CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,130 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 87 of 143
- CVE-2024-45850HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘IN…
- CVE-2024-45851HIGHCVSS 8.8EG 8.82024-09-12
An arbitrary code execution vulnerability exists in versions 23.10.5.0 up to 24.7.4.1 of the MindsDB platform, when the Microsoft SharePoint integration is installed on the server. For databases created with the SharePoint engine, an ‘IN…
- CVE-2024-45873CRITICALCVSS 9.8EG 9.82024-10-07
A DLL hijacking vulnerability in VegaBird Yaazhini 2.0.2 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Yaazhini.exe.
- CVE-2024-45874CRITICALCVSS 9.8EG 9.82024-10-07
A DLL hijacking vulnerability in VegaBird Vooki 5.2.9 allows attackers to execute arbitrary code / maintain persistence via placing a crafted DLL file in the same directory as Vooki.exe.
- CVE-2024-45933MEDIUMCVSS 6.6EG 6.62024-10-07
OnlineNewsSite v1.0 is vulnerable to Cross Site Scripting (XSS) which allows attackers to execute arbitrary code via the Title and summary fields in the /admin/post/edit/ endpoint.
- CVE-2024-4605HIGHCVSS 8.8EG 8.82024-05-14
The Breakdance plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.7.1 via post meta data. This is due to the plugin storing custom data in metadata without an underscore prefix. This makes i…
- CVE-2024-46076CRITICALCVSS 9.8EG 9.82024-10-07
RuoYi v4.7.9 and before has a security flaw that allows escaping from comments within the code generation feature, enabling the injection of malicious code.
- CVE-2024-46080HIGHCVSS 8.0EG 8.02024-10-01
Scriptcase v9.10.023 and before is vulnerable to Remote Code Execution (RCE) via the nm_zip function.
- CVE-2024-46103CRITICALCVSS 9.8EG 9.82024-09-20
SEMCMS 4.8 is vulnerable to SQL Injection via SEMCMS_Main.php.
- CVE-2024-46489HIGHCVSS 8.8EG 8.82024-09-25
A remote command execution (RCE) vulnerability in promptr v6.0.7 allows attackers to execute arbitrary commands via a crafted URL.
- CVE-2024-46507HIGHCVSS 7.3EG 7.32026-05-08
A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.
- CVE-2024-4662HIGHCVSS 8.8EG 8.82024-05-23
The Oxygen Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.8.2 via post metadata. This is due to the plugin storing custom data in post metadata without an underscore prefix. This…
- CVE-2024-46639HIGHCVSS 7.6EG 7.62024-09-23
A cross-site scripting (XSS) vulnerability in HelpDeskZ v2.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name text field of Custom Fields message box.
- CVE-2024-46640CRITICALCVSS 9.8EG 9.82024-09-20
SeaCMS 13.2 has a remote code execution vulnerability located in the file sql.class.chp. Although the system has a check function, the check function is not executed during execution, allowing remote code execution by writing to the file t…
- CVE-2024-46960HIGHCVSS 8.8EG 8.82024-11-07
The ASD com.rocks.video.downloader (aka HD Video Downloader All Format) application through 7.0.129 for Android allows an attacker to execute arbitrary JavaScript code via the com.rocks.video.downloader.MainBrowserActivity component.
- CVE-2024-46961HIGHCVSS 8.1EG 8.12024-11-07
The Inshot com.downloader.privatebrowser (aka Video Downloader - XDownloader) application through 1.3.5 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.privatebrowser.activity.PrivateMainActivity …
- CVE-2024-46962CRITICALCVSS 9.1EG 9.12024-11-11
The SYQ com.downloader.video.fast (aka Master Video Downloader) application through 2.0 for Android allows an attacker to execute arbitrary JavaScript code via the com.downloader.video.fast.SpeedMainAct component.
- CVE-2024-46963HIGHCVSS 8.1EG 8.12024-11-11
The com.superfast.video.downloader (aka Super Unlimited Video Downloader - All in One) application through 5.1.9 for Android allows an attacker to execute arbitrary JavaScript code via the com.bluesky.browser.ui.BrowserMainActivity compone…
- CVE-2024-46964HIGHCVSS 8.1EG 8.12024-11-11
The com.video.downloader.all (aka All Video Downloader) application through 11.28 for Android allows an attacker to execute arbitrary JavaScript code via the com.video.downloader.all.StartActivity component.
- CVE-2024-46965MEDIUMCVSS 5.4EG 5.42024-11-11
The DS allvideo.downloader.browser (aka Fast Video Downloader: Browser) application through 1.6-RC1 for Android allows an attacker to execute arbitrary JavaScript code via the allvideo.downloader.browser.DefaultBrowserActivity component.
- CVE-2024-46966HIGHCVSS 8.1EG 8.12024-11-11
The Ikhgur mn.ikhgur.khotoch (aka Video Downloader Pro & Browser) application through 1.0.42 for Android allows an attacker to execute arbitrary JavaScript code via the mn.ikhgur.khotoch.MainActivity component.
- CVE-2024-47051CRITICALCVSS 9.1EG 9.12025-02-26
This advisory addresses two critical security vulnerabilities present in Mautic versions before 5.2.3. These vulnerabilities could be exploited by authenticated users. * Remote Code Execution (RCE) via Asset Upload: A Remote Code Exec…
- CVE-2024-47158HIGHCVSS 5.4EG 7.42024-10-25
N-LINE 2.0.6 and prior versions contain a code injection vulnerability. If this vulnerability is exploited, arbitrary code may be executed on the instructor's browser, or the instructor may be directed to a malicious website.
- CVE-2024-47208CRITICALCVSS 9.8EG 9.82024-11-18
Server-Side Request Forgery (SSRF), Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 18.12.17. Users are recommended to upgrade to version 18.12.17, which fi…
- CVE-2024-47219CRITICALCVSS 9.8EG 9.82024-09-22
An issue was discovered in vesoft NebulaGraph through 3.8.0. It allows shell command injection.
- CVE-2024-47826LOWCVSS 3.5EG 3.52024-10-14
eLabFTW is an open source electronic lab notebook for research labs. A vulnerability in versions prior to 5.1.5 allows an attacker to inject arbitrary HTML tags in the pages: "experiments.php" (show mode), "database.php" (show mode) or "se…
- CVE-2024-47879HIGHCVSS 7.6EG 7.62024-10-24
OpenRefine is a free, open source tool for working with messy data. Prior to version 3.8.3, lack of cross-site request forgery protection on the `preview-expression` command means that visiting a malicious website could cause an attacker-c…
- CVE-2024-48050CRITICALCVSS 9.8EG 9.82024-11-04
In agentscope <=v0.0.4, the file agentscope\web\workstation\workflow_utils.py has the function is_callable_expression. Within this function, the line result = eval(s) poses a security risk as it can directly execute user-provided commands.
- CVE-2024-48061CRITICALCVSS 9.8EG 9.82024-11-04
langflow <=1.0.18 is vulnerable to Remote Code Execution (RCE) as any component provided the code functionality and the components run on the local machine rather than in a sandbox.
- CVE-2024-48070CRITICALCVSS 9.8EG 9.82024-11-19
An issue in Weaver E-cology v. attackers construct special requests to insert remote malicious code and to trigger malicious code execution, and control server privileges
- CVE-2024-48138CRITICALCVSS 9.8EG 9.82024-10-29
A remote code execution (RCE) vulnerability in the component /PluXml/core/admin/parametres_edittpl.php of PluXml v5.8.16 and lower allows attackers to execute arbitrary code via injecting a crafted payload into a template.
- CVE-2024-48168CRITICALCVSS 9.8EG 9.82024-10-14
A stack overflow vulnerability exists in the sub_402280 function of the HNAP service of D-Link DCS-960L 1.09, allowing an attacker to execute arbitrary code.
- CVE-2024-48204CRITICALCVSS 9.8EG 9.82024-10-25
SQL injection vulnerability in Hanzhou Haobo network management system 1.0 allows a remote attacker to execute arbitrary code via a crafted script.
- CVE-2024-48235MEDIUMCVSS 6.5EG 6.52024-10-25
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the save method of the TemplateController.java file.
- CVE-2024-48236MEDIUMCVSS 6.5EG 6.52024-10-25
An issue in ofcms 1.1.2 allows a remote attacker to execute arbitrary code via the FileOutputStream function in the write String method of the ofcms-admin\src\main\java\com\ofsoft\cms\core\uitle\FileUtils.java file
- CVE-2024-48279HIGHCVSS 7.6EG 7.62024-10-15
A HTML Injection vulnerability was found in /search-result.php of PHPGurukul User Registration & Login and User Management System 3.2. This vulnerability allows remote attackers to execute arbitrary HTML code via the searchkey parameter in…
- CVE-2024-48359CRITICALCVSS 9.8EG 9.82024-10-31
Qualitor v8.24 was discovered to contain a remote code execution (RCE) vulnerability via the gridValoresPopHidden parameter.
- CVE-2024-48453CRITICALCVSS 9.8EG 9.82024-12-04
An issue in INOVANCE AM401_CPU1608TPTN allows a remote attacker to execute arbitrary code via the ExecuteUserProgramUpgrade function
- CVE-2024-48514CRITICALCVSS 9.8EG 9.82024-10-24
php-heic-to-jpg <= 1.0.5 is vulnerable to code injection (fixed in 1.0.6). An attacker who can upload heic images is able to execute code on the remote server via the file name. As a result, the CIA is no longer guaranteed. This affects ph…
- CVE-2024-48579CRITICALCVSS 9.8EG 9.82024-10-25
SQL Injection vulnerability in Best House rental management system project in php v.1.0 allows a remote attacker to execute arbitrary code via the username parameter of the login request.
- CVE-2024-48581CRITICALCVSS 9.8EG 9.82024-10-25
File Upload vulnerability in Best courier management system in php v.1.0 allows a remote attacker to execute arbitrary code via the admin_class.php component.
- CVE-2024-48655HIGHCVSS 8.8EG 8.82024-10-25
An issue in Total.js CMS v.1.0 allows a remote attacker to execute arbitrary code via the func.js file.
- CVE-2024-48694CRITICALCVSS 9.8EG 9.82024-11-19
File Upload vulnerability in Xi'an Daxi Information technology OfficeWeb365 v.8.6.1.0 and v7.18.23.0 allows a remote attacker to execute arbitrary code via the pw/savedraw component.
- CVE-2024-48700HIGHCVSS 7.2EG 7.22024-10-25
Kliqqi-CMS has a background arbitrary code execution vulnerability that attackers can exploit to implant backdoors or getShell via the edit_page.php component.
- CVE-2024-48744MEDIUMCVSS 6.1EG 6.12024-10-16
A Reflected Cross Site Scripting (XSS) vulnerability was found in /trms/listed- teachers.php in PHPGurukul Teachers Record Management System v2.1, which allows remote attackers to execute arbitrary code via "searchinput" POST request param…
- CVE-2024-48818CRITICALCVSS 9.8EG 9.82025-03-25
An issue in IIT Bombay, Mumbai, India Bodhitree of cs101 version allows a remote attacker to execute arbitrary code.
- CVE-2024-48829MEDIUMCVSS 6.7EG 6.72025-11-12
Dell SmartFabric OS10 Software, versions prior to 10.6.1.0, contain an Improper Control of Generation of Code ('Code Injection') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, lead…
- CVE-2024-4883CRITICALCVSS 9.8EG 9.82024-06-25
In WhatsUp Gold versions released before 2023.1.3, a Remote Code Execution issue exists in Progress WhatsUp Gold. This vulnerability allows an unauthenticated attacker to achieve the RCE as a service account through NmApi.exe.
- CVE-2024-48839CRITICALCVSS 10.0EG 10.02024-12-05
Improper Input Validation vulnerability allows Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-4884CRITICALCVSS 9.8EG 9.82024-06-25
In WhatsUp Gold versions released before 2023.1.3, an unauthenticated Remote Code Execution vulnerability in Progress WhatsUpGold. The Apm.UI.Areas.APM.Controllers.CommunityController allows execution of commands with iisapppool\nmco…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →