CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 79 of 143
- CVE-2024-21683CRITICALCVSS 8.8EG 9.02024-05-21
This High severity RCE (Remote Code Execution) vulnerability was introduced in version 5.2 of Confluence Data Center and Server. This RCE (Remote Code Execution) vulnerability, with a CVSS Score of 7.2, allows an authenticated attacker to…
- CVE-2024-21689HIGHCVSS 8.0EG 8.02024-08-20
This High severity RCE (Remote Code Execution) vulnerability CVE-2024-21689 was introduced in versions 9.1.0, 9.2.0, 9.3.0, 9.4.0, 9.5.0, and 9.6.0 of Bamboo Data Center and Server. This RCE (Remote Code Execution) vulnerability, with…
- CVE-2024-21737CRITICALCVSS 9.1EG 9.12024-01-09
In SAP Application Interface Framework File Adapter - version 702, a high privilege user can use a function module to traverse through various layers and execute OS commands directly. By this, such user can control the behaviour of the …
- CVE-2024-21760HIGHCVSS 8.4EG 8.42025-03-18
An improper control of generation of code ('Code Injection') vulnerability [CWE-94] in FortiSOAR Connector FortiSOAR 7.4 all versions, 7.3 all versions, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an authenticated att…
- CVE-2024-21832LOWCVSS 3.5EG 3.52024-07-09
A potential JSON injection attack vector exists in PingFederate REST API data stores using the POST method and a JSON request body.
- CVE-2024-21892HIGHCVSS 7.8EG 7.82024-02-20
On Linux, Node.js ignores certain environment variables if those may have been set by an unprivileged user while the process is running with elevated privileges with the only exception of CAP_NET_BIND_SERVICE. Due to a bug in the implement…
- CVE-2024-2195CRITICALCVSS 9.8EG 9.82024-04-10
A critical Remote Code Execution (RCE) vulnerability was identified in the aimhubio/aim project, specifically within the `/api/runs/search/run/` endpoint, affecting versions >= 3.0.0. The vulnerability resides in the `run_search_api` funct…
- CVE-2024-22020MEDIUMCVSS 6.5EG 6.52024-07-09
A security flaw in Node.js allows a bypass of network import restrictions. By embedding non-network imports in data URLs, an attacker can execute arbitrary code, compromising system security. Verified on various platforms, the vulnerabili…
- CVE-2024-2209MEDIUMCVSS 6.3EG 6.32024-03-27
A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory w…
- CVE-2024-22116CRITICALCVSS 9.9EG 9.92024-08-12
An administrator with restricted permissions can exploit the script execution functionality within the Monitoring Hosts section. The lack of default escaping for script parameters enabled this user ability to execute arbitrary code via the…
- CVE-2024-22123LOWCVSS 2.7EG 2.72024-08-12
Setting SMS media allows to set GSM modem file. Later this file is used as Linux device. But due everything is a file for Linux, it is possible to set another file, e.g. log file and zabbix_server will try to communicate with it as modem. …
- CVE-2024-22127CRITICALCVSS 9.1EG 9.12024-03-12
SAP NetWeaver Administrator AS Java (Administrator Log Viewer plug-in) - version 7.50, allows an attacker with high privileges to upload potentially dangerous files which leads to command injection vulnerability. This would enable the att…
- CVE-2024-22131CRITICALCVSS 9.1EG 9.12024-02-13
In SAP ABA (Application Basis) - versions 700, 701, 702, 731, 740, 750, 751, 752, 75C, 75I, an attacker authenticated as a user with a remote execution authorization can use a vulnerable interface. This allows the attacker to use the inter…
- CVE-2024-22144CRITICALCVSS 9.0EG 9.02024-04-25
Improper Control of Generation of Code ('Code Injection') vulnerability in Eli Scheetz Anti-Malware Security and Brute-Force Firewall gotmls allows Code Injection.This issue affects Anti-Malware Security and Brute-Force Firewall: from n/a …
- CVE-2024-22169HIGHCVSS 7.1EG 7.12024-08-02
WD Discovery versions prior to 5.0.589 contain a misconfiguration in the Node.js environment settings that could allow code execution by utilizing the 'ELECTRON_RUN_AS_NODE' environment variable. Any malicious application operating with s…
- CVE-2024-22188HIGHCVSS 7.2EG 7.22024-03-05
TYPO3 before 13.0.1 allows an authenticated admin user (with system maintainer privileges) to execute arbitrary shell commands (with the privileges of the web server) via a command injection vulnerability in form fields of the Install Tool…
- CVE-2024-22274HIGHCVSS 7.2EG 7.22024-05-21
The vCenter Server contains an authenticated remote code execution vulnerability. A malicious actor with administrative privileges on the vCenter appliance shell may exploit this issue to run arbitrary commands on the underlying operating…
- CVE-2024-22514HIGHCVSS 8.8EG 8.82024-02-06
An issue discovered in iSpyConnect.com Agent DVR 5.1.6.0 allows attackers to run arbitrary files by restoring a crafted backup file.
- CVE-2024-22533CRITICALCVSS 9.8EG 9.82024-02-02
Before Beetl v3.15.12, the rendering template has a server-side template injection (SSTI) vulnerability. When the incoming template is controllable, it will be filtered by the DefaultNativeSecurityManager blacklist. Because blacklist filte…
- CVE-2024-22632CRITICALCVSS 9.8EG 9.82024-04-26
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hmsg parameter. This vulnerability is triggered via a crafted POST request.
- CVE-2024-22633CRITICALCVSS 9.8EG 9.82024-04-26
Setor Informatica Sistema Inteligente para Laboratorios (S.I.L.) 388 was discovered to contain a remote code execution (RCE) vulnerability via the hprinter parameter. This vulnerability is triggered via a crafted POST request.
- CVE-2024-22722HIGHCVSS 7.2EG 7.22024-04-11
Server Side Template Injection (SSTI) vulnerability in Form Tools 3.1.1 allows attackers to run arbitrary commands via the Group Name field under the add forms section of the application.
- CVE-2024-22724MEDIUMCVSS 6.6EG 6.62024-03-21
An issue was discovered in osCommerce v4, allows local attackers to bypass file upload restrictions and execute arbitrary code via administrator profile photo upload feature.
- CVE-2024-22891CRITICALCVSS 9.8EG 9.82024-03-01
Nteract v.0.28.0 was discovered to contain a remote code execution (RCE) vulnerability via the Markdown link.
- CVE-2024-22899HIGHCVSS 8.8EG 8.82024-02-02
Vinchin Backup & Recovery v7.2 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the syncNtpTime function.
- CVE-2024-22988CRITICALCVSS 9.8EG 9.82024-02-23
ZKteco ZKBio WDMS before 9.0.2 Build 20250526 allows an attacker to download a database backup via the /files/backup/ component because the filename is based on a predictable timestamp.
- CVE-2024-23208HIGHCVSS 7.8EG 7.82024-01-23
The issue was addressed with improved memory handling. This issue is fixed in iOS 17.3 and iPadOS 17.3, macOS Sonoma 14.3, tvOS 17.3, watchOS 10.3. An app may be able to execute arbitrary code with kernel privileges.
- CVE-2024-23278HIGHCVSS 8.6EG 8.62024-03-08
The issue was addressed with improved checks. This issue is fixed in iOS 16.7.6 and iPadOS 16.7.6, iOS 17.4 and iPadOS 17.4, macOS Sonoma 14.4, macOS Ventura 13.6.5, tvOS 17.4, watchOS 10.4. An app may be able to break out of its sandbox.
- CVE-2024-23601CRITICALCVSS 9.8EG 9.82024-05-28
A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this v…
- CVE-2024-23692CRITICALCVSS 9.8EG 9.8⚠ KEV2024-05-31
Rejetto HTTP File Server, up to and including version 2.3m, is vulnerable to a template injection vulnerability. This vulnerability allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a…
- CVE-2024-23727HIGHCVSS 8.4EG 8.42024-03-28
The YI Smart Kami Vision com.kamivision.yismart application through 1.0.0_20231219 for Android allows a remote attacker to execute arbitrary JavaScript code via an implicit intent to the com.ants360.yicamera.activity.WebViewActivity compon…
- CVE-2024-23741CRITICALCVSS 9.8EG 9.82024-01-28
An issue in Hyper on macOS version 3.4.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings.
- CVE-2024-23742CRITICALCVSS 9.8EG 9.82024-01-28
An issue in Loom on macOS version 0.196.1 and before, allows remote attackers to execute arbitrary code via the RunAsNode and enableNodeClilnspectArguments settings. NOTE: the vendor disputes this because it requires local access to a vict…
- CVE-2024-23746CRITICALCVSS 9.8EG 9.82024-02-02
Miro Desktop 0.8.18 on macOS allows local Electron code injection via a complex series of steps that might be usable in some environments (bypass a kTCCServiceSystemPolicyAppBundles requirement via a file copy, an app.app/Contents rename, …
- CVE-2024-23750HIGHCVSS 8.8EG 8.82024-01-22
MetaGPT through 0.6.4 allows the QaEngineer role to execute arbitrary code because RunCode.run_script() passes shell metacharacters to subprocess.Popen.
- CVE-2024-23752CRITICALCVSS 9.8EG 9.82024-01-22
GenerateSDFPipeline in synthetic_dataframe in PandasAI (aka pandas-ai) through 1.5.17 allows attackers to trigger the generation of arbitrary Python code that is executed by SDFCodeExecutor. An attacker can create a dataframe that provides…
- CVE-2024-23755HIGHCVSS 8.8EG 8.82024-03-23
ClickUp Desktop before 3.3.77 on macOS and Windows allows code injection because of specific Electron Fuses. There is inadequate protection against code injection through settings such as RunAsNode.
- CVE-2024-23920HIGHCVSS 8.8EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2024-23921HIGHCVSS 8.8EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of ChargePoint Home Flex charging stations. Authentication is not required to exploit this vulnerability. The specific flaw exists wi…
- CVE-2024-23929HIGHCVSS 7.3EG 8.02025-01-31
This vulnerability allows network-adjacent attackers to create arbitrary files on affected installations of Pioneer DMH-WT7600NEX devices. Although authentication is required to exploit this vulnerability, the existing authentication mecha…
- CVE-2024-23963HIGHCVSS 8.0EG 8.82025-01-31
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine Halo9 devices. An attacker must first obtain the ability to pair a malicious Bluetooth device with the target system in orde…
- CVE-2024-24091CRITICALCVSS 9.8EG 9.82024-02-08
Yealink Meeting Server before v26.0.0.66 was discovered to contain an OS command injection vulnerability via the file upload interface.
- CVE-2024-24230HIGHCVSS 7.5EG 7.52024-03-18
Komm.One CMS 10.4.2.14 has a Server-Side Template Injection (SSTI) vulnerability via the Velocity template engine. It allows remote attackers to execute arbitrary code via a URL that specifies java.lang.Runtime in conjunction with getRunti…
- CVE-2024-24278HIGHCVSS 7.5EG 7.52024-03-05
An issue in Teamwire Windows desktop client v.2.0.1 through v.2.4.0 allows a remote attacker to obtain sensitive information via a crafted payload to the message function.
- CVE-2024-24294CRITICALCVSS 9.8EG 9.82024-05-20
A Prototype Pollution issue in Blackprint @blackprint/engine v.0.9.0 allows an attacker to execute arbitrary code via the _utils.setDeepProperty function of engine.min.js.
- CVE-2024-24396MEDIUMCVSS 6.1EG 6.12024-02-05
Cross Site Scripting vulnerability in Stimulsoft GmbH Stimulsoft Dashboard.JS before v.2024.1.2 allows a remote attacker to execute arbitrary code via a crafted payload to the search bar component.
- CVE-2024-24421CRITICALCVSS 9.8EG 9.82025-01-21
A type confusion in the nas_message_decode function of Magma <= 1.8.0 (fixed in v1.9 commit 08472ba98b8321f802e95f5622fa90fec2dea486) allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via a crafted NAS packet.
- CVE-2024-24469HIGHCVSS 8.8EG 8.82024-02-05
Cross Site Request Forgery vulnerability in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the delete_post .php.
- CVE-2024-24486CRITICALCVSS 9.1EG 9.12024-04-15
An issue discovered in silex technology DS-600 Firmware v.1.4.1 allows a remote attacker to edit device settings via the SAVE EEP_DATA command.
- CVE-2024-24520HIGHCVSS 7.8EG 7.82024-03-21
An issue in Lepton CMS v.7.0.0 allows a local attacker to execute arbitrary code via the upgrade.php file in the languages place.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →