CWE-94
7,044 CVEs • Abstraction: Base • Likelihood of Exploit: Medium
Improper Control of Generation of Code ('Code Injection')
The product constructs all or part of a code segment using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the syntax or behavior of the intended code segment.
CVEs (7,044)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
Summit is a node web framework. When using the PouchDB driver in the module, Summit 0.1.0 and later allows an attacker to execute arbitrary commands via the collection name. |
1Huawei 201288h V5 Firmware 2288h V5 Firmware2488 V5 Firmware+17 moreJun 17, 2026 Jun 1, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to mod...Show more |
1Huawei 201288h V5 Firmware 2288h V5 Firmware2488 V5 Firmware+17 moreJun 17, 2026 Jun 1, 2018 N/A· v4 8.8 HIGH· v3 9.0 HIGH· v2 The iBMC (Intelligent Baseboard Management Controller) of some Huawei servers have a JSON injection vulnerability due to insufficient input validation. An authenticated, remote attacker can launch a JSON injection to mod...Show more |
1Reduce Css Calc Project 1Reduce Css Calc Nov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Arbitrary code execution is possible in reduce-css-calc node module <=1.2.4 through crafted css. This makes cross sites scripting (XSS) possible on the client and arbitrary code injection possible on the server and user...Show more |
An arbitrary code injection vector was found in PouchDB 6.0.4 and lesser via the map/reduce functions used in PouchDB temporary views and design documents. The code execution engine for this branch is not properly sandbo...Show more |
1Shell Quote Project 1Shell Quote Nov 21, 2024 May 31, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The npm module "shell-quote" 1.6.0 and earlier cannot correctly escape ">" and "<" operator used for redirection in shell. Applications that depend on shell-quote may also be vulnerable. A malicious user could perform co...Show more |
1Remarkable Project 1Remarkable Nov 21, 2024 May 31, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Certain input when passed into remarkable before 1.4.1 will bypass the bad protocol check that disallows the javascript: scheme allowing for javascript: url's to be injected into the rendered content. |
An issue was discovered in Moodle 3.x. A Teacher creating a Calculated question can intentionally cause remote code execution on the server, aka eval injection. |
1Pivotal Software 1Spring Security Oauth Nov 21, 2024 May 11, 2018 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Spring Security OAuth, versions 2.3 prior to 2.3.3, 2.2 prior to 2.2.2, 2.1 prior to 2.1.2, 2.0 prior to 2.0.15 and older unsupported versions contains a remote code execution vulnerability. A malicious user or attacker...Show more |
SAP MaxDB ODBC driver (all versions before 7.9.09.07) allows an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. |
Axublog 1.1.0 allows remote Code Execution as demonstrated by injection of PHP code (contained in the webkeywords parameter) into the cmsconfig.php file. |
1Redhat 2Ansible Tower CloudformsNov 21, 2024 May 2, 2018 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 Ansible Tower through version 3.2.3 has a vulnerability that allows users only with access to define variables for a job template to execute arbitrary code on the Tower server. |
Command injection vulnerability in Combodo iTop 2.4.1 allows remote authenticated administrators to execute arbitrary commands by changing the platform configuration, because web/env-production/itop-config/config.php con...Show more |
A Code Injection issue was discovered in DlgSelectMibFile.asp in Ipswitch WhatsUp Gold before 2018 (18.0). Malicious actors can inject a specially crafted SNMP MIB file that could allow them to execute arbitrary commands...Show more |
site/index.php/admin/trees/add/ in BigTree 4.2.22 and earlier allows remote attackers to upload and execute arbitrary PHP code because the BigTreeStorage class in core/inc/bigtree/apis/storage.php does not prevent upload...Show more |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 27, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In CMS Made Simple (CMSMS) through 2.2.7, the "module import" operation in the admin dashboard contains a remote code execution vulnerability, exploitable by an admin user, because an XML Package can contain base64-encod...Show more |
1Cmsmadesimple 1Cms Made Simple Nov 21, 2024 Apr 27, 2018 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 In CMS Made Simple (CMSMS) through 2.2.7, the "file unpack" operation in the admin dashboard contains a remote code execution vulnerability exploitable by an admin user because a .php file can be present in the extracted...Show more |
Cosmo 1.0.0Beta6 allows attackers to execute arbitrary PHP code via the Database Prefix field on the Database Info screen of install.php. |
1Ibm 1Qradar Security Information And Event Manager Nov 21, 2024 Apr 26, 2018 N/A· v4 5.6 MEDIUM· v3 6.8 MEDIUM· v2 IBM Security QRadar SIEM 7.2 and 7.3 could allow an unauthenticated user to execute code remotely with lower level privileges under unusual circumstances. IBM X-Force ID: 134810. |
Centers for Disease Control and Prevention MicrobeTRACE 0.1.12 allows remote attackers to execute arbitrary code, related to code injection via a crafted CSV file with an initial '><script type="text/javascript" src=' li...Show more |