CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,127 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 83 of 143
- CVE-2024-35515CRITICALCVSS 9.8EG 9.82024-09-18
Insecure deserialization in sqlitedict up to v2.1.0 allows attackers to execute arbitrary code.
- CVE-2024-35581MEDIUMCVSS 6.1EG 6.12024-05-28
A cross-site scripting (XSS) vulnerability in Sourcecodester Laboratory Management System v1.0 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Borrower Name input field.
- CVE-2024-3562HIGHCVSS 8.8EG 8.82024-06-20
The Custom Field Suite plugin for WordPress is vulnerable to PHP Code Injection in all versions up to, and including, 2.6.7 via the Loop custom field. This is due to insufficient sanitization of input prior to being used in a call to the e…
- CVE-2024-36057CRITICALCVSS 9.8EG 9.82026-04-07
Koha Library before 23.05.10 fails to sanitize user-controllable filenames prior to unzipping, leading to remote code execution. The line "qx/unzip $filename -d $dirname/;" in upload-cover-image.pl is vulnerable to command injection via sh…
- CVE-2024-36074HIGHCVSS 7.2EG 7.22024-06-27
Netwrix CoSoSys Endpoint Protector through 5.9.3 and CoSoSys Unify through 7.0.6 contain a remote code execution vulnerability in the Endpoint Protector and Unify agent in the way that the EasyLock dependency is acquired from the server. A…
- CVE-2024-36075MEDIUMCVSS 6.5EG 6.52024-06-27
The CoSoSys Endpoint Protector through 5.9.3 and Unify agent through 7.0.6 is susceptible to an arbitrary code execution vulnerability due to the way an archive obtained from the Endpoint Protector or Unify server is extracted on the endpo…
- CVE-2024-36078MEDIUMCVSS 6.7EG 6.72024-05-19
In Zammad before 6.3.1, a Ruby gem bundled by Zammad is installed with world-writable file permissions. This allowed a local attacker on the server to modify the gem's files, injecting arbitrary code into Zammad processes (which run with t…
- CVE-2024-36120HIGHCVSS 8.1EG 8.12024-05-31
javascript-deobfuscator removes common JavaScript obfuscation techniques. In affected versions crafted payloads targeting expression simplification can lead to code execution. This issue has been patched in version 1.1.0. Users are advised…
- CVE-2024-36268CRITICALCVSS 9.8EG 9.82024-08-02
Improper Control of Generation of Code ('Code Injection') vulnerability in Apache InLong. This issue affects Apache InLong: from 1.10.0 through 1.12.0, which could lead to Remote Code Execution. Users are advised to upgrade to Apache InLo…
- CVE-2024-36361MEDIUMCVSS 6.8EG 6.82024-05-24
Pug through 3.0.2 allows JavaScript code execution if an application accepts untrusted input for the name option of the compileClient, compileFileClient, or compileClientWithDependenciesTracked function. NOTE: these functions are for compi…
- CVE-2024-36401CRITICALCVSS 9.8EG 9.8⚠ KEV2024-07-01
GeoServer is an open source server that allows users to share and edit geospatial data. Prior to versions 2.22.6, 2.23.6, 2.24.4, and 2.25.2, multiple OGC request parameters allow Remote Code Execution (RCE) by unauthenticated users throug…
- CVE-2024-36456CRITICALCVSS 9.4EG 9.42024-07-15
This vulnerability allows an unauthenticated attacker to achieve remote command execution on the affected PAM system by uploading a specially crafted PAM upgrade file.
- CVE-2024-36531MEDIUMCVSS 5.7EG 5.72024-06-10
nukeviet v.4.5 and before and nukeviet-egov v.1.2.02 and before are vulnerable to arbitrary code execution via the /admin/extensions/upload.php component.
- CVE-2024-36568CRITICALCVSS 9.8EG 9.82024-06-03
Sourcecodester Gas Agency Management System v1.0 is vulnerable to SQL Injection via /gasmark/editbrand.php?id=.
- CVE-2024-36575CRITICALCVSS 9.8EG 9.82024-06-17
A Prototype Pollution issue in getsetprop 1.1.0 allows an attacker to execute arbitrary code via global.accessor.
- CVE-2024-36581HIGHCVSS 7.6EG 7.62024-06-17
A Prototype Pollution issue in abw badger-database 1.2.1 allows an attacker to execute arbitrary code via dist/badger-database.esm.
- CVE-2024-36598HIGHCVSS 8.1EG 8.12024-06-14
An arbitrary file upload vulnerability in Aegon Life v1.0 allows attackers to execute arbitrary code via uploading a crafted image file.
- CVE-2024-3660CRITICALCVSS 9.8EG 9.82024-04-16
A arbitrary code injection vulnerability in TensorFlow's Keras framework (<2.13) allows attackers to execute arbitrary code with the same permissions as the application using a model that allow arbitrary code irrespective of the applicatio…
- CVE-2024-36622CRITICALCVSS 9.8EG 9.82024-11-29
In RaspAP raspap-webgui 3.0.9 and earlier, a command injection vulnerability exists in the clearlog.php script. The vulnerability is due to improper sanitization of user input passed via the logfile parameter.
- CVE-2024-36679CRITICALCVSS 10.0EG 10.02024-06-19
In the module "Module Live Chat Pro (All in One Messaging)" (livechatpro) <=8.4.0, a guest can perform PHP Code injection. Due to a predictable token, the method `Lcp::saveTranslations()` suffer of a white writer that can inject PHP code i…
- CVE-2024-36694HIGHCVSS 7.2EG 8.02024-12-18
OpenCart 4.0.2.3 is vulnerable to Server-Side Template Injection (SSTI) via the Theme Editor Function.
- CVE-2024-37014CRITICALCVSS 9.8EG 9.82024-06-10
Langflow through 0.6.19 allows remote code execution if untrusted users are able to reach the "POST /api/v1/custom_component" endpoint and provide a Python script.
- CVE-2024-37061HIGHCVSS 8.8EG 8.82024-06-04
Remote Code Execution can occur in versions of the MLflow platform running version 1.11.0 or newer, enabling a maliciously crafted MLproject to execute arbitrary code on an end user’s system when run.
- CVE-2024-37084CRITICALCVSS 9.8EG 9.82024-07-25
In Spring Cloud Data Flow versions prior to 2.11.4, a malicious user who has access to the Skipper server api can use a crafted upload request to write an arbitrary file to any location on the file system which could lead to compromisin…
- CVE-2024-37109CRITICALCVSS 9.9EG 9.92024-06-24
Improper Control of Generation of Code ('Code Injection') vulnerability in Membership Software WishList Member X allows Code Injection.This issue affects WishList Member X: from n/a before 3.26.7.
- CVE-2024-37124CRITICALCVSS 9.8EG 9.82024-06-19
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.
- CVE-2024-37149HIGHCVSS 7.2EG 7.22024-07-10
GLPI is an open-source asset and IT management software package that provides ITIL Service Desk features, licenses tracking and software auditing. An authenticated technician user can upload a malicious PHP script and hijack the plugin loa…
- CVE-2024-37273CRITICALCVSS 9.8EG 9.82024-06-04
An arbitrary file upload vulnerability in the /v1/app/appendFileSync interface of Jan v0.4.12 allows attackers to execute arbitrary code via uploading a crafted file.
- CVE-2024-37287CRITICALCVSS 9.1EG 9.12024-08-13
A flaw allowing arbitrary code execution was discovered in Kibana. An attacker with access to ML and Alerting connector features, as well as write access to internal ML indices can trigger a prototype pollution vulnerability, ultimately le…
- CVE-2024-3734MEDIUMCVSS 6.5EG 6.52024-05-02
The FOX – Currency Switcher Professional for WooCommerce plugin is vulnerable to Unauthenticated Arbitrary Shortcode Execution in versions up to, and including, 1.4.1.8. This allows unauthenticated attackers to execute arbitrary shortcod…
- CVE-2024-37382HIGHCVSS 7.2EG 7.22024-08-08
An issue discovered in import host feature in Ab Initio Metadata Hub and Authorization Gateway before 4.3.1.1 allows attackers to run arbitrary code via crafted modification of server configuration.
- CVE-2024-37405MEDIUMCVSS 6.5EG 6.52024-07-12
Livechat messages can be leaked by combining two NoSQL injections affecting livechat:loginByToken (pre-authentication) and livechat:loadHistory.
- CVE-2024-37743CRITICALCVSS 9.8EG 9.82025-06-24
An issue in mmzdev KnowledgeGPT V.0.0.5 allows a remote attacker to execute arbitrary code via the Document Display Component.
- CVE-2024-37770CRITICALCVSS 9.1EG 9.12024-07-10
14Finger v1.1 was discovered to contain a remote command execution (RCE) vulnerability in the fingerprint function. This vulnerability allows attackers to execute arbitrary commands via a crafted payload.
- CVE-2024-37773MEDIUMCVSS 4.8EG 4.82024-12-16
An HTML injection vulnerability in Sunbird DCIM dcTrack 9.1.2 allows attackers authenticated as administrators to inject arbitrary HTML code in an admin screen.
- CVE-2024-37777HIGHCVSS 8.8EG 8.82025-08-27
O2OA v9.0.3 was discovered to contain a remote code execution (RCE) vulnerability via the mainOutput() function.
- CVE-2024-37779HIGHCVSS 8.8EG 8.82024-09-23
WoodWing Elvis DAM v6.98.1 was discovered to contain an authenticated remote command execution (RCE) vulnerability via the Apache Ant script functionality.
- CVE-2024-37821HIGHCVSS 8.8EG 8.82024-06-18
An arbitrary file upload vulnerability in the Upload Template function of Dolibarr ERP CRM up to v19.0.1 allows attackers to execute arbitrary code via uploading a crafted .SQL file.
- CVE-2024-3784MEDIUMCVSS 6.6EG 6.62024-04-15
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 Accounts (/admin/CloudAccounts). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.
- CVE-2024-37845HIGHCVSS 7.2EG 7.22024-10-25
MangoOS before 5.2.0 was discovered to contain an authenticated remote code execution (RCE) vulnerability via the Active Process Command feature.
- CVE-2024-37846CRITICALCVSS 4.6EG 9.82024-10-25
MangoOS before 5.2.0 was discovered to contain a Client-Side Template Injection (CSTI) vulnerability via the Platform Management Edit page.
- CVE-2024-37849CRITICALCVSS 9.8EG 9.82024-06-13
A SQL Injection vulnerability in itsourcecode Billing System 1.0 allows a local attacker to execute arbitrary code in process.php via the username parameter.
- CVE-2024-3785MEDIUMCVSS 6.6EG 6.62024-04-15
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device NAS shared section (/admin/DeviceNAS). Exploitation of this vulnerability could allow a remote user to execute arbit…
- CVE-2024-37855HIGHCVSS 8.4EG 8.42024-06-25
An issue in Nepstech Wifi Router xpon (terminal) NTPL-Xpon1GFEVN, hardware verstion 1.0 firmware 2.0.1 allows a remote attacker to execute arbitrary code via the router's Telnet port 2345 without requiring authentication credentials.
- CVE-2024-3786MEDIUMCVSS 6.6EG 6.62024-04-15
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through Device Synchronizations (/admin/DeviceReplication). Exploitation of this vulnerability could allow a remote user to execute…
- CVE-2024-37860HIGHCVSS 7.3EG 7.32024-12-05
Buffer Overflow vulnerability in Open Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_amcl process
- CVE-2024-37862HIGHCVSS 7.3EG 7.32024-12-05
Buffer Overflow vulnerability in Open Robotic Robotic Operating System 2 ROS2 navigation2- ROS2-humble&& navigation2-humble allows a local attacker to execute arbitrary code via a crafted .yaml file to the nav2_planner process.
- CVE-2024-3787MEDIUMCVSS 6.6EG 6.62024-05-14
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through S3 disks (/admin/DeviceS3). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.
- CVE-2024-3788MEDIUMCVSS 6.6EG 6.62024-05-14
Vulnerability in WBSAirback 21.02.04, which involves improper neutralisation of Server-Side Includes (SSI), through License (/admin/CDPUsers). Exploitation of this vulnerability could allow a remote user to execute arbitrary code.
- CVE-2024-37885LOWCVSS 3.8EG 3.82024-06-14
The Nextcloud Desktop Client is a tool to synchronize files from Nextcloud Server with your computer. A code injection in Nextcloud Desktop Client for macOS allowed to load arbitrary code when starting the client with DYLD_INSERT_LIBRARIES…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →