CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 78 of 143
- CVE-2024-13738HIGHCVSS 7.3EG 7.32025-05-03
The The Motors - Car Dealer, Rental & Listing WordPress theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 5.6.65. This is due to the software allowing users to execute an action …
- CVE-2024-13785MEDIUMCVSS 5.6EG 5.62026-03-21
The The Contact Form, Survey, Quiz & Popup Form Builder – ARForms plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.7.2. This is due to the software allowing users to execute an a…
- CVE-2024-13792HIGHCVSS 7.3EG 7.32025-02-20
The WooCommerce Food - Restaurant Menu & Food ordering plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.3.2. This is due to the software allowing users to execute an action that do…
- CVE-2024-13793HIGHCVSS 7.3EG 7.32025-05-08
The Wolmart | Multi-Vendor Marketplace WooCommerce Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.8.11. This is due to the software allowing users to execute an action that …
- CVE-2024-13797HIGHCVSS 7.3EG 7.32025-02-18
The PressMart - Modern Elementor WooCommerce WordPress Theme theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.2.16. This is due to the software allowing users to execute an action t…
- CVE-2024-13806MEDIUMCVSS 6.5EG 6.52025-03-01
The The Authors List plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.0.6. This is due to the software allowing users to execute an action that does not properly validate a value b…
- CVE-2024-13808HIGHCVSS 8.8EG 8.82025-04-26
The Xpro Elementor Addons - Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.4.9 via the custom PHP widget. This is due to their only being client side controls when determining who ca…
- CVE-2024-13812MEDIUMCVSS 6.5EG 6.52025-04-26
The The Anps Theme plugin plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 1.1.1. This is due to the software allowing users to execute an action that does not properly validate a va…
- CVE-2024-13814MEDIUMCVSS 5.4EG 5.42025-02-12
The The Global Gallery - WordPress Responsive Gallery plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 9.1.5. This is due to the software allowing users to execute an action that doe…
- CVE-2024-13815MEDIUMCVSS 6.5EG 6.52025-03-05
The The Listingo theme for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 3.2.7. This is due to the software allowing users to execute an action that does not properly validate a value before…
- CVE-2024-13861HIGHCVSS 7.8EG 7.82025-04-11
A code injection vulnerability in the Debian package component of Taegis Endpoint Agent (Linux) versions older than 1.3.10 allows local users arbitrary code execution as root. Redhat-based systems using RPM packages are not affected.
- CVE-2024-13890HIGHCVSS 7.2EG 7.22025-03-08
The Allow PHP Execute plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 1.0. This is due to allowing PHP code to be entered by all users for whom unfiltered HTML is allowed. This makes it possib…
- CVE-2024-13895MEDIUMCVSS 4.3EG 4.32025-03-08
The The Code Snippets CPT plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 2.1.0. This is due to the software allowing users to execute an action that does not properly validate a va…
- CVE-2024-13900MEDIUMCVSS 4.1EG 4.12025-02-21
The Head, Footer and Post Injections plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 3.3.0. This makes it possible for authenticated attackers, with Administrator-level access and above, to in…
- CVE-2024-13902LOWCVSS 2.4EG 2.42025-03-06
A vulnerability, which was classified as problematic, was found in huang-yk student-manage 1.0. This affects an unknown part of the component Edit a Student Information Page. The manipulation of the argument Class leads to cross site scrip…
- CVE-2024-13928HIGHCVSS 7.2EG 7.22025-05-22
SQL injection vulnerabilities in ASPECT allow unintended access and manipulation of database repositories if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through…
- CVE-2024-13929HIGHCVSS 7.2EG 7.22025-05-22
Servlet injection vulnerabilities in ASPECT allow remote code execution if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3…
- CVE-2024-13952HIGHCVSS 8.4EG 8.42025-05-22
Predictable filename vulnerabilities in ASPECT may expose sensitive information to a potential attacker if administrator credentials become compromisedThis issue affects ASPECT-Enterprise: through 3.*; NEXUS Series: through 3.*; MATRIX Ser…
- CVE-2024-14020MEDIUMCVSS 5.0EG 5.02026-01-07
A weakness has been identified in carboneio carbone up to fbcd349077ad0e8748be73eab2a82ea92b6f8a7e. This impacts an unknown function of the file lib/input.js of the component Formatter Handler. Executing a manipulation can lead to improper…
- CVE-2024-1490HIGHCVSS 7.2EG 7.22026-04-09
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell com…
- CVE-2024-1577CRITICALCVSS 9.8EG 9.82024-06-12
Remote Code Execution vulnerability in MegaBIP software allows to execute arbitrary code on the server without requiring authentication by saving crafted by the attacker PHP code to one of the website files. This issue affects MegaBIP so…
- CVE-2024-1705MEDIUMCVSS 5.6EG 5.62024-02-21
A vulnerability was found in Shopwind up to 4.6. It has been rated as critical. This issue affects the function actionCreate of the file /public/install/controllers/DefaultController.php of the component Installation. The manipulation lead…
- CVE-2024-1706LOWCVSS 3.5EG 3.52024-02-21
A vulnerability was determined in ZKTeco ZKBio Access IVS up to 3.3.2. This impacts an unknown function of the component Department Name Search Bar. This manipulation with the input <marquee>hi causes cross site scripting. Remote exploitat…
- CVE-2024-1885MEDIUMCVSS 6.3EG 6.32024-02-26
This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage.
- CVE-2024-2016MEDIUMCVSS 6.3EG 6.32024-03-21
A vulnerability, which was classified as critical, was found in ZhiCms 4.0. Affected is the function index of the file app/manage/controller/setcontroller.php. The manipulation of the argument sitename leads to code injection. It is possib…
- CVE-2024-20359CRITICALCVSS 6.0EG 9.0⚠ KEV2024-04-24
A vulnerability in a legacy capability that allowed for the preloading of VPN clients and plug-ins and that has been available in Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allo…
- CVE-2024-20485MEDIUMCVSS 6.7EG 6.72024-10-23
A vulnerability in the VPN web server of Cisco Adaptive Security Appliance (ASA) Software and Cisco Firepower Threat Defense (FTD) Software could allow an authenticated, local attacker to execute arbitrary code with root-level privileges. …
- CVE-2024-2097HIGHCVSS 7.5EG 7.52024-03-27
An authenticated malicious client can send a special LINQ query to execute arbitrary code remotely (RCE) on the SCM server from List control, and execute the arbitrary code on the same system where SCMArchivedEventViewerTool is installed i…
- CVE-2024-21351CRITICALCVSS 7.6EG 9.0⚠ KEV2024-02-13
Windows SmartScreen Security Feature Bypass Vulnerability
- CVE-2024-21378HIGHCVSS 8.8EG 8.82024-02-13
Microsoft Outlook Remote Code Execution Vulnerability
- CVE-2024-21508CRITICALCVSS 9.8EG 9.82024-04-11
Versions of the package mysql2 before 3.9.4 are vulnerable to Remote Code Execution (RCE) via the readCodeFor function due to improper validation of the supportBigNumbers and bigNumberStrings values.
- CVE-2024-21511CRITICALCVSS 9.8EG 9.82024-04-23
Versions of the package mysql2 before 3.9.7 are vulnerable to Arbitrary Code Injection due to improper sanitization of the timezone parameter in the readCodeFor function by calling a native MySQL Server date/time function.
- CVE-2024-21513HIGHCVSS 8.5EG 8.52024-07-15
Versions of the package langchain-experimental from 0.0.15 and before 0.0.21 are vulnerable to Arbitrary Code Execution when retrieving values from the database, the code will attempt to call 'eval' on all values. An attacker can exploit t…
- CVE-2024-21534CRITICALCVSS 9.8EG 9.82024-10-11
All versions of the package jsonpath-plus are vulnerable to Remote Code Execution (RCE) due to improper input sanitization. An attacker can execute aribitrary code on the system by exploiting the unsafe default usage of vm in Node. **Note…
- CVE-2024-21537HIGHCVSS 8.8EG 8.82024-10-31
Versions of the package lilconfig from 3.1.0 and before 3.1.1 are vulnerable to Arbitrary Code Execution due to the insecure usage of eval in the dynamicImport function. An attacker can exploit this vulnerability by passing a malicious inp…
- CVE-2024-21541HIGHCVSS 7.3EG 7.32024-11-13
Versions of the package dom-iterator before 1.0.1 are vulnerable to Arbitrary Code Execution due to use of the Function constructor without complete input sanitization. Function generates a new function body and thus care must be given to …
- CVE-2024-21546CRITICALCVSS 9.8EG 9.82024-12-18
Versions of the package unisharp/laravel-filemanager before 2.9.1 are vulnerable to Remote Code Execution (RCE) through using a valid mimetype and inserting the . character after the php file extension. This allows the attacker to execute …
- CVE-2024-21552CRITICALCVSS 9.8EG 9.82024-07-22
All versions of `SuperAGI` are vulnerable to Arbitrary Code Execution due to unsafe use of the ‘eval’ function. An attacker could induce the LLM output to exploit this vulnerability and gain arbitrary code execution on the SuperAGI app…
- CVE-2024-21571HIGHCVSS 8.1EG 8.12024-12-06
Snyk has identified a remote code execution (RCE) vulnerability in all versions of Code Agent. The vulnerability enables an attacker to execute arbitrary code within the Code Agent container. Exploiting this vulnerability would require an …
- CVE-2024-21574CRITICALCVSS 10.0EG 10.02024-12-12
The issue stems from a missing validation of the pip field in a POST request sent to the /customnode/install endpoint used to install custom nodes which is added to the server by the extension. This allows an attacker to craft a request th…
- CVE-2024-21576CRITICALCVSS 10.0EG 10.02024-12-13
ComfyUI-Bmad-Nodes is vulnerable to Code Injection. The issue stems from a validation bypass in the BuildColorRangeHSVAdvanced, FilterContour and FindContour custom nodes. In the entrypoint function to each node, there’s a call to eval w…
- CVE-2024-21577CRITICALCVSS 10.0EG 10.02024-12-13
ComfyUI-Ace-Nodes is vulnerable to Code Injection. The ACE_ExpressionEval node contains an eval() in its entrypoint function that accepts arbitrary user-controlled data. A user can create a workflow that results in executing arbitrary code…
- CVE-2024-21643HIGHCVSS 7.1EG 7.12024-01-10
IdentityModel Extensions for .NET provide assemblies for web developers that wish to use federated identity providers for establishing the caller's identity. Anyone leveraging the `SignedHttpRequest`protocol or the `SignedHttpRequestValida…
- CVE-2024-21646CRITICALCVSS 9.8EG 9.82024-01-09
Azure uAMQP is a general purpose C library for AMQP 1.0. The UAMQP library is used by several clients to implement AMQP protocol communication. When clients using this library receive a crafted binary type data, an integer overflow or wra…
- CVE-2024-21649HIGHCVSS 8.8EG 8.82024-01-30
The vantage6 technology enables to manage and deploy privacy enhancing technologies like Federated Learning (FL) and Multi-Party Computation (MPC). Prior to 4.2.0, authenticated users could inject code into algorithm environment variables,…
- CVE-2024-21650CRITICALCVSS 9.8EG 9.82024-01-08
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki is vulnerable to a remote code execution (RCE) attack through its user registration feature. This issue allows an attacker to ex…
- CVE-2024-21672HIGHCVSS 8.8EG 8.82024-01-16
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 2.1.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.3 and a CVSS Vector of CVSS:3.0/AV:N/AC:…
- CVE-2024-21673HIGHCVSS 8.8EG 8.82024-01-16
This High severity Remote Code Execution (RCE) vulnerability was introduced in versions 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.0 and a CVSS Vector of CVSS:3.0/AV:N/A…
- CVE-2024-21674HIGHCVSS 7.5EG 8.62024-01-16
This High severity Remote Code Execution (RCE) vulnerability was introduced in version 7.13.0 of Confluence Data Center and Server. Remote Code Execution (RCE) vulnerability, with a CVSS Score of 8.6 and a CVSS Vector of CVSS:3.0/AV:N/AC:…
- CVE-2024-21682HIGHCVSS 7.2EG 7.22024-02-20
This High severity Injection vulnerability was introduced in Assets Discovery 1.0 - 6.2.0 (all versions). Assets Discovery, which can be downloaded via Atlassian Marketplace, is a network scanning tool that can be used with or without an…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →