Перейти к содержимому
Noroxi

CWE-94 · 5 483 записей

Improper Control of Generation of Code ('Code Injection')

CVE этого класса

5 487 записей

  • CVE-2022-24816
    100Срочно

    Improper Control of Generation of Code in jai-ext

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    geosolutionsgroup · jai-ext13 апр. 2022 г.

  • CVE-2025-32432
    100Срочно

    Craft CMS Allows Remote Code Execution

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    craftcms · craft cms25 апр. 2025 г.

  • CVE-2021-22205
    100Срочно

    An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %

    gitlab · gitlab23 апр. 2021 г.

  • CVE-2015-1635
    99Срочно

    HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    microsoft · windows 714 апр. 2015 г.

  • CVE-2017-9841
    99Срочно

    Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    phpunit project · phpunit27 июн. 2017 г.

  • CVE-2022-22954
    99Срочно

    VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · identity manager11 апр. 2022 г.

  • CVE-2022-22963
    99Срочно

    In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · spring cloud function1 апр. 2022 г.

  • CVE-2023-3519
    99Срочно

    Unauthenticated remote code execution

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    citrix · netscaler application delivery controller19 июл. 2023 г.

  • CVE-2019-16759
    99Срочно

    vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vbulletin · vbulletin24 сент. 2019 г.

  • CVE-2022-22965
    99Срочно

    A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %

    vmware · spring framework1 апр. 2022 г.

  • CVE-2017-7494
    99Срочно

    Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    samba · samba30 мая 2017 г.

  • CVE-2014-6287
    99Срочно

    The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attacke

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    rejetto · http file server7 окт. 2014 г.

  • CVE-2018-7602
    99Срочно

    Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    drupal · drupal19 июл. 2018 г.

  • CVE-2021-44529
    99Срочно

    A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager cloud services appliance8 дек. 2021 г.

  • CVE-2022-3236
    99Срочно

    A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    sophos · firewall23 сент. 2022 г.

  • CVE-2008-4250
    99Срочно

    The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    microsoft · windows 200023 окт. 2008 г.

  • CVE-2026-1281
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2026-1340
    99Срочно

    A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %

    ivanti · endpoint manager mobile29 янв. 2026 г.

  • CVE-2022-22947
    99Срочно

    In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %

    vmware · spring cloud gateway3 мар. 2022 г.

  • CVE-2019-7609
    99Срочно

    Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %

    elastic · kibana25 мар. 2019 г.

  • CVE-2023-25717
    98Срочно

    Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %

    ruckuswireless · ruckus wireless admin13 февр. 2023 г.

  • CVE-2018-1273
    98Срочно

    Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    broadcom · spring data commons11 апр. 2018 г.

  • CVE-2023-33246
    98Срочно

    Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    apache · rocketmq24 мая 2023 г.

  • CVE-2009-1151
    98Срочно

    Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %

    phpmyadmin · phpmyadmin26 мар. 2009 г.

  • CVE-2024-56145
    96Срочно

    RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms

    КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 97 %

    craftcms · craft cms18 дек. 2024 г.

Все классы уязвимостей