CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,126 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 70 of 143
- CVE-2023-39022CRITICALCVSS 9.8EG 9.82023-07-28
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39023CRITICALCVSS 9.8EG 9.82023-07-28
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39059HIGHCVSS 8.8EG 8.82023-08-28
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
- CVE-2023-39157CRITICALCVSS 9.0EG 9.02023-12-31
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.
- CVE-2023-39320CRITICALCVSS 9.8EG 9.82023-09-08
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "…
- CVE-2023-39333MEDIUMCVSS 5.3EG 5.32024-09-07
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebA…
- CVE-2023-39445HIGHCVSS 8.8EG 8.82023-08-18
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.
- CVE-2023-39469HIGHCVSS 7.2EG 8.12024-05-03
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this …
- CVE-2023-39593MEDIUMCVSS 5.6EG 5.62024-10-17
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- CVE-2023-39631CRITICALCVSS 9.8EG 9.82023-09-01
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
- CVE-2023-39660CRITICALCVSS 9.8EG 9.82023-08-21
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
- CVE-2023-39661CRITICALCVSS 9.8EG 9.82023-08-15
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
- CVE-2023-39681CRITICALCVSS 9.8EG 9.82023-09-05
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
- CVE-2023-39685HIGHCVSS 7.5EG 7.52023-09-01
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
- CVE-2023-39956MEDIUMCVSS 6.1EG 6.12023-09-06
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if t…
- CVE-2023-40050CRITICALCVSS 9.9EG 9.92023-10-31
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
- CVE-2023-40177CRITICALCVSS 9.9EG 9.92023-08-23
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any registered user can use the content field of their user profile page to execute arbitrary scripts with programming rights, thus ef…
- CVE-2023-40221HIGHCVSS 8.8EG 8.82023-09-18
The absence of filters when loading some sections in the web application of the vulnerable device allows potential attackers to inject malicious code that will be interpreted when a legitimate user accesses the web section (MA…
- CVE-2023-40252HIGHCVSS 6.0EG 7.72023-08-17
Improper Control of Generation of Code ('Code Injection') vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Replace Trusted Executable.This issue affects Genian NAC…
- CVE-2023-40253MEDIUMCVSS 6.0EG 6.02023-08-11
Improper Authentication vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Authentication Abuse.This issue affects Genian NAC V4.0: from V4.0.0 through V4.0.155; Gen…
- CVE-2023-40254HIGHCVSS 7.5EG 7.52023-08-11
Download of Code Without Integrity Check vulnerability in Genians Genian NAC V4.0, Genians Genian NAC V5.0, Genians Genian NAC Suite V5.0, Genians Genian ZTNA allows Malicious Software Update.This issue affects Genian NAC V4.0: from V4.0.0…
- CVE-2023-40313HIGHCVSS 7.1EG 7.12023-08-17
A BeanShell interpreter in remote server mode runs in OpenMNS Horizon versions earlier than 32.0.2 and in related Meridian versions which could allow arbitrary remote Java code execution. The solution is to upgrade to Meridian 2023.1.6, 20…
- CVE-2023-40606CRITICALCVSS 9.1EG 9.12023-12-29
Improper Control of Generation of Code ('Code Injection') vulnerability in Kanban for WordPress Kanban Boards for WordPress.This issue affects Kanban Boards for WordPress: from n/a through 2.5.21.
- CVE-2023-40621MEDIUMCVSS 6.3EG 6.32023-09-12
SAP PowerDesigner Client - version 16.7, allows an unauthenticated attacker to inject VBScript code in a document and have it opened by an unsuspecting user, to have it executed by the application on behalf of the user. The application has…
- CVE-2023-40809MEDIUMCVSS 6.1EG 6.12023-11-18
OpenCRX version 5.2.0 is vulnerable to HTML injection via the Activity Search Criteria-Activity Number.
- CVE-2023-40826HIGHCVSS 7.5EG 7.52023-08-28
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the zippluginPath parameter.
- CVE-2023-40827HIGHCVSS 7.5EG 7.52023-08-28
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the loadpluginPath parameter.
- CVE-2023-40828HIGHCVSS 7.5EG 7.52023-08-28
An issue in pf4j pf4j v.3.9.0 and before allows a remote attacker to obtain sensitive information and execute arbitrary code via the expandIfZip method in the extract function.
- CVE-2023-41005HIGHCVSS 7.8EG 7.82023-08-28
An issue in Pagekit pagekit v.1.0.18 alows a remote attacker to execute arbitrary code via thedownloadAction and updateAction functions in UpdateController.php
- CVE-2023-41179CRITICALCVSS 7.2EG 9.0⚠ KEV2023-09-19
A vulnerability in the 3rd party AV uninstaller module contained in Trend Micro Apex One (on-prem and SaaS), Worry-Free Business Security and Worry-Free Business Security Services could allow an attacker to manipulate the module to execute…
- CVE-2023-41319HIGHCVSS 7.2EG 7.22023-09-06
Fides is an open-source privacy engineering platform for managing the fulfillment of data privacy requests in a runtime environment, and the enforcement of privacy regulations in code. The Fides webserver API allows custom integrations to …
- CVE-2023-41362HIGHCVSS 7.2EG 7.22023-08-29
MyBB before 1.8.36 allows Code Injection by users with certain high privileges. Templates in Admin CP intentionally use eval, and there was some validation of the input to eval, but type juggling interfered with this when using PCRE within…
- CVE-2023-4141HIGHCVSS 8.8EG 8.82023-08-04
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus2' parameter. This allows authenticated attackers with author-level permissions or above, if the…
- CVE-2023-4142HIGHCVSS 8.8EG 8.82023-08-04
The WP Ultimate CSV Importer plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 7.9.8 via the '->cus1' parameter. This allows authenticated attackers with author-level permissions or above, if the…
- CVE-2023-41444HIGHCVSS 7.8EG 7.82023-09-28
An issue in Binalyze IREC.sys v.3.11.0 and before allows a local attacker to execute arbitrary code and escalate privileges via the fun_1400084d0 function in IREC.sys driver.
- CVE-2023-41450HIGHCVSS 8.8EG 8.82023-09-28
An issue in phpkobo AjaxNewsTicker v.1.0.5 allows a remote attacker to execute arbitrary code via a crafted payload to the reque parameter.
- CVE-2023-41503CRITICALCVSS 9.8EG 9.82024-03-07
Student Enrollment In PHP v1.0 was discovered to contain a SQL injection vulnerability via the Login function.
- CVE-2023-41544CRITICALCVSS 9.8EG 9.82023-12-30
SSTI injection vulnerability in jeecg-boot version 3.5.3, allows remote attackers to execute arbitrary code via crafted HTTP request to the /jmreport/loadTableData component.
- CVE-2023-41630CRITICALCVSS 9.8EG 9.82023-10-17
eSST Monitoring v2.147.1 was discovered to contain a remote code execution (RCE) vulnerability via the Gii code generator component.
- CVE-2023-41724CRITICALCVSS 8.8EG 9.62024-03-31
A command injection vulnerability in Ivanti Sentry prior to 9.19.0 allows unauthenticated threat actor to execute arbitrary commands on the underlying operating system of the appliance within the same physical or logical network.
- CVE-2023-41783HIGHCVSS 7.8EG 7.82024-01-03
There is a command injection vulnerability of ZTE's ZXCLOUD iRAI. Due to the program failed to adequately validate the user's input, an attacker could exploit this vulnerability to escalate local privileges.
- CVE-2023-41892CRITICALCVSS 9.8EG 9.82023-09-13
Craft CMS is a platform for creating digital experiences. This is a high-impact, low-complexity attack vector. Users running Craft installations before 4.4.15 are encouraged to update to at least that version to mitigate the issue. This is…
- CVE-2023-41898HIGHCVSS 7.8EG 7.82023-10-19
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript ex…
- CVE-2023-41984HIGHCVSS 7.8EG 7.82023-09-27
The issue was addressed with improved memory handling. This issue is fixed in macOS Ventura 13.6, tvOS 17, iOS 16.7 and iPadOS 16.7, macOS Monterey 12.7, watchOS 10, iOS 17 and iPadOS 17, macOS Sonoma 14. An app may be able to execute arbi…
- CVE-2023-42374CRITICALCVSS 9.8EG 9.82024-02-13
An issue in mystenlabs Sui Blockchain before v.1.6.3 allow a remote attacker to execute arbitrary code and cause a denial of service via a crafted compressed script to the Sui node component.
- CVE-2023-42404MEDIUMCVSS 4.9EG 4.92025-04-28
OneVision Workspace before WS23.1 SR1 (build w31.040) allows arbitrary Java EL execution.
- CVE-2023-42470CRITICALCVSS 9.8EG 9.82023-09-11
The Imou Life com.mm.android.smartlifeiot application through 6.8.0 for Android allows Remote Code Execution via a crafted intent to an exported component. This relates to the com.mm.android.easy4ip.MainActivity activity. JavaScript execut…
- CVE-2023-42471CRITICALCVSS 9.8EG 9.82023-09-11
The wave.ai.browser application through 1.0.35 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. It contains a manifest entry that exports the wave.ai.browser.ui.splash.SplashScreen activity. T…
- CVE-2023-42658HIGHCVSS 7.8EG 8.82023-10-31
Archive command in Chef InSpec prior to 4.56.58 and 5.22.29 allow local command execution via maliciously crafted profile.
- CVE-2023-42833HIGHCVSS 8.8EG 8.82024-01-10
A correctness issue was addressed with improved checks. This issue is fixed in macOS Sonoma 14, Safari 17, iOS 17 and iPadOS 17. Processing web content may lead to arbitrary code execution.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →