CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 82 of 143
- CVE-2024-31396MEDIUMCVSS 6.6EG 6.62024-05-22
Code injection vulnerability exists in a-blog cms Ver.3.1.x series versions prior to Ver.3.1.12 and Ver.3.0.x series versions prior to Ver.3.0.32. If this vulnerability is exploited, a user with an administrator or higher privilege who can…
- CVE-2024-31465CRITICALCVSS 9.9EG 9.92024-04-10
XWiki Platform is a generic wiki platform. Starting in version 5.0-rc-1 and prior to versions 14.10.20, 15.5.4, and 15.9-rc-1, any user with edit right on any page can execute any code on the server by adding an object of type `XWiki.Searc…
- CVE-2024-31621HIGHCVSS 7.6EG 8.42024-04-29
An issue in FlowiseAI Inc Flowise v.1.6.2 and before allows a remote attacker to execute arbitrary code via a crafted script to the api/v1 component.
- CVE-2024-31648MEDIUMCVSS 6.1EG 6.12024-04-15
Cross Site Scripting (XSS) in Insurance Management System v1.0, allows remote attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Category Name parameter at /core/new_category2.
- CVE-2024-31666CRITICALCVSS 9.8EG 9.82024-04-22
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via a crafted script to the edit_addon_post.php component.
- CVE-2024-31807CRITICALCVSS 9.8EG 9.82024-04-08
TOTOLINK EX200 V4.0.3c.7646_B20201211 was discovered to contain a remote code execution (RCE) vulnerability via the hostTime parameter in the NTPSyncWithHost function.
- CVE-2024-31819CRITICALCVSS 9.8EG 9.82024-04-10
An issue in WWBN AVideo v.12.4 through v.14.2 allows a remote attacker to execute arbitrary code via the systemRootPath parameter of the submitIndex.php component.
- CVE-2024-31822CRITICALCVSS 9.8EG 9.82024-04-29
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the saveLanguageFiles method of the Languages.php component.
- CVE-2024-31823HIGHCVSS 8.8EG 8.82024-04-29
An issue in Ecommerce-CodeIgniter-Bootstrap commit v. d22b54e8915f167a135046ceb857caaf8479c4da allows a remote attacker to execute arbitrary code via the removeSecondaryImage method of the Publish.php component.
- CVE-2024-31864CRITICALCVSS 9.8EG 9.82024-04-09
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache Zeppelin. The attacker can inject sensitive configuration or malicious code when connecting MySQL database via JDBC driver. This issue affects Apache Zeppel…
- CVE-2024-31974MEDIUMCVSS 6.3EG 6.32024-05-17
The com.solarized.firedown (aka Solarized FireDown Browser & Downloader) application 1.0.76 for Android allows a remote attacker to execute arbitrary JavaScript code via a crafted intent. com.solarized.firedown.IntentActivity uses a WebVie…
- CVE-2024-31982CRITICALCVSS 10.0EG 10.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 2.4-milestone-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, XWiki's database search allows remote code execution through the search text. This allows remote code exe…
- CVE-2024-31984CRITICALCVSS 9.9EG 9.92024-04-10
XWiki Platform is a generic wiki platform. Starting in version 7.2-rc-1 and prior to versions 4.10.20, 15.5.4, and 15.10-rc-1, by creating a document with a specially crafted title, it is possible to trigger remote code execution in the (S…
- CVE-2024-31996CRITICALCVSS 10.0EG 10.02024-04-10
XWiki Platform is a generic wiki platform. Starting in version 3.0.1 and prior to versions 4.10.19, 15.5.4, and 15.10-rc-1, the HTML escaping of escaping tool that is used in XWiki doesn't escape `{`, which, when used in certain places, al…
- CVE-2024-32030HIGHCVSS 8.1EG 8.22024-06-19
Kafka UI is an Open-Source Web UI for Apache Kafka Management. Kafka UI API allows users to connect to different Kafka brokers by specifying their network address and port. As a separate feature, it also provides the ability to monitor the…
- CVE-2024-32350HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecPsk" parameter in the "cstecgi.cgi" binary.
- CVE-2024-32352HIGHCVSS 8.8EG 8.82024-05-14
TOTOLINK X5000R V9.1.0cu.2350_B20230313 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the "ipsecL2tpEnable" parameter in the "cstecgi.cgi" binary.
- CVE-2024-32358HIGHCVSS 7.5EG 7.52024-04-25
An issue in Jpress v.5.1.0 allows a remote attacker to execute arbitrary code via a crafted script to the custom plug-in module function, a different vulnerability than CVE-2024-43033.
- CVE-2024-32404MEDIUMCVSS 6.0EG 6.02024-04-26
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1, allows remote attackers to execute arbitrary code via a crafted payload to the Markup Sandbox feature.
- CVE-2024-32406HIGHCVSS 7.5EG 7.52024-04-26
Server-Side Template Injection (SSTI) vulnerability in inducer relate before v.2024.1 allows a remote attacker to execute arbitrary code via a crafted payload to the Batch-Issue Exam Tickets function.
- CVE-2024-32491CRITICALCVSS 9.8EG 9.82024-04-29
An issue was discovered in Znuny and Znuny LTS 6.0.31 through 6.5.7 and Znuny 7.0.1 through 7.0.16 where a logged-in user can upload a file (via a manipulated AJAX Request) to an arbitrary writable location by traversing paths. Arbitrary c…
- CVE-2024-32492HIGHCVSS 7.1EG 7.12024-04-29
An issue was discovered in Znuny 7.0.1 through 7.0.16 where the ticket detail view in the customer front allows the execution of external JavaScript.
- CVE-2024-32499MEDIUMCVSS 4.9EG 4.92025-04-28
Newforma Project Center Server through 2023.3.0.32259 allows remote code execution because .NET Remoting is exposed.
- CVE-2024-32599CRITICALCVSS 10.0EG 10.02024-04-18
Improper Control of Generation of Code ('Code Injection') vulnerability in Deepak anand WP Dummy Content Generator wp-dummy-content-generator.This issue affects WP Dummy Content Generator: from n/a through <= 3.2.1.
- CVE-2024-32641CRITICALCVSS 9.8EG 9.82025-12-03
Masa CMS is an open source Enterprise Content Management platform. Masa CMS versions prior to 7.2.8, 7.3.13, and 7.4.6 are vulnerable to remote code execution. The vulnerability exists in the addParam function, which accepts user input via…
- CVE-2024-32680HIGHCVSS 8.8EG 8.82024-05-17
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of Code ('Code Injection') vulnerability in PluginUS HUSKY – Products Filter for WooCommerce (formerly WOOF) allows Using Mali…
- CVE-2024-32925HIGHCVSS 8.8EG 8.82024-06-13
In dhd_prot_txstatus_process of dhd_msgbuf.c, there is a possible out of bounds write due to a missing bounds check. This could lead to remote code execution with no additional execution privileges needed. User interaction is not needed fo…
- CVE-2024-3319CRITICALCVSS 9.1EG 9.12024-05-15
An issue was identified in the Identity Security Cloud (ISC) Transform preview and IdentityProfile preview API endpoints that allowed an authenticated administrator to execute user-defined templates as part of attribute transforms which co…
- CVE-2024-33225HIGHCVSS 7.8EG 7.82024-05-22
An issue in the component RTKVHD64.sys of Realtek Semiconductor Corp Realtek(r) High Definition Audio Function Driver v6.0.9549.1 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-33228HIGHCVSS 8.4EG 8.42024-05-22
An issue in the component segwindrvx64.sys of Insyde Software Corp SEG Windows Driver v100.00.07.02 allows attackers to escalate privileges and execute arbitrary code via sending crafted IOCTL requests.
- CVE-2024-33294CRITICALCVSS 9.1EG 9.12024-05-06
An issue in Library System using PHP/MySQli with Source Code V1.0 allows a remote attacker to execute arbitrary code via the _FAILE variable in the student_edit_photo.php component.
- CVE-2024-33335MEDIUMCVSS 6.3EG 6.32024-06-20
SQL Injection vulnerability in H3C technology company SeaSQL DWS V2.0 allows a remote attacker to execute arbitrary code via a crafted file.
- CVE-2024-33394MEDIUMCVSS 5.9EG 5.92024-05-02
An issue in kubevirt kubevirt v1.2.0 and before allows a local attacker to execute arbitrary code via a crafted command to get the token component.
- CVE-2024-33430HIGHCVSS 8.8EG 8.82024-05-01
An issue in phiola/src/afilter/pcm_convert.h:513 of phiola v2.0-rc22 allows a remote attacker to execute arbitrary code via the a crafted .wav file.
- CVE-2024-33442MEDIUMCVSS 4.3EG 4.32024-05-01
An issue in flusity-CMS v.2.33 allows a remote attacker to execute arbitrary code via the add_post.php component.
- CVE-2024-33443HIGHCVSS 7.1EG 7.12024-04-29
An issue in onethink v.1.1 allows a remote attacker to execute arbitrary code via a crafted script to the AddonsController.class.php component.
- CVE-2024-33445CRITICALCVSS 9.8EG 9.82024-04-29
An issue in hisiphp v2.0.111 allows a remote attacker to execute arbitrary code via a crafted script to the SystemPlugins::mkInfo parameter in the SystemPlugins.php component.
- CVE-2024-33644CRITICALCVSS 9.9EG 9.92024-05-17
Improper Control of Generation of Code ('Code Injection') vulnerability in WPCustomify Customify Site Library allows Code Injection.This issue affects Customify Site Library: from n/a through 0.0.9.
- CVE-2024-33871HIGHCVSS 8.8EG 8.82024-07-03
An issue was discovered in Artifex Ghostscript before 10.03.1. contrib/opvp/gdevopvp.c allows arbitrary code execution via a custom Driver library, exploitable via a crafted PostScript document. This occurs because the Driver parameter for…
- CVE-2024-3408CRITICALCVSS 9.8EG 9.82024-06-06
man-group/dtale version 3.10.0 is vulnerable to an authentication bypass and remote code execution (RCE) due to improper input validation. The vulnerability arises from a hardcoded `SECRET_KEY` in the flask configuration, allowing attacker…
- CVE-2024-34225MEDIUMCVSS 6.1EG 6.12024-05-14
Cross Site Scripting vulnerability in php-lms/admin/?page=system_info in Computer Laboratory Management System using PHP and MySQL 1.0 allow remote attackers to inject arbitrary web script or HTML via the name, shortname parameters.
- CVE-2024-34344HIGHCVSS 8.8EG 8.82024-08-05
Nuxt is a free and open-source framework to create full-stack web applications and websites with Vue.js. Due to the insufficient validation of the `path` parameter in the NuxtTestComponentWrapper, an attacker can execute arbitrary JavaScri…
- CVE-2024-34405CRITICALCVSS 9.1EG 9.12024-06-11
Improper deep link validation in McAfee Security: Antivirus VPN for Android before 8.3.0 could allow an attacker to launch an arbitrary URL within the app.
- CVE-2024-34461CRITICALCVSS 9.8EG 9.82024-05-04
Zenario before 9.5.60437 uses Twig filters insecurely in the Twig Snippet plugin, and in the site-wide HEAD and BODY elements, enabling code execution by a designer or an administrator.
- CVE-2024-34761HIGHCVSS 8.5EG 8.52024-06-10
Vulnerability discovered by executing a planned security audit. Improper Control of Generation of Code ('Code Injection') vulnerability in WPENGINE INC Advanced Custom Fields PRO allows Code Injection.This issue affects Advanced Custom Fi…
- CVE-2024-35226HIGHCVSS 7.3EG 7.32024-05-28
Smarty is a template engine for PHP, facilitating the separation of presentation (HTML/CSS) from application logic. In affected versions template authors could inject php code by choosing a malicious file name for an extends-tag. Sites tha…
- CVE-2024-35285CRITICALCVSS 9.8EG 9.82024-10-21
A vulnerability in NuPoint Messenger (NPM) of Mitel MiCollab through 9.8.0.33 allows an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization.
- CVE-2024-35314CRITICALCVSS 9.8EG 9.82024-10-21
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an unauthenticated attacker to conduct a command injection attack due to insufficien…
- CVE-2024-35315MEDIUMCVSS 5.6EG 5.62024-10-21
A vulnerability in the Desktop Client of Mitel MiCollab through 9.7.1.110, and MiVoice Business Solution Virtual Instance (MiVB SVI) 1.0.0.25, could allow an authenticated attacker to conduct a privilege escalation attack due to improper f…
- CVE-2024-35339CRITICALCVSS 9.8EG 9.82024-05-24
Tenda FH1206 V1.2.0.8(8155) was discovered to contain a command injection vulnerability via the mac parameter at ip/goform/WriteFacMac.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →