CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,130 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 88 of 143
- CVE-2024-48840CRITICALCVSS 10.0EG 10.02024-12-05
Unauthorized Access vulnerabilities allow Remote Code Execution. Affected products: ABB ASPECT - Enterprise v3.08.02; NEXUS Series v3.08.02; MATRIX Series v3.08.02
- CVE-2024-4889HIGHCVSS 7.2EG 7.22024-06-06
A code injection vulnerability exists in the berriai/litellm application, version 1.34.6, due to the use of unvalidated input in the eval function within the secret management system. This vulnerability requires a valid Google KMS configur…
- CVE-2024-48908MEDIUMCVSS 6.9EG 6.92025-08-28
lychee link checking action checks links in Markdown, HTML, and text files using lychee. Prior to version 2.0.2, there is a potential attack of arbitrary code injection vulnerability in lychee-setup of the composite action at action.yml. T…
- CVE-2024-48962HIGHCVSS 8.8EG 8.82024-11-18
Improper Control of Generation of Code ('Code Injection'), Cross-Site Request Forgery (CSRF), : Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 1…
- CVE-2024-48964HIGHCVSS 7.5EG 7.52024-10-23
The package Snyk CLI before 1.1294.0 is vulnerable to Code Injection when scanning an untrusted Gradle project. The vulnerability can be triggered if Snyk test is run inside the untrusted project due to the improper handling of the current…
- CVE-2024-49048HIGHCVSS 8.1EG 8.12024-11-12
TorchGeo Remote Code Execution Vulnerability
- CVE-2024-49254CRITICALCVSS 10.0EG 10.02024-10-16
Improper Control of Generation of Code ('Code Injection') vulnerability in sunjianle ajax-extend ajax-extend allows Code Injection.This issue affects ajax-extend: from n/a through <= 1.0.
- CVE-2024-49271CRITICALCVSS 9.1EG 9.12024-10-16
Deserialization of Untrusted Data vulnerability in Unlimited Elements Unlimited Elements For Elementor (Free Widgets, Addons, Templates) unlimited-elements-for-elementor allows Command Injection.This issue affects Unlimited Elements For El…
- CVE-2024-49362HIGHCVSS 7.7EG 7.72024-11-14
Joplin is a free, open source note taking and to-do application. Joplin-desktop has a vulnerability that leads to remote code execution (RCE) when a user clicks on an <a> link within untrusted notes. The issue arises due to insufficient sa…
- CVE-2024-49375CRITICALCVSS 9.0EG 9.02025-01-14
Open source machine learning framework. A vulnerability has been identified in Rasa that enables an attacker who has the ability to load a maliciously crafted model remotely into a Rasa instance to achieve Remote Code Execution. The prereq…
- CVE-2024-49747CRITICALCVSS 9.8EG 9.82025-01-21
In gatts_process_read_by_type_req of gatt_sr.cc, there is a possible out of bounds write due to a logic error in the code. This could lead to remote code execution with no additional execution privileges needed. User interaction is not nee…
- CVE-2024-50405MEDIUMCVSS 5.5EG 5.52025-03-07
An improper neutralization of CRLF sequences ('CRLF Injection') vulnerability has been reported to affect several QNAP operating system versions. If exploited, the vulnerability could allow remote attackers who have gained administrator ac…
- CVE-2024-50450HIGHCVSS 7.3EG 7.32024-10-28
Improper Control of Generation of Code ('Code Injection') vulnerability in RealMag777 MDTF wp-meta-data-filter-and-taxonomy-filter allows Code Injection.This issue affects MDTF: from n/a through <= 1.3.3.4.
- CVE-2024-50492HIGHCVSS 8.3EG 8.32024-10-28
Improper Control of Generation of Code ('Code Injection') vulnerability in Scott Paterson ScottCart scottcart allows Code Injection.This issue affects ScottCart: from n/a through <= 1.1.
- CVE-2024-50498CRITICALCVSS 10.0EG 10.02024-10-28
Improper Control of Generation of Code ('Code Injection') vulnerability in Ajit Bohra WP Query Console wp-query-console allows Code Injection.This issue affects WP Query Console: from n/a through <= 1.0.
- CVE-2024-50611HIGHCVSS 7.2EG 7.22024-10-27
CycloneDX cdxgen through 10.10.7, when run against an untrusted codebase, may execute code contained within build-related files such as build.gradle.kts, a similar issue to CVE-2022-24441. cdxgen is used by, for example, OWASP dep-scan. NO…
- CVE-2024-50636CRITICALCVSS 9.8EG 9.82024-11-11
PyMOL 2.5.0 contains a vulnerability in its "Run Script" function, which allows the execution of arbitrary Python code embedded within .PYM files. Attackers can craft a malicious .PYM file containing a Python reverse shell payload and expl…
- CVE-2024-50658CRITICALCVSS 9.8EG 9.82025-01-07
Server-Side Template Injection (SSTI) was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the shippingAsBilling and firstname parameters in updateuserinfo.html file
- CVE-2024-50660CRITICALCVSS 9.8EG 9.82025-01-07
File Upload Bypass was found in AdPortal 3.0.39 allows a remote attacker to execute arbitrary code via the file upload functionality
- CVE-2024-50704CRITICALCVSS 10.0EG 10.02025-03-04
Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via a specially crafted HTTP POST request.
- CVE-2024-50707CRITICALCVSS 10.0EG 10.02025-03-04
Unauthenticated remote code execution vulnerability in Uniguest Tripleplay before 24.2.1 allows remote attackers to execute arbitrary code via the X-Forwarded-For header in an HTTP GET request.
- CVE-2024-50715HIGHCVSS 7.5EG 7.52024-12-27
An issue in smarts-srl.com Smart Agent v.1.1.0 allows a remote attacker to obtain sensitive information via command injection through a vulnerable unsanitized parameter defined in the /youtubeInfo.php component.
- CVE-2024-50804HIGHCVSS 7.8EG 7.82024-11-18
Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\ProgramData\MSI\One Dragon Center\Data folder
- CVE-2024-50808HIGHCVSS 8.8EG 8.82024-11-08
SeaCms 13.1 is vulnerable to code injection in the notification module of the member message notification module in the backend user module, due to unsafe handling of the "notify" variable in admin_notify.php.
- CVE-2024-5082HIGHCVSS 7.1EG 7.12024-11-14
A Remote Code Execution vulnerability has been discovered in Sonatype Nexus Repository 2. This issue affects Nexus Repository 2 OSS/Pro versions up to and including 2.15.1.
- CVE-2024-50919CRITICALCVSS 9.8EG 9.82024-11-18
Jpress until v5.1.1 has arbitrary file uploads on the windows platform, and the construction of non-standard file formats such as .jsp. can lead to arbitrary command execution
- CVE-2024-50960HIGHCVSS 7.2EG 7.22025-04-15
A command injection vulnerability in the Nmap diagnostic tool in the admin web console of Extron SMP 111 <=3.01, SMP 351 <=2.16, SMP 352 <= 2.16, and SME 211 <= 3.02, allows a remote authenticated attacker to execute arbitrary commands as …
- CVE-2024-51243HIGHCVSS 7.2EG 7.22024-10-30
The eladmin v2.7 and before contains a remote code execution (RCE) vulnerability that can control all application deployment servers of this management system via DeployController.java.
- CVE-2024-51298CRITICALCVSS 9.8EG 9.82024-10-30
In Draytek Vigor3900 1.5.1.3, attackers can inject malicious commands into mainfunction.cgi and execute arbitrary commands by calling the doGRETunnel function.
- CVE-2024-51329HIGHCVSS 8.8EG 8.82024-11-04
A Host header injection vulnerability in Agile-Board 1.0 allows attackers to obtain the password reset token via user interaction with a crafted password reset link.
- CVE-2024-51330MEDIUMCVSS 5.1EG 5.12024-11-15
An issue in UltiMaker Cura v.4.41 and 5.8.1 and before allows a local attacker to execute arbitrary code via Inter-process communication (IPC) mechanism between Cura application and CuraEngine processes, localhost network stack, printing s…
- CVE-2024-51360CRITICALCVSS 9.8EG 9.82025-05-23
An issue in Hospital Management System In PHP V4.0 allows a remote attacker to execute arbitrary code via the hms/doctor/edit-profile.php file
- CVE-2024-51367CRITICALCVSS 9.8EG 9.82024-11-21
An arbitrary file upload vulnerability in the component \Users\username.BlackBoard of BlackBoard v2.0.0.2 allows attackers to execute arbitrary code via uploading a crafted .xml file.
- CVE-2024-51424CRITICALCVSS 9.8EG 9.82024-10-30
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the Owned.setOwner function. NOTE: this is disputed by third parties because the impact is limi…
- CVE-2024-51427CRITICALCVSS 9.8EG 9.82024-10-30
An issue in the PepeGxng smart contract (which can be run on the Ethereum blockchain) allows remote attackers to have an unspecified impact via the mint function. NOTE: this is disputed by third parties because the impact is limited to fun…
- CVE-2024-51757CRITICALCVSS 9.3EG 9.32024-11-06
happy-dom is a JavaScript implementation of a web browser without its graphical user interface. Versions of happy-dom prior to 15.10.2 may execute code on the host via a script tag. This would execute code in the user context of happy-dom.…
- CVE-2024-51768HIGHCVSS 8.0EG 8.02025-07-14
An hsqldb-related remote code execution vulnerability exists in HPE AutoPass License Server (APLS) prior to 9.17.
- CVE-2024-51815CRITICALCVSS 9.0EG 9.02024-12-06
Improper Control of Generation of Code ('Code Injection') vulnerability in Cristián Lávaque s2Member s2member allows Code Injection.This issue affects s2Member: from n/a through <= 241114.
- CVE-2024-51941HIGHCVSS 8.8EG 8.82025-01-21
A remote code injection vulnerability exists in the Ambari Metrics and AMS Alerts feature, allowing authenticated users to inject and execute arbitrary code. The vulnerability occurs when processing alert definitions, where malicious in…
- CVE-2024-52393CRITICALCVSS 9.1EG 9.12024-11-14
Deserialization of Untrusted Data vulnerability in Eric Teubert Podlove Podcast Publisher podlove-podcasting-plugin-for-wordpress.This issue affects Podlove Podcast Publisher: from n/a through <= 4.1.15.
- CVE-2024-52427CRITICALCVSS 9.9EG 9.92024-11-18
Deserialization of Untrusted Data vulnerability in Vollstart Event Tickets with Ticket Scanner event-tickets-with-ticket-scanner allows Server Side Include (SSI) Injection.This issue affects Event Tickets with Ticket Scanner: from n/a thro…
- CVE-2024-52434CRITICALCVSS 9.1EG 9.12024-11-18
Deserialization of Untrusted Data vulnerability in supsystic Popup by Supsystic popup-by-supsystic allows Command Injection.This issue affects Popup by Supsystic: from n/a through <= 1.10.29.
- CVE-2024-52765CRITICALCVSS 9.8EG 9.82024-11-20
H3C GR-1800AX MiniGRW1B0V100R007 is vulnerable to remote code execution (RCE) via the aspForm parameter.
- CVE-2024-52786CRITICALCVSS 9.8EG 9.82025-08-22
An authentication bypass vulnerability in anji-plus AJ-Report up to v1.4.2 allows unauthenticated attackers to execute arbitrary code via a crafted URL.
- CVE-2024-52899HIGHCVSS 8.5EG 8.52024-11-26
IBM Data Virtualization Manager for z/OS 1.1 and 1.2 could allow an authenticated user to inject malicious JDBC URL parameters and execute code on the server.
- CVE-2024-52925MEDIUMCVSS 6.8EG 6.82025-02-26
In OPSWAT MetaDefender Kiosk before 4.7.0, arbitrary code execution can be performed by an attacker via the MD Kiosk Unlock Device feature for software encrypted USB drives.
- CVE-2024-52945HIGHCVSS 7.8EG 7.82024-11-18
An issue was discovered in Veritas NetBackup before 10.5. This only applies to NetBackup components running on a Windows Operating System. If a user executes specific NetBackup commands or an attacker uses social engineering techniques to …
- CVE-2024-52959HIGHCVSS 7.2EG 7.22024-11-27
A Improper Control of Generation of Code ('Code Injection') vulnerability in plugin management in iota C.ai Conversational Platform from 1.0.0 through 2.1.3 allows remote authenticated users to perform arbitrary system commands via a DLL f…
- CVE-2024-53268HIGHCVSS 7.2EG 7.22024-11-25
Joplin is an open source, privacy-focused note taking app with sync capabilities for Windows, macOS, Linux, Android and iOS. In affected versions attackers are able to abuse the fact that openExternal is used without any filtering of URI s…
- CVE-2024-53303HIGHCVSS 8.8EG 8.82025-04-16
A remote code execution (RCE) vulnerability in the upload_file function of LRQA Nettitude PoshC2 after commit 123db87 allows authenticated attackers to execute arbitrary code via a crafted POST request.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →