CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,126 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 69 of 143
- CVE-2023-36437HIGHCVSS 8.8EG 8.82023-11-14
Azure DevOps Server Remote Code Execution Vulnerability
- CVE-2023-36467HIGHCVSS 8.0EG 8.02023-06-28
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services. data.all versions 1.2.0 through 1.5.1 do not prevent remote code execution when a user injects Python commands into the ‘…
- CVE-2023-36542HIGHCVSS 8.8EG 8.82023-07-29
Apache NiFi 0.0.2 through 1.22.0 include Processors and Controller Services that support HTTP URL references for retrieving drivers, which allows an authenticated and authorized user to configure a location that enables custom code executi…
- CVE-2023-3656CRITICALCVSS 9.8EG 9.82023-10-03
cashIT! - serving solutions. Devices from "PoS/ Dienstleistung, Entwicklung & Vertrieb GmbH" to 03.A06rks 2023.02.37 are affected by an unauthenticated remote code execution vulnerability. This vulnerability can be triggered by an HTTP end…
- CVE-2023-36570HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36571HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36572HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36573HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36574HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36575HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36589HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36591HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36592HIGHCVSS 7.3EG 7.32023-10-10
Microsoft Message Queuing (MSMQ) Remote Code Execution Vulnerability
- CVE-2023-36645CRITICALCVSS 9.1EG 9.12024-04-04
SQL injection vulnerability in ITB-GmbH TradePro v9.5, allows remote attackers to run SQL queries via oordershow component in customer function.
- CVE-2023-3665MEDIUMCVSS 5.5EG 5.52023-10-04
A code injection vulnerability in Trellix ENS 10.7.0 April 2023 release and earlier, allowed a local user to disable the ENS AMSI component via environment variables, leading to denial of service and or the execution of arbitrary code.
- CVE-2023-36702HIGHCVSS 7.8EG 7.82023-10-10
Microsoft DirectMusic Remote Code Execution Vulnerability
- CVE-2023-36718HIGHCVSS 7.8EG 7.82023-10-10
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
- CVE-2023-36789HIGHCVSS 7.2EG 7.22023-10-10
Skype for Business Remote Code Execution Vulnerability
- CVE-2023-36859HIGHCVSS 8.8EG 8.82023-07-06
PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
- CVE-2023-36923HIGHCVSS 7.8EG 7.82023-08-08
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the …
- CVE-2023-36992HIGHCVSS 7.2EG 7.22023-07-07
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
- CVE-2023-37198MEDIUMCVSS 6.8EG 6.82023-07-12
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
- CVE-2023-37199MEDIUMCVSS 6.8EG 6.82023-07-12
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
- CVE-2023-37273HIGHCVSS 8.1EG 8.12023-07-13
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 by cloning the git repo and executing `docker compose run auto-gpt` in the repo root uses …
- CVE-2023-37274HIGHCVSS 7.5EG 7.52023-07-13
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-GPT is executed directly on the host system via the provided run.sh or run.bat files, custom Python code execution is sa…
- CVE-2023-37424HIGHCVSS 8.1EG 8.12023-08-22
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's…
- CVE-2023-37427HIGHCVSS 7.2EG 7.22023-08-22
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows…
- CVE-2023-37466CRITICALCVSS 9.8EG 9.82023-07-14
vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanit…
- CVE-2023-37470CRITICALCVSS 10.0EG 10.02023-08-04
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on…
- CVE-2023-37518MEDIUMCVSS 6.4EG 6.42024-01-30
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
- CVE-2023-37565HIGHCVSS 8.0EG 8.02023-07-13
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1…
- CVE-2023-37582CRITICALCVSS 9.8EG 9.82023-07-12
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verificati…
- CVE-2023-37659CRITICALCVSS 9.8EG 9.82023-07-11
xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
- CVE-2023-37909CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arb…
- CVE-2023-37914CRITICALCVSS 9.9EG 9.92023-08-17
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote co…
- CVE-2023-38198CRITICALCVSS 9.8EG 9.82023-07-13
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
- CVE-2023-38484HIGHCVSS 8.0EG 8.02023-09-06
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to g…
- CVE-2023-38576HIGHCVSS 8.0EG 8.02023-08-18
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS commands on a certain management console.
- CVE-2023-38860CRITICALCVSS 9.8EG 9.82023-08-15
An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
- CVE-2023-38877HIGHCVSS 8.8EG 8.82023-09-28
A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to user…
- CVE-2023-38889CRITICALCVSS 9.8EG 9.82023-08-15
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
- CVE-2023-38943HIGHCVSS 8.8EG 8.82023-08-05
ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.
- CVE-2023-39010CRITICALCVSS 9.8EG 9.82023-07-28
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
- CVE-2023-39013CRITICALCVSS 9.8EG 9.82023-07-28
Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.
- CVE-2023-39015CRITICALCVSS 9.8EG 9.82023-07-28
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
- CVE-2023-39016CRITICALCVSS 9.8EG 9.82023-07-28
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39017CRITICALCVSS 9.8EG 9.82023-07-28
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disp…
- CVE-2023-39018CRITICALCVSS 9.8EG 9.82023-07-28
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple t…
- CVE-2023-39020CRITICALCVSS 9.8EG 9.82023-07-28
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39021CRITICALCVSS 9.8EG 9.82023-07-28
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →