CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,126 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 73 of 143
- CVE-2023-50810MEDIUMCVSS 6.0EG 6.02024-08-12
In certain Sonos products before Sonos S1 Release 11.12 and S2 release 15.9, a vulnerability exists in the U-Boot component of the firmware that allow persistent arbitrary code execution with Linux kernel privileges. A failure to correctly…
- CVE-2023-51015CRITICALCVSS 9.8EG 9.82023-12-22
TOTOLINX EX1800T v9.1.0cu.2112_B20220316 is vulnerable to arbitrary command execution in the ‘enable parameter’ of the setDmzCfg interface of the cstecgi .cgi
- CVE-2023-51018CRITICALCVSS 9.8EG 9.82023-12-22
TOTOlink EX1800T v9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘opmode’ parameter of the setWiFiApConfig interface of the cstecgi .cgi.
- CVE-2023-51026CRITICALCVSS 9.8EG 9.82023-12-22
TOTOlink EX1800T V9.1.0cu.2112_B20220316 is vulnerable to unauthorized arbitrary command execution in the ‘hour’ parameter of the setRebootScheCfg interface of the cstecgi .cgi.
- CVE-2023-51066HIGHCVSS 8.8EG 8.82024-01-13
An authenticated remote code execution vulnerability in QStar Archive Solutions Release RELEASE_3-0 Build 7 Patch 0 allows attackers to arbitrarily execute commands.
- CVE-2023-51282HIGHCVSS 7.5EG 7.52024-01-16
An issue in mingSoft MCMS v.5.2.4 allows a a remote attacker to obtain sensitive information via a crafted script to the password parameter.
- CVE-2023-51313HIGHCVSS 8.8EG 8.82025-02-20
PHPJabbers Restaurant Booking System v3.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameter…
- CVE-2023-51317MEDIUMCVSS 6.5EG 6.52025-02-20
PHPJabbers Restaurant Booking System v3.0 is vulnerable to Multiple HTML Injection in the "name, plugin_sms_api_key, plugin_sms_country_code, title, plugin_sms_api_key, title" parameters.
- CVE-2023-51320MEDIUMCVSS 5.3EG 5.32025-02-20
PHPJabbers Night Club Booking Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any paramet…
- CVE-2023-51324MEDIUMCVSS 6.5EG 6.52025-02-20
PHPJabbers Shared Asset Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any paramet…
- CVE-2023-51331MEDIUMCVSS 6.5EG 6.52025-02-20
PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any paramete…
- CVE-2023-51387HIGHCVSS 8.8EG 8.82023-12-22
Hertzbeat is an open source, real-time monitoring system. Hertzbeat uses aviatorscript to evaluate alert expressions. The alert expressions are supposed to be some simple expressions. However, due to improper sanitization for alert express…
- CVE-2023-51420CRITICALCVSS 8.8EG 9.12023-12-29
Improper Control of Generation of Code ('Code Injection') vulnerability in Soft8Soft LLC Verge3D Publishing and E-Commerce.This issue affects Verge3D Publishing and E-Commerce: from n/a through 4.5.2.
- CVE-2023-51770HIGHCVSS 7.5EG 7.52024-02-20
Arbitrary File Read Vulnerability in Apache Dolphinscheduler. This issue affects Apache DolphinScheduler: before 3.2.1. We recommend users to upgrade Apache DolphinScheduler to version 3.2.1, which fixes the issue.
- CVE-2023-51784CRITICALCVSS 9.8EG 9.82024-01-03
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong.This issue affects Apache InLong: from 1.5.0 through 1.9.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLong'…
- CVE-2023-51797MEDIUMCVSS 6.7EG 6.72024-04-19
Buffer Overflow vulnerability in Ffmpeg v.N113007-g8d24a28d06 allows a local attacker to execute arbitrary code via the libavfilter/avf_showwaves.c:722:24 in showwaves_filter_frame
- CVE-2023-51801CRITICALCVSS 9.8EG 9.82024-02-29
SQL Injection vulnerability in the Simple Student Attendance System v.1.0 allows a remote attacker to execute arbitrary code via a crafted payload to the id parameter in the student_form.php and the class_form.php pages.
- CVE-2023-51820MEDIUMCVSS 6.8EG 6.82024-02-02
An issue in Blurams Lumi Security Camera (A31C) v.2.3.38.12558 allows a physically proximate attackers to execute arbitrary code.
- CVE-2023-5201CRITICALCVSS 8.8EG 9.92023-09-30
The OpenHook plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 4.3.0 via the 'php' shortcode. This allows authenticated attackers with subscriber-level permissions or above, to execute code on th…
- CVE-2023-5221CRITICALCVSS 9.8EG 9.82023-09-27
A vulnerability classified as critical has been found in ForU CMS. This affects an unknown part of the file /install/index.php. The manipulation of the argument db_name leads to code injection. It is possible to initiate the attack remotel…
- CVE-2023-52251CRITICALCVSS 8.8EG 9.02024-01-25
An issue discovered in provectus kafka-ui 0.4.0 through 0.7.1 allows remote attackers to execute arbitrary code via the q parameter of /api/clusters/local/topics/{topic}/messages.
- CVE-2023-5226HIGHCVSS 7.5EG 7.52023-12-01
An issue has been discovered in GitLab affecting all versions before 16.4.3, all versions starting from 16.5 before 16.5.3, all versions starting from 16.6 before 16.6.1. Under certain circumstances, a malicious actor bypass prohibited bra…
- CVE-2023-52381CRITICALCVSS 9.8EG 9.82024-02-18
Script injection vulnerability in the email module.Successful exploitation of this vulnerability may affect service confidentiality, integrity, and availability.
- CVE-2023-53883HIGHCVSS 7.2EG 7.22025-12-15
Webedition CMS v2.9.8.8 contains a remote code execution vulnerability that allows authenticated attackers to inject system commands through PHP page creation. Attackers can create a new PHP page with malicious system commands in the descr…
- CVE-2023-53888HIGHCVSS 8.8EG 8.82025-12-15
Zomplog 3.9 contains a remote code execution vulnerability that allows authenticated attackers to inject and execute arbitrary PHP code through file manipulation endpoints. Attackers can upload files (such as JavaScript) and rename them to…
- CVE-2023-53940HIGHCVSS 7.8EG 7.82025-12-18
Codigo Markdown Editor 1.0.1 contains a code execution vulnerability that allows attackers to run arbitrary system commands by crafting a malicious markdown file. Attackers can embed a video source with an onerror event that executes shell…
- CVE-2023-54345HIGHCVSS 8.8EG 8.82026-05-05
Frappe Framework ERPNext 13.4.0 contains a sandbox escape vulnerability in RestrictedPython that allows authenticated users with System Manager role to execute arbitrary code by exploiting frame introspection. Attackers can create a server…
- CVE-2023-5500HIGHCVSS 8.8EG 8.82023-12-11
This vulnerability allows an remote attacker with low privileges to misuse Improper Control of Generation of Code ('Code Injection') to gain full control of the affected device.
- CVE-2023-5512MEDIUMCVSS 5.7EG 5.72023-12-15
An issue has been discovered in GitLab CE/EE affecting all versions from 16.3 before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when specific HTML…
- CVE-2023-5539HIGHCVSS 8.8EG 8.82023-11-09
A remote code execution risk was identified in the Lesson activity. By default this was only available to teachers and managers.
- CVE-2023-5540HIGHCVSS 8.8EG 8.82023-11-09
A remote code execution risk was identified in the IMSCP activity. By default this was only available to teachers and managers.
- CVE-2023-5550CRITICALCVSS 9.8EG 9.82023-11-09
In a shared hosting environment that has been misconfigured to allow access to other users' content, a Moodle user who also has direct access to the web server outside of the Moodle webroot could utilise a local file include to achieve rem…
- CVE-2023-5604CRITICALCVSS 9.8EG 9.82023-11-27
The Asgaros Forum WordPress plugin before 2.7.1 allows forum administrators, who may not be WordPress (super-)administrators, to set insecure configuration that allows unauthenticated users to upload dangerous files (e.g. .php, .phtml), po…
- CVE-2023-5623HIGHCVSS 7.8EG 7.82023-10-26
NNM failed to properly set ACLs on its installation directory, which could allow a low privileged user to run arbitrary code with SYSTEM privileges where NNM is installed to a non-standard location
- CVE-2023-5677MEDIUMCVSS 6.3EG 6.32024-02-05
Brandon Rothel from QED Secure Solutions and Sam Hanson of Dragos have found that the VAPIX API tcptest.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after aut…
- CVE-2023-5762HIGHCVSS 8.8EG 8.82023-12-04
The Filr WordPress plugin before 1.2.3.6 is vulnerable from an RCE (Remote Code Execution) vulnerability, which allows the operating system to execute commands and fully compromise the server on behalf of a user with Author-level privilege…
- CVE-2023-5800MEDIUMCVSS 5.4EG 5.42024-02-05
Vintage, member of the AXIS OS Bug Bounty Program, has found that the VAPIX API create_overlay.cgi did not have a sufficient input validation allowing for a possible remote code execution. This flaw can only be exploited after authenticati…
- CVE-2023-5843CRITICALCVSS 9.8EG 9.82023-10-30
The Ads by datafeedr.com plugin for WordPress is vulnerable to Remote Code Execution in versions up to, and including, 1.1.3 via the 'dfads_ajax_load_ads' function. This allows unauthenticated attackers to execute code on the server. The p…
- CVE-2023-6016CRITICALCVSS 9.8EG 10.02023-11-16
An attacker is able to gain remote code execution on a server hosting the H2O dashboard through it's POJO model import feature.
- CVE-2023-6051MEDIUMCVSS 6.5EG 6.52023-12-15
An issue has been discovered in GitLab CE/EE affecting all versions before 16.4.4, all versions starting from 16.5 before 16.5.4, all versions starting from 16.6 before 16.6.2. File integrity may be compromised when source code or installa…
- CVE-2023-6125HIGHCVSS 8.8EG 8.82023-11-14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- CVE-2023-6126CRITICALCVSS 9.8EG 9.82023-11-14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- CVE-2023-6131HIGHCVSS 8.8EG 8.82023-11-14
Code Injection in GitHub repository salesagility/suitecrm prior to 7.14.2, 7.12.14, 8.4.2.
- CVE-2023-6188CRITICALCVSS 9.8EG 9.82023-11-17
A vulnerability was found in GetSimpleCMS 3.3.16/3.4.0a. It has been rated as critical. This issue affects some unknown processing of the file /admin/theme-edit.php. The manipulation leads to code injection. The attack may be initiated rem…
- CVE-2023-6248CRITICALCVSS 9.8EG 10.02023-11-21
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks…
- CVE-2023-6288HIGHCVSS 7.8EG 7.82023-12-06
Code injection in Remote Desktop Manager 2023.3.9.3 and earlier on macOS allows an attacker to execute code via the DYLIB_INSERT_LIBRARIES environment variable.
- CVE-2023-6395MEDIUMCVSS 6.7EG 6.72024-01-16
The Mock software contains a vulnerability wherein an attacker could potentially exploit privilege escalation, enabling the execution of arbitrary code with root user privileges. This weakness stems from the absence of proper sandboxing du…
- CVE-2023-6494MEDIUMCVSS 4.4EG 4.42024-04-13
The WPC Smart Quick View for WooCommerce plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 4.0.2 due to insufficient input sanitization and output escaping. This make…
- CVE-2023-6540HIGHCVSS 7.5EG 7.52024-01-03
A vulnerability was reported in the Lenovo Browser Mobile and Lenovo Browser HD Apps for Android that could allow an attacker to craft a payload that could result in the disclosure of sensitive information.
- CVE-2023-6548CRITICALCVSS 5.5EG 9.0⚠ KEV2024-01-17
Improper Control of Generation of Code ('Code Injection') in NetScaler ADC and NetScaler Gateway allows an attacker with access to NSIP, CLIP or SNIP with management interface to perform Authenticated (low privileged) remote code execu…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →