023-0788HIGHCVSS 8.1EG 8.12023-02-12
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- CVE-2023-0792MEDIUMCVSS 6.5EG 6.52023-02-12
Code Injection in GitHub repository thorsten/phpmyfaq prior to 3.1.11.
- CVE-2023-0877HIGHCVSS 8.8EG 8.82023-02-17
Code Injection in GitHub repository froxlor/froxlor prior to 2.0.11.
- CVE-2023-0888HIGHCVSS 4.9EG 7.22023-03-13
An improper neutralization of directives in dynamically evaluated code vulnerability in the WiFi Battery embedded web server in versions L90/U70 and L92/U92 can be used to gain administrative access to the WiFi communication module. An aut…
- CVE-2023-1003HIGHCVSS 5.3EG 7.82023-03-07
A vulnerability, which was classified as critical, was found in Typora up to 1.5.5 on Windows. Affected is an unknown function of the component WSH JScript Handler. The manipulation leads to code injection. An attack has to be approached l…
- CVE-2023-1004HIGHCVSS 5.3EG 7.82023-02-24
A vulnerability has been found in MarkText up to 0.17.1 on Windows and classified as critical. Affected by this vulnerability is an unknown functionality of the component WSH JScript Handler. The manipulation leads to code injection. Local…
- CVE-2023-1005HIGHCVSS 5.3EG 7.82023-02-24
A vulnerability was found in JP1016 Markdown-Electron and classified as critical. Affected by this issue is some unknown functionality. The manipulation leads to code injection. Attacking locally is a requirement. The exploit has been disc…
- CVE-2023-1030MEDIUMCVSS 3.5EG 6.12023-02-24
A vulnerability has been found in SourceCodester/code-projects Online Boat Reservation System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /boat/login.php of the component POST P…
- CVE-2023-1049HIGHCVSS 7.8EG 7.82023-06-14
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
- CVE-2023-1097CRITICALCVSS 9.3EG 9.82023-03-01
Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The followin…
- CVE-2023-1178MEDIUMCVSS 5.7EG 5.72023-05-03
An issue has been discovered in GitLab CE/EE affecting all versions from 8.6 before 15.9.6, all versions starting from 15.10 before 15.10.5, all versions starting from 15.11 before 15.11.1. File integrity may be compromised when source cod…
- CVE-2023-1250HIGHCVSS 7.4EG 7.82023-03-20
Improper Input Validation vulnerability in OTRS AG OTRS (ACL modules), OTRS AG ((OTRS)) Community Edition (ACL modules) allows Local Execution of Code. When creating/importing an ACL it was possible to inject code that gets executed via ma…
- CVE-2023-1283CRITICALCVSS 10.0EG 10.02023-03-08
Code Injection in GitHub repository builderio/qwik prior to 0.21.0.
- CVE-2023-1287CRITICALCVSS 9.0EG 9.82023-03-09
An XSL template vulnerability in ENOVIA Live Collaboration V6R2013xE allows Remote Code Execution.
- CVE-2023-1304HIGHCVSS 8.8EG 8.82023-03-21
An authenticated attacker can leverage an exposed getattr() method via a Jinja template to smuggle OS commands and perform other actions that are normally expected to be private methods. This issue was resolved in the Managed and SaaS depl…
- CVE-2023-1306HIGHCVSS 8.8EG 8.82023-03-21
An authenticated attacker can leverage an exposed resource.db() accessor method to smuggle Python method calls via a Jinja template, which can lead to code execution. This issue was resolved in the Managed and SaaS deployments on February …
- CVE-2023-1367LOWCVSS 3.8EG 3.82023-03-13
Code Injection in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
- CVE-2023-1406HIGHCVSS 8.8EG 8.82023-04-10
The JetEngine WordPress plugin before 3.1.3.1 includes uploaded files without adequately ensuring that they are not executable, leading to a remote code execution vulnerability.
- CVE-2023-1482HIGHCVSS 4.7EG 8.82023-03-18
A vulnerability, which was classified as problematic, was found in HkCms 2.2.4.230206. This affects an unknown part of the file /admin.php/appcenter/local.html?type=addon of the component External Plugin Handler. The manipulation leads to …
- CVE-2023-1708CRITICALCVSS 5.7EG 9.82023-04-05
An issue was identified in GitLab CE/EE affecting all versions from 1.0 prior to 15.8.5, 15.9 prior to 15.9.4, and 15.10 prior to 15.10.1 where non-printable characters gets copied from clipboard, allowing unexpected commands to be execute…
- CVE-2023-1773CRITICALCVSS 6.3EG 9.82023-03-31
A vulnerability was found in Rockoa 2.3.2. It has been declared as critical. This vulnerability affects unknown code of the file webmainConfig.php of the component Configuration File Handler. The manipulation leads to code injection. The a…
- CVE-2023-1947CRITICALCVSS 6.3EG 9.82023-04-07
A vulnerability was found in taoCMS 3.0.2. It has been classified as critical. Affected is an unknown function of the file /admin/admin.php. The manipulation leads to code injection. It is possible to launch the attack remotely. The exploi…
- CVE-2023-20063HIGHCVSS 8.2EG 8.22023-11-01
A vulnerability in the inter-device communication mechanisms between devices that are running Cisco Firepower Threat Defense (FTD) Software and devices that are running Cisco Firepower Management (FMC) Software could allow an authenticated…
- CVE-2023-2017HIGHCVSS 8.8EG 8.82023-04-17
Server-side Template Injection (SSTI) in Shopware 6 (<= v6.4.20.0, v6.5.0.0-rc1 <= v6.5.0.0-rc4), affecting both shopware/core and shopware/platform GitHub repositories, allows remote attackers with access to a Twig environment without the…
- CVE-2023-20209MEDIUMCVSS 6.5EG 6.92023-08-16
A vulnerability in the web-based management interface of Cisco Expressway Series and Cisco TelePresence Video Communication Server (VCS) could allow an authenticated, remote attacker with read-write privileges on the application to perform…
- CVE-2023-2056CRITICALCVSS 6.3EG 9.82023-04-14
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical. This issue affects the function GetSystemFile of the file module_main.php. The manipulation leads to code injection. The attack may be initiated remotely. The ex…
- CVE-2023-21553HIGHCVSS 7.5EG 7.52023-02-14
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-21569MEDIUMCVSS 5.5EG 5.52023-06-14
Azure DevOps Server Spoofing Vulnerability
- CVE-2023-21886HIGHCVSS 8.1EG 8.12023-01-18
Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). Supported versions that are affected are Prior to 6.1.42 and prior to 7.0.6. Difficult to exploit vulnerability allows unauthenticated attacker…
- CVE-2023-21890CRITICALCVSS 9.8EG 9.82023-01-18
Vulnerability in the Oracle Communications Converged Application Server product of Oracle Communications (component: Core). Supported versions that are affected are 7.1.0 and 8.0.0. Easily exploitable vulnerability allows unauthenticated…
- CVE-2023-22381HIGHCVSS 4.1EG 8.82023-03-02
A code injection vulnerability was identified in GitHub Enterprise Server that allowed setting arbitrary environment variables from a single environment variable value in GitHub Actions when using a Windows based runner. To exploit this vu…
- CVE-2023-22506HIGHCVSS 8.8EG 8.82023-07-19
This High severity Injection and RCE (Remote Code Execution) vulnerability known as CVE-2023-22506 was introduced in version 8.0.0 of Bamboo Data Center. This Injection and RCE (Remote Code Execution) vulnerability, with a CVSS Score o…
- CVE-2023-22513HIGHCVSS 8.8EG 8.82023-09-19
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 8.0.0 of Bitbucket Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 8.5, allows an authenticated attacker to…
- CVE-2023-22514HIGHCVSS 7.8EG 7.82024-01-16
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 3.4.14 of Sourcetree for Mac and Sourcetree for Windows. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.8, and a CVSS Vect…
- CVE-2023-22526HIGHCVSS 8.8EG 8.82024-01-16
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 7.19.0 of Confluence Data Center. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to execu…
- CVE-2023-2259CRITICALCVSS 7.2EG 9.12023-04-24
Improper Neutralization of Special Elements Used in a Template Engine in GitHub repository alfio-event/alf.io prior to 2.0-M4-2304.
- CVE-2023-22677HIGHCVSS 8.5EG 8.52023-12-29
Improper Control of Generation of Code ('Code Injection') vulnerability in BinaryStash WP Booklet.This issue affects WP Booklet: from n/a through 2.1.8.
- CVE-2023-22731CRITICALCVSS 9.9EG 9.92023-01-17
Shopware is an open source commerce platform based on Symfony Framework and Vue js. In a Twig environment **without the Sandbox extension**, it is possible to refer to PHP functions in twig filters like `map`, `filter`, `sort`. This allows…
- CVE-2023-22853HIGHCVSS 8.8EG 8.82023-01-14
Tiki before 24.1, when feature_create_webhelp is enabled, allows lib/structures/structlib.php PHP Object Injection because of an eval.
- CVE-2023-22855CRITICALCVSS 9.8EG 9.82023-02-15
Kardex Mlog MCC 5.7.12+0-a203c2a213-master allows remote code execution. It spawns a web interface listening on port 8088. A user-controllable path is handed to a path-concatenation method (Path.Combine from .NET) without proper sanitisati…
- CVE-2023-22889CRITICALCVSS 9.8EG 9.82023-03-08
SmartBear Zephyr Enterprise through 7.15.0 mishandles user-defined input during report generation. This could lead to remote code execution by unauthenticated users.
- CVE-2023-22952CRITICALCVSS 8.8EG 9.0⚠ KEV2023-01-11
In SugarCRM before 12.0. Hotfix 91155, a crafted request can inject custom PHP code through the EmailTemplates because of missing input validation.
- CVE-2023-23477CRITICALCVSS 8.1EG 9.82023-02-03
IBM WebSphere Application Server 8.5 and 9.0 traditional could allow a remote attacker to execute arbitrary code on the system with a specially crafted sequence of serialized objects. IBM X-Force ID: 245513.
- CVE-2023-23496HIGHCVSS 8.8EG 8.82023-02-27
The issue was addressed with improved checks. This issue is fixed in macOS Ventura 13.2, watchOS 9.3, iOS 15.7.2 and iPadOS 15.7.2, Safari 16.3, tvOS 16.3, iOS 16.3 and iPadOS 16.3. Processing maliciously crafted web content may lead to ar…
- CVE-2023-23551CRITICALCVSS 9.1EG 9.82023-02-13
Control By Web X-600M devices run Lua scripts and are vulnerable to code injection, which could allow an attacker to remotely execute arbitrary code.
- CVE-2023-2359HIGHCVSS 8.8EG 8.82023-06-19
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
- CVE-2023-23619CRITICALCVSS 9.9EG 9.92023-01-26
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents. Versions prior to 1.0.0 are vulnerable to Code injection. This issue affects anyone who is using the default presets and/…
- CVE-2023-23645CRITICALCVSS 9.9EG 9.92024-05-17
Improper Control of Generation of Code ('Code Injection') vulnerability in MainWP MainWP Code Snippets Extension allows Code Injection.This issue affects MainWP Code Snippets Extension: from n/a through 4.0.2.
- CVE-2023-23912HIGHCVSS 8.8EG 8.82023-02-09
A vulnerability, found in EdgeRouters Version 2.0.9-hotfix.5 and earlier and UniFi Security Gateways (USG) Version 4.4.56 and earlier with their DHCPv6 prefix delegation set to dhcpv6-stateless or dhcpv6-stateful, allows a malicious actor …
- CVE-2023-24059HIGHCVSS 7.3EG 7.32023-01-22
Grand Theft Auto V for PC allows attackers to achieve partial remote code execution or modify files on a PC, as exploited in the wild in January 2023.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →