CWE-94 · 5 483 записей
Improper Control of Generation of Code ('Code Injection')
CVE этого класса
5 487 записей
| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2022-24816Готовый эксплойт | Improper Control of Generation of Code in jai-extgeosolutionsgroup · jai-ext · CWE-94 | Критическая10,0 | KEV | 99,9 % | 13 апр. 2022 г. |
100Срочно | CVE-2025-32432Готовый эксплойт | Craft CMS Allows Remote Code Executioncraftcms · craft cms · CWE-94 | Критическая10,0 | KEV | 99,8 % | 25 апр. 2025 г. |
100Срочно | CVE-2021-22205Готовый эксплойт | An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.gitlab · gitlab · CWE-94 | Критическая10,0 | KEV | 99,7 % | 23 апр. 2021 г. |
99Срочно | CVE-2015-1635Готовый эксплойт | HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote amicrosoft · windows 7 · CWE-94 | Критическая9,8 | KEV | 100,0 % | 14 апр. 2015 г. |
99Срочно | CVE-2017-9841Готовый эксплойт | Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST daphpunit project · phpunit · CWE-94 | Критическая9,8 | KEV | 100,0 % | 27 июн. 2017 г. |
99Срочно | CVE-2022-22954Готовый эксплойт | VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.vmware · identity manager · CWE-94 | Критическая9,8 | KEV | 100,0 % | 11 апр. 2022 г. |
99Срочно | CVE-2022-22963Готовый эксплойт | In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user tovmware · spring cloud function · CWE-94 | Критическая9,8 | KEV | 99,9 % | 1 апр. 2022 г. |
99Срочно | CVE-2023-3519Готовый эксплойт | Unauthenticated remote code executioncitrix · netscaler application delivery controller · CWE-94 | Критическая9,8 | KEV | 99,7 % | 19 июл. 2023 г. |
99Срочно | CVE-2019-16759Готовый эксплойт | vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring revbulletin · vbulletin · CWE-94 | Критическая9,8 | KEV | 99,7 % | 24 сент. 2019 г. |
99Срочно | CVE-2022-22965Готовый эксплойт | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.vmware · spring framework · CWE-94 | Критическая9,8 | KEV | 99,6 % | 1 апр. 2022 г. |
99Срочно | CVE-2017-7494Готовый эксплойт | Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious clisamba · samba · CWE-94 | Критическая9,8 | KEV | 99,4 % | 30 мая 2017 г. |
99Срочно | CVE-2014-6287Готовый эксплойт | The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attackerejetto · http file server · CWE-94 | Критическая9,8 | KEV | 99,3 % | 7 окт. 2014 г. |
99Срочно | CVE-2018-7602Готовый эксплойт | Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004drupal · drupal · CWE-94 | Критическая9,8 | KEV | 99,2 % | 19 июл. 2018 г. |
99Срочно | CVE-2021-44529Готовый эксплойт | A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code witivanti · endpoint manager cloud services appliance · CWE-94 | Критическая9,8 | KEV | 99,1 % | 8 дек. 2021 г. |
99Срочно | CVE-2022-3236Готовый эксплойт | A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1sophos · firewall · CWE-94 | Критическая9,8 | KEV | 98,9 % | 23 сент. 2022 г. |
99Срочно | CVE-2008-4250Готовый эксплойт | The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta amicrosoft · windows 2000 · CWE-94 | Критическая9,8 | KEV | 98,8 % | 23 окт. 2008 г. |
99Срочно | CVE-2026-1281Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,7 % | 29 янв. 2026 г. |
99Срочно | CVE-2026-1340Готовый эксплойт | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.ivanti · endpoint manager mobile · CWE-94 | Критическая9,8 | KEV | 98,6 % | 29 янв. 2026 г. |
99Срочно | CVE-2022-22947Готовый эксплойт | In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuatvmware · spring cloud gateway · CWE-94 | Критическая10,0 | KEV | 98,3 % | 3 мар. 2022 г. |
99Срочно | CVE-2019-7609Готовый эксплойт | Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.elastic · kibana · CWE-94 | Критическая10,0 | KEV | 95,3 % | 25 мар. 2019 г. |
98Срочно | CVE-2023-25717Готовый эксплойт | Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLoginruckuswireless · ruckus wireless admin · CWE-94 | Критическая9,8 | KEV | 98,1 % | 13 февр. 2023 г. |
98Срочно | CVE-2018-1273Готовый эксплойт | Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilitbroadcom · spring data commons · CWE-94 | Критическая9,8 | KEV | 97,0 % | 11 апр. 2018 г. |
98Срочно | CVE-2023-33246Готовый эксплойт | Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration functionapache · rocketmq · CWE-94 | Критическая9,8 | KEV | 96,6 % | 24 мая 2023 г. |
98Срочно | CVE-2009-1151Готовый эксплойт | Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to injephpmyadmin · phpmyadmin · CWE-94 | Критическая9,8 | KEV | 96,6 % | 26 мар. 2009 г. |
96Срочно | CVE-2024-56145Готовый эксплойт | RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cmscraftcms · craft cms · CWE-94 | Критическая9,3 | KEV | 97,4 % | 18 дек. 2024 г. |
- CVE-2022-24816100Срочно
Improper Control of Generation of Code in jai-ext
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %geosolutionsgroup · jai-ext13 апр. 2022 г.
- CVE-2025-32432100Срочно
Craft CMS Allows Remote Code Execution
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %craftcms · craft cms25 апр. 2025 г.
- CVE-2021-22205100Срочно
An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %gitlab · gitlab23 апр. 2021 г.
- CVE-2015-163599Срочно
HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %microsoft · windows 714 апр. 2015 г.
- CVE-2017-984199Срочно
Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %phpunit project · phpunit27 июн. 2017 г.
- CVE-2022-2295499Срочно
VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · identity manager11 апр. 2022 г.
- CVE-2022-2296399Срочно
In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring cloud function1 апр. 2022 г.
- CVE-2023-351999Срочно
Unauthenticated remote code execution
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %citrix · netscaler application delivery controller19 июл. 2023 г.
- CVE-2019-1675999Срочно
vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vbulletin · vbulletin24 сент. 2019 г.
- CVE-2022-2296599Срочно
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 100 %vmware · spring framework1 апр. 2022 г.
- CVE-2017-749499Срочно
Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %samba · samba30 мая 2017 г.
- CVE-2014-628799Срочно
The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attacke
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %rejetto · http file server7 окт. 2014 г.
- CVE-2018-760299Срочно
Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %drupal · drupal19 июл. 2018 г.
- CVE-2021-4452999Срочно
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager cloud services appliance8 дек. 2021 г.
- CVE-2022-323699Срочно
A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %sophos · firewall23 сент. 2022 г.
- CVE-2008-425099Срочно
The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %microsoft · windows 200023 окт. 2008 г.
- CVE-2026-128199Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2026-134099Срочно
A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 99 %ivanti · endpoint manager mobile29 янв. 2026 г.
- CVE-2022-2294799Срочно
In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 98 %vmware · spring cloud gateway3 мар. 2022 г.
- CVE-2019-760999Срочно
Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 95 %elastic · kibana25 мар. 2019 г.
- CVE-2023-2571798Срочно
Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 98 %ruckuswireless · ruckus wireless admin13 февр. 2023 г.
- CVE-2018-127398Срочно
Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %broadcom · spring data commons11 апр. 2018 г.
- CVE-2023-3324698Срочно
Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %apache · rocketmq24 мая 2023 г.
- CVE-2009-115198Срочно
Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 97 %phpmyadmin · phpmyadmin26 мар. 2009 г.
- CVE-2024-5614596Срочно
RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms
КритическаяCVSS 9,3KEVГотовый эксплойтEPSS 97 %craftcms · craft cms18 дек. 2024 г.