CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,125 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 67 of 143
- CVE-2023-28354CRITICALCVSS 9.8EG 9.82025-01-09
An issue was discovered in Opsview Monitor Agent 6.8. An unauthenticated remote attacker can call check_nrpe against affected targets, specifying known NRPE plugins, which in default installations are configured to accept command control c…
- CVE-2023-2859HIGHCVSS 8.8EG 8.82023-05-24
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.9.
- CVE-2023-28706CRITICALCVSS 9.8EG 9.82023-04-07
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Software Foundation Apache Airflow Hive Provider.This issue affects Apache Airflow Hive Provider: before 6.0.0.
- CVE-2023-28793HIGHCVSS 7.8EG 7.82023-10-23
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- CVE-2023-28796HIGHCVSS 7.1EG 7.12023-10-23
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
- CVE-2023-29209CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the legacy notification activity macro can execute arbitrary Groovy, Python or Vel…
- CVE-2023-29210CRITICALCVSS 9.9EG 9.92023-04-15
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents including the notification preferences macros can execute arbitrary Groovy, Python or Veloci…
- CVE-2023-29211CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights `WikiManager.DeleteWiki` can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki i…
- CVE-2023-29212CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-29214CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with edit rights can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the XWiki installation. The root cau…
- CVE-2023-2928HIGHCVSS 6.3EG 7.32023-05-27
A vulnerability was found in DedeCMS up to 5.7.106. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file uploads/dede/article_allowurl_edit.php. The manipulation of the argument allurls l…
- CVE-2023-29374CRITICALCVSS 9.8EG 9.82023-04-05
In LangChain through 0.0.131, the LLMMathChain chain allows prompt injection attacks that can execute arbitrary code via the Python exec method.
- CVE-2023-29382CRITICALCVSS 9.8EG 9.82023-07-06
An issue in Zimbra Collaboration ZCS v.8.8.15 and v.9.0 allows an attacker to execute arbitrary code via the sfdc_preauth.jsp component.
- CVE-2023-29400HIGHCVSS 7.3EG 7.32023-05-11
Templates containing actions in unquoted HTML attributes (e.g. "attr={{.}}") executed with empty input can result in output with unexpected results when parsed due to HTML normalization rules. This may allow injection of arbitrary attribut…
- CVE-2023-29402CRITICALCVSS 9.8EG 9.82023-06-08
The go command may generate unexpected code at build time when using cgo. This may result in unexpected behavior when running a go program which uses cgo. This may occur when running an untrusted module which contains directories with newl…
- CVE-2023-29404CRITICALCVSS 9.8EG 9.82023-06-08
The go command may execute arbitrary code at build time when using cgo. This may occur when running "go get" on a malicious module, or when running any other command which builds untrusted code. This is can by triggered by linker flags, sp…
- CVE-2023-2943HIGHCVSS 8.8EG 8.82023-05-27
Code Injection in GitHub repository openemr/openemr prior to 7.0.1.
- CVE-2023-29453CRITICALCVSS 9.8EG 9.82023-10-12
Templates do not properly consider backticks (`) as Javascript string delimiters, and do not escape them as expected. Backticks are used, since ES6, for JS template literals. If a template contains a Go template action within a Javascript …
- CVE-2023-29492CRITICALCVSS 9.8EG 9.8⚠ KEV2023-04-11
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account. This does not provide access to stored survey or response data.
- CVE-2023-29509CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Commons are technical libraries common to several other top level XWiki projects. Any user with view rights on commonly accessible documents can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full access to the…
- CVE-2023-29566CRITICALCVSS 9.8EG 9.82023-04-24
huedawn-tesseract 0.3.3 and dawnsparks-node-tesseract 0.4.0 to 0.4.1 was discovered to contain a remote code execution (RCE) vulnerability via the child_process function.
- CVE-2023-29861CRITICALCVSS 9.8EG 9.82023-05-15
An issue found in FLIR-DVTEL version not specified allows a remote attacker to execute arbitrary code via a crafted request to the management page of the device.
- CVE-2023-29862CRITICALCVSS 9.8EG 9.82023-05-15
An issue found in Agasio-Camera device version not specified allows a remote attacker to execute arbitrary code via the check and authLevel parameters.
- CVE-2023-29963HIGHCVSS 7.2EG 7.22023-05-05
S-CMS v5.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the component /admin/ajax.php.
- CVE-2023-30130HIGHCVSS 8.8EG 8.82023-05-12
An issue found in CraftCMS v.3.8.1 allows a remote attacker to execute arbitrary code via a crafted script to the Section parameter.
- CVE-2023-30131CRITICALCVSS 9.8EG 9.82023-10-19
An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls.
- CVE-2023-30145CRITICALCVSS 9.8EG 9.82023-05-26
Camaleon CMS v2.7.0 was discovered to contain a Server-Side Template Injection (SSTI) vulnerability via the formats parameter.
- CVE-2023-30179HIGHCVSS 7.2EG 7.22023-06-13
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI). An authenticated attacker can inject Twig Template to User Photo Location field when setting User Photo Location in User Settings, lead to Remote Code Executio…
- CVE-2023-30349CRITICALCVSS 9.8EG 9.82023-04-27
JFinal CMS v5.1.0 was discovered to contain a remote code execution (RCE) vulnerability via the ActionEnter function.
- CVE-2023-30404CRITICALCVSS 9.8EG 9.82023-04-26
Aigital Wireless-N Repeater Mini_Router v0.131229 was discovered to contain a remote code execution (RCE) vulnerability via the sysCmd parameter in the formSysCmd function. This vulnerability is exploited via a crafted HTTP request.
- CVE-2023-30537CRITICALCVSS 9.9EG 9.92023-04-16
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user with the right to add an object on a page can execute arbitrary Groovy, Python or Velocity code in XWiki leading to full acce…
- CVE-2023-30638HIGHCVSS 7.2EG 7.22023-04-14
Atos Unify OpenScape SBC 10 before 10R3.1.3, OpenScape Branch 10 before 10R3.1.2, and OpenScape BCF 10 before 10R10.7.0 allow remote authenticated admins to inject commands.
- CVE-2023-30912HIGHCVSS 7.2EG 7.22023-10-25
A remote code execution issue exists in HPE OneView.
- CVE-2023-30990HIGHCVSS 8.6EG 8.62023-07-04
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture. IBM X-Force ID: 254036.
- CVE-2023-31037HIGHCVSS 7.2EG 7.22024-01-24
NVIDIA Bluefield 2 and Bluefield 3 DPU BMC contains a vulnerability in ipmitool, where a root user may cause code injection by a network call. A successful exploit of this vulnerability may lead to code execution on the OS.
- CVE-2023-31044HIGHCVSS 8.8EG 8.82026-03-03
An issue was discovered in Nokia Impact before Mobile 23_FP1. In Impact DM 19.11 onwards, a remote authenticated user, using the Add Campaign functionality, can inject a malicious payload within the Campaign Name. This data can be exported…
- CVE-2023-31296MEDIUMCVSS 5.3EG 5.32023-12-29
CSV Injection vulnerability in Sesami Cash Point & Transport Optimizer (CPTO) version 6.3.8.6 (#718), allows attackers to obtain sensitive information via the User Name field.
- CVE-2023-31315HIGHCVSS 7.5EG 7.52024-08-12
Improper validation in a model specific register (MSR) could allow a malicious program with ring0 access to modify SMM configuration while SMI lock is enabled, potentially leading to arbitrary code execution.
- CVE-2023-31414HIGHCVSS 8.8EG 8.82023-05-04
Kibana versions 8.0.0 through 8.7.0 contain an arbitrary code execution flaw. An attacker with write access to Kibana yaml or env configuration could add a specific payload that will attempt to execute JavaScript code. This could lead to t…
- CVE-2023-31415HIGHCVSS 8.8EG 8.82023-05-04
Kibana version 8.7.0 contains an arbitrary code execution flaw. An attacker with All privileges to the Uptime/Synthetics feature could send a request that will attempt to execute JavaScript code. This could lead to the attacker executing a…
- CVE-2023-31447CRITICALCVSS 9.8EG 9.82023-08-21
user_login.cgi on Draytek Vigor2620 devices before 3.9.8.4 (and on all versions of Vigor2925 devices) allows attackers to send a crafted payload to modify the content of the code segment, insert shellcode, and execute arbitrary code.
- CVE-2023-31493MEDIUMCVSS 6.6EG 6.62024-10-15
RCE (Remote Code Execution) exists in ZoneMinder through 1.36.33 as an attacker can create a new .php log file in language folder, while executing a crafted payload and escalate privileges allowing execution of any commands on the remote s…
- CVE-2023-32095CRITICALCVSS 9.9EG 9.92023-12-29
Improper Control of Generation of Code ('Code Injection') vulnerability in Milan Dinić Rename Media Files.This issue affects Rename Media Files: from n/a through 1.0.1.
- CVE-2023-3224CRITICALCVSS 9.8EG 9.82023-06-13
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
- CVE-2023-32383HIGHCVSS 7.8EG 7.82024-01-10
This issue was addressed by forcing hardened runtime on the affected binaries at the system level. This issue is fixed in macOS Monterey 12.6.6, macOS Big Sur 11.7.7, macOS Ventura 13.4. An app may be able to inject code into sensitive bin…
- CVE-2023-32418HIGHCVSS 7.8EG 7.82023-07-27
The issue was addressed with improved checks. This issue is fixed in macOS Monterey 12.6.8, macOS Ventura 13.5, macOS Big Sur 11.7.9. Processing a file may lead to unexpected app termination or arbitrary code execution.
- CVE-2023-32527HIGHCVSS 8.8EG 8.82023-06-26
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute lo…
- CVE-2023-32528HIGHCVSS 8.8EG 8.82023-06-26
Trend Micro Mobile Security (Enterprise) 9.8 SP5 contains vulnerable .php files that could allow a remote attacker to execute arbitrary code on affected installations. Please note: an attacker must first obtain the ability to execute lo…
- CVE-2023-32540HIGHCVSS 7.2EG 7.22023-06-06
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modi…
- CVE-2023-32546MEDIUMCVSS 4.4EG 4.42023-06-13
Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier. If this vulnerability is exploited, a non-administrative user of the Mac where the product is installed may store and obtain audio and image data…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →