İçeriğe atla
Noroxi

CWE-94 · 5.483 kayıt

Improper Control of Generation of Code ('Code Injection')

Bu sınıftaki CVE’ler

5.486 kayıt

  • Improper Control of Generation of Code in jai-ext

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    geosolutionsgroup · jai-ext13 Nis 2022

  • Craft CMS Allows Remote Code Execution

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    craftcms · craft cms25 Nis 2025

  • An issue has been discovered in GitLab CE/EE affecting all versions starting from 11.9.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %100

    gitlab · gitlab23 Nis 2021

  • HTTP.sys in Microsoft Windows 7 SP1, Windows Server 2008 R2 SP1, Windows 8, Windows 8.1, and Windows Server 2012 Gold and R2 allows remote a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    microsoft · windows 714 Nis 2015

  • Util/PHP/eval-stdin.php in PHPUnit before 4.8.28 and 5.x before 5.6.3 allows remote attackers to execute arbitrary PHP code via HTTP POST da

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    phpunit project · phpunit27 Haz 2017

  • VMware Workspace ONE Access and Identity Manager contain a remote code execution vulnerability due to server-side template injection.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · identity manager11 Nis 2022

  • In Spring Cloud Function versions 3.1.6, 3.2.2 and older unsupported versions, when using routing functionality it is possible for a user to

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring cloud function1 Nis 2022

  • Unauthenticated remote code execution

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    citrix · netscaler application delivery controller19 Tem 2023

  • vBulletin 5.x through 5.5.4 allows remote command execution via the widgetConfig[code] parameter in an ajax/render/widget_php routestring re

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vbulletin · vbulletin24 Eyl 2019

  • A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %100

    vmware · spring framework1 Nis 2022

  • Samba since version 3.5.0 and before 4.6.4, 4.5.10 and 4.4.14 is vulnerable to remote code execution vulnerability, allowing a malicious cli

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    samba · samba30 May 2017

  • The findMacroMarker function in parserLib.pas in Rejetto HTTP File Server (aks HFS or HttpFileServer) 2.3x before 2.3c allows remote attacke

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    rejetto · http file server7 Eki 2014

  • Drupal core - Highly critical - Remote Code Execution - SA-CORE-2018-004

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    drupal · drupal19 Tem 2018

  • A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code wit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    ivanti · endpoint manager cloud services appliance8 Ara 2021

  • A code injection vulnerability in the User Portal and Webadmin allows a remote attacker to execute code in Sophos Firewall version v19.0 MR1

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    sophos · firewall23 Eyl 2022

  • The Server service in Microsoft Windows 2000 SP4, XP SP2 and SP3, Server 2003 SP1 and SP2, Vista Gold and SP1, Server 2008, and 7 Pre-Beta a

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    microsoft · windows 200023 Eki 2008

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    ivanti · endpoint manager mobile29 Oca 2026

  • A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution.

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %99

    ivanti · endpoint manager mobile29 Oca 2026

  • In spring cloud gateway versions prior to 3.1.1+ and 3.0.7+ , applications are vulnerable to a code injection attack when the Gateway Actuat

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %98

    vmware · spring cloud gateway3 Mar 2022

  • Kibana versions before 5.6.15 and 6.6.1 contain an arbitrary code execution flaw in the Timelion visualizer.

    KritikCVSS 10,0KEVSilahlaştırılmışEPSS %95

    elastic · kibana25 Mar 2019

  • Ruckus Wireless Admin through 10.4 allows Remote Code Execution via an unauthenticated HTTP GET Request, as demonstrated by a /forms/doLogin

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %98

    ruckuswireless · ruckus wireless admin13 Şub 2023

  • Spring Data Commons, versions prior to 1.13 to 1.13.10, 2.0 to 2.0.5, and older unsupported versions, contain a property binder vulnerabilit

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    broadcom · spring data commons11 Nis 2018

  • Apache RocketMQ: Possible remote code execution vulnerability when using the update configuration function

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    apache · rocketmq24 May 2023

  • Static code injection vulnerability in setup.php in phpMyAdmin 2.11.x before 2.11.9.5 and 3.x before 3.1.3.1 allows remote attackers to inje

    KritikCVSS 9,8KEVSilahlaştırılmışEPSS %97

    phpmyadmin · phpmyadmin26 Mar 2009

  • RCE when PHP `register_argc_argv` config setting is enabled in craftcms/cms

    KritikCVSS 9,3KEVSilahlaştırılmışEPSS %97

    craftcms · craft cms18 Ara 2024

Tüm zafiyet sınıfları