CWE-94— Improper Control of Generation of Code (Code Injection)
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.— MITRE CWE catalog
7,132 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 90 of 143
- CVE-2024-56373HIGHCVSS 8.4EG 8.42026-02-24
DAG Author (who already has quite a lot of permissions) could manipulate database of Airflow 2 in the way to execute arbitrary code in the web-server context, which they should normally not be able to do, leading to potentially remote code…
- CVE-2024-56448MEDIUMCVSS 6.7EG 6.72025-01-08
Vulnerability of improper access control in the home screen widget module Impact: Successful exploitation of this vulnerability may affect availability.
- CVE-2024-5651HIGHCVSS 8.8EG 8.82024-08-12
A flaw was found in the Fence Agents Remediation operator. This vulnerability can allow a Remote Code Execution (RCE) primitive by supplying an arbitrary command to execute in the --ssh-path/--telnet-path arguments. A low-privilege user, f…
- CVE-2024-56518CRITICALCVSS 9.8EG 9.82025-04-17
Hazelcast Management Center through 6.0 allows remote code execution via a JndiLoginModule user.provider.url in a hazelcast-client XML document (aka a client configuration file), which can be uploaded at the /cluster-connections URI.
- CVE-2024-56803MEDIUMCVSS 5.1EG 5.12024-12-31
Ghostty is a cross-platform terminal emulator. Ghostty, as allowed by default in 1.0.0, allows attackers to modify the window title via a certain character escape sequence and then insert it back to the command line in the user's terminal,…
- CVE-2024-5683CRITICALCVSS 9.8EG 9.82024-06-24
Improper Control of Generation of Code ('Code Injection') vulnerability in Next4Biz CRM & BPM Software Business Process Manangement (BPM) allows Remote Code Inclusion. This issue affects Business Process Manangement (BPM): from 6.6.4.4 be…
- CVE-2024-57061CRITICALCVSS 9.8EG 9.82025-03-19
An issue in Termius Version 9.9.0 through v.9.16.0 allows a physically proximate attacker to execute arbitrary code via the insecure Electron Fuses configuration.
- CVE-2024-57099CRITICALCVSS 9.8EG 9.82025-02-03
ClassCMS v4.8 has a code execution vulnerability. Attackers can exploit this vulnerability by constructing a payload in the classview parameter of the model management feature, allowing them to execute arbitrary code and potentially take c…
- CVE-2024-57401CRITICALCVSS 9.8EG 9.82025-02-20
SQL Injection vulnerability in Uniclare Student portal v.2 and before allows a remote attacker to execute arbitrary code via the Forgot Password function.
- CVE-2024-57487MEDIUMCVSS 6.5EG 6.52025-01-13
In Code-Projects Online Car Rental System 1.0, the file upload feature does not validate file extensions or MIME types allowing an attacker to upload a PHP shell without any restrictions and execute commands on the server.
- CVE-2024-5751CRITICALCVSS 9.8EG 9.82024-06-27
BerriAI/litellm version v1.35.8 contains a vulnerability where an attacker can achieve remote code execution. The vulnerability exists in the `add_deployment` function, which decodes and decrypts environment variables from base64 and assig…
- CVE-2024-57601MEDIUMCVSS 6.1EG 6.12025-02-12
Cross Site Scripting vulnerability in Alex Tselegidis EasyAppointments v.1.5.0 allows a remote attacker to execute arbitrary code via the legal_settings parameter.
- CVE-2024-57609HIGHCVSS 8.6EG 8.62025-02-06
An issue in Kanaries Inc Pygwalker before v.0.4.9.9 allows a remote attacker to obtain sensitive information and execute arbitrary code via the redirect_path parameter of the login redirection function.
- CVE-2024-57707CRITICALCVSS 9.8EG 9.82025-02-07
An issue in DataEase v1 allows an attacker to execute arbitrary code via the user account and password components.
- CVE-2024-58258HIGHCVSS 7.2EG 7.22025-07-13
SugarCRM before 13.0.4 and 14.x before 14.0.1 allows SSRF in the API module because a limited type of code injection can occur.
- CVE-2024-5826CRITICALCVSS 9.8EG 9.82024-06-27
In the latest version of vanna-ai/vanna, the `vanna.ask` function is vulnerable to remote code execution due to prompt injection. The root cause is the lack of a sandbox when executing LLM-generated code, allowing an attacker to manipulate…
- CVE-2024-58284HIGHCVSS 7.2EG 7.22025-12-10
PopojiCMS 2.0.1 contains an authenticated remote command execution vulnerability that allows administrative users to inject malicious PHP code through the metadata settings endpoint. Attackers can log in and modify the meta content to crea…
- CVE-2024-5834HIGHCVSS 8.8EG 8.82024-06-11
Inappropriate implementation in Dawn in Google Chrome prior to 126.0.6478.54 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)
- CVE-2024-58351CRITICALCVSS 9.8EG 9.82026-06-20
Flowise before 2.1.4 allows configuration to be injected into the Chainflow during execution via the overrideConfig option, supported in both the frontend web integration and the backend Prediction API. Because this feature is enabled by d…
- CVE-2024-5979HIGHCVSS 7.5EG 7.52024-06-27
In h2oai/h2o-3 version 3.46.0, the `run_tool` command in the `rapids` component allows the `main` function of any class under the `water.tools` namespace to be called. One such class, `MojoConvertTool`, crashes the server when invoked with…
- CVE-2024-6005LOWCVSS 3.5EG 3.52024-06-15
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the component Department Section. The manipulation of the argument Departm…
- CVE-2024-6006LOWCVSS 3.5EG 3.52024-06-15
A vulnerability was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Summer Schedule Handler. The manipulation of the argument Schedule Na…
- CVE-2024-6206HIGHCVSS 7.5EG 7.52024-06-25
A security vulnerability has been identified in HPE Athonet Mobile Core software. The core application contains a code injection vulnerability where a threat actor could execute arbitrary commands with the privilege of the underlying conta…
- CVE-2024-6344LOWCVSS 2.4EG 2.42024-06-26
A vulnerability, which was classified as problematic, was found in ZKTeco ZKBio CVSecurity V5000 4.1.0. This affects an unknown part of the component Push Configuration Section. The manipulation of the argument Configuration Name leads to …
- CVE-2024-6345HIGHCVSS 8.8EG 8.82024-07-15
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved…
- CVE-2024-6365CRITICALCVSS 9.8EG 9.82024-07-09
The Product Table by WBW plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 2.0.1 via the 'saveCustomTitle' function. This is due to missing authorization and lack of sanitization of appended …
- CVE-2024-6376HIGHCVSS 7.0EG 7.02024-07-01
MongoDB Compass may be susceptible to code injection due to insufficient sandbox protection settings with the usage of ejson shell parser in Compass' connection handling. This issue affects MongoDB Compass versions prior to version 1.42.2
- CVE-2024-6386CRITICALCVSS 9.9EG 9.92024-08-21
The WPML plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.6.12 via Twig Server-Side Template Injection. This is due to missing input validation and sanitization on the render function. Thi…
- CVE-2024-6507HIGHCVSS 8.1EG 8.12024-07-04
Command injection when ingesting a remote Kaggle dataset due to a lack of input sanitization in the ingest_kaggle() API
- CVE-2024-6596CRITICALCVSS 9.8EG 9.82024-09-10
An unauthenticated remote attacker can run malicious c# code included in curve files and execute commands in the users context.
- CVE-2024-6602CRITICALCVSS 9.8EG 9.82024-07-09
A mismatch between allocator and deallocator could have led to memory corruption. This vulnerability affects Firefox < 128, Firefox ESR < 115.13, Thunderbird < 115.13, and Thunderbird < 128.
- CVE-2024-6655HIGHCVSS 7.0EG 7.02024-07-16
A flaw was found in the GTK library. Under certain conditions, it is possible for a library to be injected into a GTK application from the current working directory.
- CVE-2024-6726HIGHCVSS 8.8EG 8.82024-07-29
Versions of Delphix Engine prior to Release 25.0.0.0 contain a flaw which results in Remote Code Execution (RCE).
- CVE-2024-6807LOWCVSS 2.4EG 2.42024-07-17
A vulnerability was found in SourceCodester Student Study Center Desk Management System 1.0 and classified as problematic. Affected by this issue is some unknown functionality of the file /sscdms/classes/Users.php?f=save of the component H…
- CVE-2024-6825HIGHCVSS 8.8EG 8.82025-03-20
BerriAI/litellm version 1.40.12 contains a vulnerability that allows remote code execution. The issue exists in the handling of the 'post_call_rules' configuration, where a callback function can be added. The provided value is split at the…
- CVE-2024-6891HIGHCVSS 8.8EG 8.82024-08-08
Attackers with a valid username and password can exploit a python code injection vulnerability during the natural login flow.
- CVE-2024-6923MEDIUMCVSS 5.5EG 5.52024-08-01
There is a MEDIUM severity vulnerability affecting CPython. The email module didn’t properly quote newlines for email headers when serializing an email message allowing for header injection when an email is serialized.
- CVE-2024-6936LOWCVSS 2.7EG 2.72024-07-21
A vulnerability, which was classified as problematic, has been found in formtools.org Form Tools 3.1.1. This issue affects some unknown processing of the file /admin/settings/index.php?page=accounts of the component Setting Handler. The ma…
- CVE-2024-6940MEDIUMCVSS 4.7EG 4.72024-07-21
A vulnerability was found in DedeCMS 5.7.114. It has been classified as critical. This affects an unknown part of the file article_template_rand.php. The manipulation leads to code injection. It is possible to initiate the attack remotely.…
- CVE-2024-6946MEDIUMCVSS 4.7EG 4.72024-07-21
A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been declared as critical. This vulnerability affects unknown code of the file /admin/pages/list. The manipulation of the argument blocks leads to code injection. The attack can …
- CVE-2024-6947MEDIUMCVSS 4.7EG 4.72024-07-21
A vulnerability was found in Flute CMS 0.2.2.4-alpha. It has been rated as critical. This issue affects the function replaceContent of the file app/Core/Support/ContentParser.php of the component Notification Handler. The manipulation lead…
- CVE-2024-6950MEDIUMCVSS 6.3EG 6.32024-07-21
A vulnerability, which was classified as critical, has been found in Prain up to 1.3.0. Affected by this issue is some unknown functionality of the file /?import of the component HTTP POST Request Handler. The manipulation of the argument …
- CVE-2024-6982HIGHCVSS 8.4EG 8.42025-03-20
A remote code execution vulnerability exists in the Calculate function of parisneo/lollms version 9.8. The vulnerability arises from the use of Python's `eval()` function to evaluate mathematical expressions within a Python sandbox that di…
- CVE-2024-6983HIGHCVSS 8.8EG 8.82024-09-27
mudler/localai version 2.17.1 is vulnerable to remote code execution. The vulnerability arises because the localai backend receives inputs not only from the configuration file but also from other inputs, allowing an attacker to upload a bi…
- CVE-2024-7093CRITICALCVSS 9.4EG 9.42024-08-01
Dispatch's notification service uses Jinja templates to generate messages to users. Jinja permits code execution within blocks, which were neither properly sanitized nor sandboxed. This vulnerability enables users to construct command line…
- CVE-2024-7094CRITICALCVSS 9.8EG 9.82024-08-13
The JS Help Desk – The Ultimate Help Desk & Support Plugin plugin for WordPress is vulnerable to PHP Code Injection leading to Remote Code Execution in all versions up to, and including, 2.8.6 via the 'storeTheme' function. This is due t…
- CVE-2024-7104CRITICALCVSS 9.8EG 9.82024-09-16
Improper Control of Generation of Code ('Code Injection') vulnerability in SFS Consulting ww.Winsure allows Code Injection. This issue affects ww.Winsure: before 4.6.2.
- CVE-2024-7218LOWCVSS 3.5EG 3.52024-07-30
A flaw has been found in SourceCodester/Campcodes School Log Management System 1.0. Affected is an unknown function of the file /admin/ajax.php?action=save_student. Executing manipulation of the argument Name can lead to cross site scripti…
- CVE-2024-7345HIGHCVSS 8.3EG 8.32024-09-03
Local ABL Client bypass of the required PASOE security checks may allow an attacker to commit unauthorized code injection into Multi-Session Agents on supported OpenEdge LTS platforms up to OpenEdge LTS 11.7.18 and LTS 12.2.13 on all suppo…
- CVE-2024-7419HIGHCVSS 8.3EG 8.32025-02-07
The WP ALL Export Pro plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 1.9.1 via the custom export fields. This is due to the missing input validation and sanitization of user-supplied data.…
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →