Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-07-08 CVE-2023-3551 Code Injection vulnerability in Teampass
Code Injection in GitHub repository nilsteampassnet/teampass prior to 3.0.10.
network
low complexity
teampass CWE-94
7.2
2023-07-07 CVE-2023-36992 Code Injection vulnerability in Travianz Project Travianz 8.3.3/8.3.4
PHP injection in TravianZ 8.3.4 and 8.3.3 in the config editor in the admin page allows remote attackers to execute PHP code.
network
low complexity
travianz-project CWE-94
7.2
2023-07-06 CVE-2023-36859 Code Injection vulnerability in Piigab M-Bus 900S Firmware
PiiGAB M-Bus SoftwarePack 900S does not correctly sanitize user input, which could allow an attacker to inject arbitrary commands.
network
low complexity
piigab CWE-94
critical
9.8
2023-07-04 CVE-2023-30990 Code Injection vulnerability in IBM I
IBM i 7.2, 7.3, 7.4, and 7.5 could allow a remote attacker to execute CL commands as QUSER, caused by an exploitation of DDM architecture.
network
low complexity
ibm CWE-94
critical
9.8
2023-06-28 CVE-2023-27866 Code Injection vulnerability in IBM Informix Jdbc Driver 4.10
IBM Informix JDBC Driver 4.10 and 4.50 is susceptible to remote code execution attack via JNDI injection when driver code or the application using the driver do not verify supplied LDAP URL in Connect String.
network
low complexity
ibm CWE-94
critical
9.8
2023-06-28 CVE-2023-36467 Code Injection vulnerability in Amazon Aws-Dataall
AWS data.all is an open source development framework to help users build a data marketplace on Amazon Web Services.
network
low complexity
amazon CWE-94
8.8
2023-06-23 CVE-2023-3393 Code Injection vulnerability in Fossbilling
Code Injection in GitHub repository fossbilling/fossbilling prior to 0.5.1.
network
low complexity
fossbilling CWE-94
7.2
2023-06-23 CVE-2023-35150 Code Injection vulnerability in Xwiki
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it.
network
low complexity
xwiki CWE-94
8.0
2023-06-23 CVE-2023-35152 Code Injection vulnerability in Xwiki
XWiki Platform is a generic wiki platform.
network
low complexity
xwiki CWE-94
8.8
2023-06-22 CVE-2023-35926 Code Injection vulnerability in Linuxfoundation Backstage
Backstage is an open platform for building developer portals.
network
low complexity
linuxfoundation CWE-94
critical
9.9