CWE-94— Improper Control of Generation of Code (Code Injection)
6,258 active CVEs classified under this weakness category. Sourced from NVD, GHSA, and vendor advisories. Full definition on MITRE →
CVEs classified under CWE-94page 67 of 126
- CVE-2023-36718HIGHCVSS 7.8EG 7.82023-10-10
Microsoft Virtual Trusted Platform Module Remote Code Execution Vulnerability
- CVE-2023-36789HIGHCVSS 7.2EG 7.22023-10-10
Skype for Business Remote Code Execution Vulnerability
- CVE-2023-36859HIGHCVSS 8.8EG 8.82023-07-06
PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
- CVE-2023-36923HIGHCVSS 7.8EG 7.82023-08-08
SAP SQLA for PowerDesigner 17 bundled with SAP PowerDesigner 16.7 SP06 PL03, allows an attacker with local access to the system, to place a malicious library, that can be executed by the application. An attacker could thereby control the …
- CVE-2023-36992HIGHCVSS 7.2EG 7.22023-07-07
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
- CVE-2023-37198MEDIUMCVSS 6.8EG 6.82023-07-12
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
- CVE-2023-37199MEDIUMCVSS 6.8EG 6.82023-07-12
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
- CVE-2023-37273HIGHCVSS 8.1EG 8.12023-07-13
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. Running Auto-GPT version prior to 0.4.3 by cloning the git repo and executing `docker compose run auto-gpt` in the repo root uses …
- CVE-2023-37274HIGHCVSS 7.5EG 7.52023-07-13
Auto-GPT is an experimental open-source application showcasing the capabilities of the GPT-4 language model. When Auto-GPT is executed directly on the host system via the provided run.sh or run.bat files, custom Python code execution is sa…
- CVE-2023-37424HIGHCVSS 8.1EG 8.12023-08-22
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an unauthenticated remote attacker to run arbitrary commands on the underlying host if certain preconditions outside of the attacker's…
- CVE-2023-37427HIGHCVSS 7.2EG 7.22023-08-22
A vulnerability in the web-based management interface of EdgeConnect SD-WAN Orchestrator could allow an authenticated remote attacker to run arbitrary commands on the underlying host. Successful exploitation of this vulnerability allows…
- CVE-2023-37466CRITICALCVSS 9.8EG 9.82023-07-14
vm2 is an advanced vm/sandbox for Node.js. The library contains critical security issues and should not be used for production. The maintenance of the project has been discontinued. In vm2 for versions up to 3.9.19, `Promise` handler sanit…
- CVE-2023-37470CRITICALCVSS 10.0EG 10.02023-08-04
Metabase is an open-source business intelligence and analytics platform. Prior to versions 0.43.7.3, 0.44.7.3, 0.45.4.3, 0.46.6.4, 1.43.7.3, 1.44.7.3, 1.45.4.3, and 1.46.6.4, a vulnerability could potentially allow remote code execution on…
- CVE-2023-37518MEDIUMCVSS 6.4EG 6.42024-01-30
HCL BigFix ServiceNow is vulnerable to arbitrary code injection. A malicious authorized attacker could inject arbitrary code and execute within the context of the running user.
- CVE-2023-37565HIGHCVSS 8.0EG 8.02023-07-13
Code injection vulnerability in ELECOM wireless LAN routers allows a network-adjacent authenticated attacker to execute arbitrary code by sending a specially crafted request. Affected products and versions are as follows: WRC-1167GHBK-S v1…
- CVE-2023-37582CRITICALCVSS 9.8EG 9.82023-07-12
The RocketMQ NameServer component still has a remote command execution vulnerability as the CVE-2023-33246 issue was not completely fixed in version 5.1.1. When NameServer address are leaked on the extranet and lack permission verificati…
- CVE-2023-37659CRITICALCVSS 9.8EG 9.82023-07-11
xalpha v0.11.4 is vulnerable to Remote Command Execution (RCE).
- CVE-2023-37909CRITICALCVSS 9.9EG 9.92023-10-25
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Starting in version 5.1-rc-1 and prior to versions 14.10.8 and 15.3-rc-1, any user who can edit their own user profile can execute arb…
- CVE-2023-37914CRITICALCVSS 9.9EG 9.92023-08-17
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. Any user who can view `Invitation.WebHome` can execute arbitrary script macros including Groovy and Python macros that allow remote co…
- CVE-2023-38198CRITICALCVSS 9.8EG 9.82023-07-13
acme.sh before 3.0.6 runs arbitrary commands from a remote server via eval, as exploited in the wild in June 2023.
- CVE-2023-38484HIGHCVSS 8.0EG 8.02023-09-06
Vulnerabilities exist in the BIOS implementation of Aruba 9200 and 9000 Series Controllers and Gateways that could allow an attacker to execute arbitrary code early in the boot sequence. An attacker could exploit this vulnerability to g…
- CVE-2023-38576HIGHCVSS 8.0EG 8.02023-08-18
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an authenticated user to execute arbitrary OS commands on a certain management console.
- CVE-2023-38860CRITICALCVSS 9.8EG 9.82023-08-15
An issue in LangChain v.0.0.231 allows a remote attacker to execute arbitrary code via the prompt parameter.
- CVE-2023-38877HIGHCVSS 8.8EG 8.82023-09-28
A host header injection vulnerability exists in gugoan's Economizzer v.0.9-beta1 and commit 3730880 (April 2023). By sending a specially crafted host header in the reset password request, it is possible to send password reset links to user…
- CVE-2023-38889CRITICALCVSS 9.8EG 9.82023-08-15
An issue in Alluxio v.2.9.3 and before allows an attacker to execute arbitrary code via a crafted script to the username parameter of lluxio.util.CommonUtils.getUnixGroups(java.lang.String).
- CVE-2023-38943HIGHCVSS 8.8EG 8.82023-08-05
ShuiZe_0x727 v1.0 was discovered to contain a remote command execution (RCE) vulnerability via the component /iniFile/config.ini.
- CVE-2023-39010CRITICALCVSS 9.8EG 9.82023-07-28
BoofCV 0.42 was discovered to contain a code injection vulnerability via the component boofcv.io.calibration.CalibrationIO.load. This vulnerability is exploited by loading a crafted camera calibration file.
- CVE-2023-39013CRITICALCVSS 9.8EG 9.82023-07-28
Duke v1.2 and below was discovered to contain a code injection vulnerability via the component no.priv.garshol.duke.server.CommonJTimer.init.
- CVE-2023-39015CRITICALCVSS 9.8EG 9.82023-07-28
webmagic-extension v0.9.0 and below was discovered to contain a code injection vulnerability via the component us.codecraft.webmagic.downloader.PhantomJSDownloader.
- CVE-2023-39016CRITICALCVSS 9.8EG 9.82023-07-28
bboss-persistent v6.0.9 and below was discovered to contain a code injection vulnerability in the component com.frameworkset.common.poolman.util.SQLManager.createPool. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39017CRITICALCVSS 9.8EG 9.82023-07-28
quartz-jobs 2.3.2 and below was discovered to contain a code injection vulnerability in the component org.quartz.jobs.ee.jms.SendQueueMessageJob.execute. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disp…
- CVE-2023-39018CRITICALCVSS 9.8EG 9.82023-07-28
FFmpeg 0.7.0 and below was discovered to contain a code injection vulnerability in the component net.bramp.ffmpeg.FFmpeg.<constructor>. This vulnerability is exploited via passing an unchecked argument. NOTE: this is disputed by multiple t…
- CVE-2023-39020CRITICALCVSS 9.8EG 9.82023-07-28
stanford-parser v3.9.2 and below was discovered to contain a code injection vulnerability in the component edu.stanford.nlp.io.getBZip2PipedInputStream. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39021CRITICALCVSS 9.8EG 9.82023-07-28
wix-embedded-mysql v4.6.1 and below was discovered to contain a code injection vulnerability in the component com.wix.mysql.distribution.Setup.apply. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39022CRITICALCVSS 9.8EG 9.82023-07-28
oscore v2.2.6 and below was discovered to contain a code injection vulnerability in the component com.opensymphony.util.EJBUtils.createStateless. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39023CRITICALCVSS 9.8EG 9.82023-07-28
university compass v2.2.0 and below was discovered to contain a code injection vulnerability in the component org.compass.core.executor.DefaultExecutorManager.configure. This vulnerability is exploited via passing an unchecked argument.
- CVE-2023-39059HIGHCVSS 8.8EG 8.82023-08-28
An issue in ansible semaphore v.2.8.90 allows a remote attacker to execute arbitrary code via a crafted payload to the extra variables parameter.
- CVE-2023-39157CRITICALCVSS 9.0EG 9.02023-12-31
Improper Control of Generation of Code ('Code Injection') vulnerability in Crocoblock JetElements For Elementor.This issue affects JetElements For Elementor: from n/a through 2.6.10.
- CVE-2023-39320CRITICALCVSS 9.8EG 9.82023-09-08
The go.mod toolchain directive, introduced in Go 1.21, can be leveraged to execute scripts and binaries relative to the root of the module when the "go" command was executed within the module. This applies to modules downloaded using the "…
- CVE-2023-39333MEDIUMCVSS 5.3EG 5.32024-09-07
Maliciously crafted export names in an imported WebAssembly module can inject JavaScript code. The injected code may be able to access data and functions that the WebAssembly module itself does not have access to, similar to as if the WebA…
- CVE-2023-39445HIGHCVSS 8.8EG 8.82023-08-18
Hidden functionality vulnerability in LAN-WH300N/RE all versions provided by LOGITEC CORPORATION allows an unauthenticated attacker to execute arbitrary code by sending a specially crafted file to the product's certain management console.
- CVE-2023-39469HIGHCVSS 7.2EG 7.22024-05-03
PaperCut NG External User Lookup Code Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of PaperCut NG. Authentication is required to exploit this …
- CVE-2023-39593MEDIUMCVSS 5.6EG 5.62024-10-17
Insecure permissions in the sys_exec function of MariaDB v10.5 allows authenticated attackers to execute arbitrary commands with elevated privileges. NOTE: this is disputed by the MariaDB Foundation because no privilege boundary is crossed.
- CVE-2023-39631CRITICALCVSS 9.8EG 9.82023-09-01
An issue in LanChain-ai Langchain v.0.0.245 allows a remote attacker to execute arbitrary code via the evaluate function in the numexpr library.
- CVE-2023-39660CRITICALCVSS 9.8EG 9.82023-08-21
An issue in Gaberiele Venturi pandasai v.0.8.0 and before allows a remote attacker to execute arbitrary code via a crafted request to the prompt function.
- CVE-2023-39661CRITICALCVSS 9.8EG 9.82023-08-15
An issue in pandas-ai v.0.9.1 and before allows a remote attacker to execute arbitrary code via the _is_jailbreak function.
- CVE-2023-39681CRITICALCVSS 9.8EG 9.82023-09-05
Cuppa CMS v1.0 was discovered to contain a remote code execution (RCE) vulnerability via the email_outgoing parameter at /Configuration.php. This vulnerability is triggered via a crafted payload.
- CVE-2023-39685HIGHCVSS 7.5EG 7.52023-09-01
An issue in hjson-java up to v3.0.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted JSON string.
- CVE-2023-39956MEDIUMCVSS 6.1EG 6.12023-09-06
Electron is a framework which lets you write cross-platform desktop applications using JavaScript, HTML and CSS. Electron apps that are launched as command line executables are impacted. Specifically this issue can only be exploited if t…
- CVE-2023-40050CRITICALCVSS 9.9EG 9.92023-10-31
Upload profile either through API or user interface in Chef Automate prior to and including version 4.10.29 using InSpec check command with maliciously crafted profile allows remote code execution.
Map vulnerabilities like CWE-94 to your infrastructure
EchelonGraph correlates every CVE — across CWE-94 and 150+ other weakness categories — against the assets you actually run. See blast radius, fix versions, and remediation steps in one graph.
Start Free Scan →