CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 81 of 143
- CVE-2024-28424HIGHCVSS 8.8EG 8.82024-03-14
zenml v0.55.4 was discovered to contain an arbitrary file upload vulnerability in the load function at /materializers/cloudpickle_materializer.py. This vulnerability allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-28593MEDIUMCVSS 5.4EG 5.42024-03-22
The Chat activity in Moodle 4.3.3 allows students to insert a potentially unwanted HTML A element or IMG element, or HTML content that leads to a performance degradation. NOTE: the vendor's Using_Chat page says "If you know some HTML code,…
- CVE-2024-28699HIGHCVSS 7.8EG 7.82024-04-22
A buffer overflow vulnerability in pdf2json v0.70 allows a local attacker to execute arbitrary code via the GString::copy() and ImgOutputDev::ImgOutputDev function.
- CVE-2024-28811LOWCVSS 3.3EG 3.32024-09-30
An issue was discovered in Infinera hiT 7300 5.60.50. A web application allows a remote privileged attacker to execute applications contained in a specific OS directory via HTTP invocations.
- CVE-2024-28847HIGHCVSS 8.8EG 8.82024-03-15
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. Similarly to the GHSL-2023-250 issue, `AlertUtil::validateExpressi…
- CVE-2024-28848HIGHCVSS 8.8EG 8.82024-03-15
OpenMetadata is a unified platform for discovery, observability, and governance powered by a central metadata repository, in-depth lineage, and seamless team collaboration. The `CompiledRule::validateExpression` method evaluates an SpEL…
- CVE-2024-28886HIGHCVSS 8.4EG 8.42024-05-28
OS command injection vulnerability exists in UTAU versions prior to v0.4.19. If a user of the product opens a crafted UTAU project file (.ust file), an arbitrary OS command may be executed.
- CVE-2024-28893HIGHCVSS 7.7EG 7.72024-05-01
Certain HP software packages (SoftPaqs) are potentially vulnerable to arbitrary code execution when the SoftPaq configuration file has been modified after extraction. HP has released updated software packages (SoftPaqs).
- CVE-2024-29014HIGHCVSS 8.8EG 8.82024-07-18
Vulnerability in SonicWall SMA100 NetExtender Windows (32 and 64-bit) client 10.2.339 and earlier versions allows an attacker to arbitrary code execution when processing an EPC Client update.
- CVE-2024-29178HIGHCVSS 8.8EG 8.82024-07-18
On versions before 2.1.4, a user could log in and perform a template injection attack resulting in Remote Code Execution on the server, The attacker must successfully log into the system to launch an attack, so this is a moderate-impact v…
- CVE-2024-29201CRITICALCVSS 9.9EG 9.92024-03-29
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can bypass the input validation mechanism in JumpServer's Ansible to execute arbitrary code within the Celery container. Since the …
- CVE-2024-29202CRITICALCVSS 9.9EG 9.92024-03-29
JumpServer is an open source bastion host and an operation and maintenance security audit system. Attackers can exploit a Jinja2 template injection vulnerability in JumpServer's Ansible to execute arbitrary code within the Celery container…
- CVE-2024-29209MEDIUMCVSS 6.0EG 6.02024-05-07
A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine. The vulnerability arises from the appl…
- CVE-2024-29276CRITICALCVSS 9.8EG 9.82024-04-02
An issue was discovered in seeyonOA version 8, allows remote attackers to execute arbitrary code via the importProcess method in WorkFlowDesignerController.class component.
- CVE-2024-29309HIGHCVSS 7.7EG 7.72024-05-02
An issue in Alfresco Content Services v.23.3.0.7 allows a remote attacker to execute arbitrary code via the Transfer Service.
- CVE-2024-29399HIGHCVSS 7.6EG 7.62024-04-11
An issue was discovered in GNU Savane v.3.13 and before, allows a remote attacker to execute arbitrary code and escalate privileges via a crafted file to the upload.php component.
- CVE-2024-29409MEDIUMCVSS 5.5EG 5.52025-03-14
File Upload vulnerability in nestjs nest v.10.3.2 allows a remote attacker to execute arbitrary code via the Content-Type header.
- CVE-2024-29477HIGHCVSS 8.8EG 8.82024-04-03
Lack of sanitization during Installation Process in Dolibarr ERP CRM up to version 19.0.0 allows an attacker with adjacent access to the network to execute arbitrary code via a specifically crafted input.
- CVE-2024-29500CRITICALCVSS 9.8EG 9.82024-04-10
An issue in the kiosk mode of Secure Lockdown Multi Application Edition v2.00.219 allows attackers to execute arbitrary code via running a ClickOnce application instance.
- CVE-2024-29513HIGHCVSS 7.8EG 7.82024-05-14
An issue in briscKernelDriver.sys in BlueRiSC WindowsSCOPE Cyber Forensics before 3.3 allows a local attacker to execute arbitrary code within the driver and create a local denial-of-service condition due to an improper DACL being applied …
- CVE-2024-29937CRITICALCVSS 9.8EG 9.82024-04-11
NFS in a BSD derived codebase, as used in OpenBSD through 7.4 and FreeBSD through 14.0-RELEASE, allows remote attackers to execute arbitrary code via a bug that is unrelated to memory corruption.
- CVE-2024-29991MEDIUMCVSS 5.0EG 5.02024-04-19
Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability
- CVE-2024-30202HIGHCVSS 7.8EG 7.82024-03-25
In Emacs before 29.3, arbitrary Lisp code is evaluated as part of turning on Org mode. This affects Org Mode before 9.6.23.
- CVE-2024-3044MEDIUMCVSS 6.5EG 6.52024-05-14
Unchecked script execution in Graphic on-click binding in affected LibreOffice versions allows an attacker to create a document which without prompt will execute scripts built-into LibreOffice on clicking a graphic. Such scripts were previ…
- CVE-2024-30565HIGHCVSS 8.8EG 8.82024-04-04
An issue was discovered in SeaCMS version 12.9, allows remote attackers to execute arbitrary code via admin notify.php.
- CVE-2024-30567MEDIUMCVSS 6.3EG 6.32024-04-16
An issue in JNT Telecom JNT Liftcom UMS V1.J Core Version JM-V15 allows a remote attacker to execute arbitrary code via the Network Troubleshooting functionality.
- CVE-2024-30568CRITICALCVSS 9.8EG 9.82024-04-03
Netgear R6850 1.1.0.88 was discovered to contain a command injection vulnerability via the c4-IPAddr parameter.
- CVE-2024-30845MEDIUMCVSS 6.1EG 6.12024-04-12
Cross Site Scripting vulnerability in Rainbow external link network disk v.5.5 allows a remote attacker to execute arbitrary code via the validation component of the input parameters.
- CVE-2024-30858CRITICALCVSS 9.8EG 9.82024-04-01
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/edit_fire_wall.php.
- CVE-2024-30868CRITICALCVSS 9.8EG 9.82024-04-01
netentsec NS-ASG 6.3 is vulnerable to SQL Injection via /admin/add_getlogin.php.
- CVE-2024-30878MEDIUMCVSS 6.1EG 6.12024-04-11
A cross-site scripting (XSS) vulnerability in RageFrame2 v2.6.43, allows remote attackers to execute arbitrary web scripts or HTML and obtain sensitive information via a crafted payload injected into the upload_drive parameter.
- CVE-2024-30923CRITICALCVSS 9.8EG 9.82024-04-18
SQL Injection vulnerability in DerbyNet v9.0 and below allows a remote attacker to execute arbitrary code via the where Clause in Racer Document Rendering
- CVE-2024-30961HIGHCVSS 7.8EG 7.82024-12-05
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the error-thrown mechanism in nav2_bt_navigator.
- CVE-2024-30962HIGHCVSS 7.8EG 7.82024-12-05
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the nav2_amcl process
- CVE-2024-30963HIGHCVSS 7.8EG 7.82024-12-05
Buffer Overflow vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via a crafted script.
- CVE-2024-30964HIGHCVSS 7.8EG 7.82024-12-05
Insecure Permissions vulnerability in Open Robotics Robotic Operating System 2 (ROS2) navigation2- ROS2-humble and navigation 2-humble allows a local attacker to execute arbitrary code via the initial_pose_sub thread created by nav2_bt_nav…
- CVE-2024-30973HIGHCVSS 8.8EG 8.82024-05-06
An issue in V-SOL G/EPON ONU HG323AC-B with firmware version V2.0.08-210715 allows an attacker to execute arbtirary code and obtain sensitive information via crafted POST request to /boaform/getASPdata/formFirewall, /boaform/getASPdata/for…
- CVE-2024-3098CRITICALCVSS 9.8EG 9.82024-04-10
A vulnerability was identified in the `exec_utils` class of the `llama_index` package, specifically within the `safe_eval` function, allowing for prompt injection leading to arbitrary code execution. This issue arises due to insufficient v…
- CVE-2024-31003HIGHCVSS 8.8EG 8.82024-04-02
Buffer Overflow vulnerability in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the AP4_MemoryByteStream::WritePartial at Ap4ByteStream.cpp.
- CVE-2024-31004CRITICALCVSS 9.8EG 9.82024-04-02
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4StsdAtom.cpp,AP4_StsdAtom::AP4_StsdAtom,mp4fragment.
- CVE-2024-31005HIGHCVSS 8.1EG 8.12024-04-02
An issue in Bento4 Bento v.1.6.0-641 allows a remote attacker to execute arbitrary code via the Ap4MdhdAtom.cpp,AP4_MdhdAtom::AP4_MdhdAtom,mp4fragment
- CVE-2024-31011CRITICALCVSS 9.8EG 9.82024-04-03
Arbitrary file write vulnerability in beescms v.4.0, allows a remote attacker to execute arbitrary code via a file path that was not isolated and the suffix was not verified in admin_template.php.
- CVE-2024-31013MEDIUMCVSS 6.1EG 6.12024-04-03
Cross Site Scripting (XSS) vulnerability in emlog version Pro 2.3, allow remote attackers to execute arbitrary code via a crafted payload to the bottom of the homepage in footer_info parameter.
- CVE-2024-31022CRITICALCVSS 9.8EG 9.82024-04-08
An issue was discovered in CandyCMS version 1.0.0, allows remote attackers to execute arbitrary code via the install.php component.
- CVE-2024-31032CRITICALCVSS 9.8EG 9.82024-03-29
An issue in Huashi Private Cloud CDN Live Streaming Acceleration Server hgateway-sixport v.1.1.2 allows a remote attacker to execute arbitrary code via the manager/ipping.php component.
- CVE-2024-3105CRITICALCVSS 9.9EG 9.92024-06-15
The Woody code snippets – Insert Header Footer Code, AdSense Ads plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.5.0 via the 'insert_php' shortcode. This is due to the plugin not restri…
- CVE-2024-3121MEDIUMCVSS 3.3EG 6.82024-06-24
A remote code execution vulnerability exists in the create_conda_env function of the parisneo/lollms repository, version 5.9.0. The vulnerability arises from the use of shell=True in the subprocess.Popen function, which allows an attacker …
- CVE-2024-31266CRITICALCVSS 9.1EG 9.12024-04-25
Improper Control of Generation of Code ('Code Injection') vulnerability in AlgolPlus Advanced Order Export For WooCommerce allows Code Injection.This issue affects Advanced Order Export For WooCommerce: from n/a through 3.4.4.
- CVE-2024-31380CRITICALCVSS 9.9EG 9.92024-04-03
Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Oxygen Builder allows Code Injection. Vendor is ignoring report, refuses to patch the issue.This issue affects Oxygen Builder: from n/a through 4.9.
- CVE-2024-31390CRITICALCVSS 9.9EG 9.92024-04-03
: Improper Control of Generation of Code ('Code Injection') vulnerability in Soflyy Breakdance allows : Code Injection.This issue affects Breakdance: from n/a through 1.7.2.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →