Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-06-20 CVE-2020-20918 Code Injection vulnerability in Pluck-Cms Pluck 4.7.10
An issue discovered in Pluck CMS v.4.7.10-dev2 allows a remote attacker to execute arbitrary php code via the hidden parameter to admin.php when editing a page.
network
low complexity
pluck-cms CWE-94
7.2
2023-06-19 CVE-2023-2359 Code Injection vulnerability in Themepunch Slider Revolution
The Slider Revolution WordPress plugin through 6.6.12 does not check for valid image files upon import, leading to an arbitrary file upload which may be escalated to Remote Code Execution in some server configurations.
network
low complexity
themepunch CWE-94
8.8
2023-06-14 CVE-2023-34253 Code Injection vulnerability in Getgrav Grav
Grav is a flat-file content management system.
network
low complexity
getgrav CWE-94
7.2
2023-06-14 CVE-2023-34448 Code Injection vulnerability in Getgrav Grav
Grav is a flat-file content management system.
network
low complexity
getgrav CWE-94
7.2
2023-06-14 CVE-2023-34251 Code Injection vulnerability in Getgrav Grav
Grav is a flat-file content management system.
network
low complexity
getgrav CWE-94
7.2
2023-06-14 CVE-2023-34252 Code Injection vulnerability in Getgrav Grav
Grav is a flat-file content management system.
network
low complexity
getgrav CWE-94
7.2
2023-06-14 CVE-2023-1049 Code Injection vulnerability in Schneider-Electric products
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause execution of malicious code when an unsuspicious user loads a project file from the local filesystem into the HMI.
local
low complexity
schneider-electric CWE-94
7.8
2023-06-13 CVE-2023-3224 Code Injection vulnerability in Nuxt 3.4.0/3.4.1/3.4.2
Code Injection in GitHub repository nuxt/nuxt prior to 3.5.3.
network
low complexity
nuxt CWE-94
critical
9.8
2023-06-13 CVE-2023-30179 Code Injection vulnerability in Craftcms Craft CMS 3.7.59
CraftCMS version 3.7.59 is vulnerable to Server-Side Template Injection (SSTI).
network
low complexity
craftcms CWE-94
7.2
2023-06-13 CVE-2023-32546 Code Injection vulnerability in Chatwork 2.6.43
Code injection vulnerability exists in Chatwork Desktop Application (Mac) 2.6.43 and earlier.
local
low complexity
chatwork CWE-94
4.4