Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-25910 Code Injection vulnerability in Siemens Simatic PCS 7, Simatic S7-Pm and Simatic Step 7
A vulnerability has been identified in SIMATIC PCS 7 (All versions < V9.1 SP2 UC04), SIMATIC S7-PM (All versions < V5.7 SP1 HF1), SIMATIC S7-PM (All versions < V5.7 SP2 HF1), SIMATIC STEP 7 V5 (All versions < V5.7).
network
low complexity
siemens CWE-94
8.8
2023-06-12 CVE-2023-34468 Code Injection vulnerability in Apache Nifi
The DBCPConnectionPool and HikariCPConnectionPool Controller Services in Apache NiFi 0.0.2 through 1.21.0 allow an authenticated and authorized user to configure a Database URL with the H2 driver that enables custom code execution. The resolution validates the Database URL and rejects H2 JDBC locations. You are recommended to upgrade to version 1.22.0 or later which fixes this issue.
network
low complexity
apache CWE-94
8.8
2023-06-09 CVE-2023-34112 Code Injection vulnerability in Bytedeco Javacpp Presets
JavaCPP Presets is a project providing Java distributions of native C++ libraries.
network
low complexity
bytedeco CWE-94
8.8
2023-06-08 CVE-2023-29402 Code Injection vulnerability in multiple products
The go command may generate unexpected code at build time when using cgo.
network
low complexity
golang fedoraproject CWE-94
critical
9.8
2023-06-08 CVE-2023-29404 Code Injection vulnerability in multiple products
The go command may execute arbitrary code at build time when using cgo.
network
low complexity
golang fedoraproject CWE-94
critical
9.8
2023-06-07 CVE-2020-36708 Code Injection vulnerability in multiple products
The following themes for WordPress are vulnerable to Function Injections in versions up to and including Shapely <= 1.2.7, NewsMag <= 2.4.1, Activello <= 1.4.0, Illdy <= 2.1.4, Allegiant <= 1.2.2, Newspaper X <= 1.3.1, Pixova Lite <= 2.0.5, Brilliance <= 1.2.7, MedZone Lite <= 1.2.4, Regina Lite <= 2.0.4, Transcend <= 1.1.8, Affluent <= 1.1.0, Bonkers <= 1.0.4, Antreas <= 1.0.2, Sparkling <= 2.4.8, and NatureMag Lite <= 1.0.4.
network
low complexity
machothemes colorlib cpothemes CWE-94
critical
9.8
2023-06-06 CVE-2023-32540 Code Injection vulnerability in Advantech Webaccess/Scada
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
network
low complexity
advantech CWE-94
critical
9.8
2023-05-31 CVE-2022-35743 Code Injection vulnerability in Microsoft products
Microsoft Windows Support Diagnostic Tool (MSDT) Remote Code Execution Vulnerability
local
low complexity
microsoft CWE-94
7.8
2023-05-30 CVE-2023-32692 Code Injection vulnerability in Codeigniter
CodeIgniter is a PHP full-stack web framework.
network
low complexity
codeigniter CWE-94
critical
9.8
2023-05-27 CVE-2023-2928 Code Injection vulnerability in Dedecms
A vulnerability was found in DedeCMS up to 5.7.106.
network
low complexity
dedecms CWE-94
8.8