Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-04-16 CVE-2023-29211 Code Injection vulnerability in Xwiki
XWiki Commons are technical libraries common to several other top level XWiki projects.
network
low complexity
xwiki CWE-94
8.8
2023-04-16 CVE-2023-29212 Code Injection vulnerability in Xwiki
XWiki Commons are technical libraries common to several other top level XWiki projects.
network
low complexity
xwiki CWE-94
8.8
2023-04-16 CVE-2023-29214 Code Injection vulnerability in Xwiki
XWiki Commons are technical libraries common to several other top level XWiki projects.
network
low complexity
xwiki CWE-94
8.8
2023-04-15 CVE-2020-29007 Code Injection vulnerability in Mediawiki Score 0.3.0
The Score extension through 0.3.0 for MediaWiki has a remote code execution vulnerability due to improper sandboxing of the GNU LilyPond executable.
network
low complexity
mediawiki CWE-94
critical
9.8
2023-04-15 CVE-2023-29209 Code Injection vulnerability in Xwiki
XWiki Commons are technical libraries common to several other top level XWiki projects.
network
low complexity
xwiki CWE-94
8.8
2023-04-15 CVE-2023-29210 Code Injection vulnerability in Xwiki
XWiki Commons are technical libraries common to several other top level XWiki projects.
network
low complexity
xwiki CWE-94
8.8
2023-04-14 CVE-2023-2056 Code Injection vulnerability in Dedecms
A vulnerability was found in DedeCMS up to 5.7.87 and classified as critical.
network
low complexity
dedecms CWE-94
critical
9.8
2023-04-11 CVE-2023-29492 Code Injection vulnerability in 3Rdmill Novi Survey
Novi Survey before 8.9.43676 allows remote attackers to execute arbitrary code on the server in the context of the service account.
network
low complexity
3rdmill CWE-94
critical
9.8
2023-04-11 CVE-2023-27897 Code Injection vulnerability in SAP Customer Relationship Management
In SAP CRM - versions 700, 701, 702, 712, 713, an attacker who is authenticated with a non-administrative role and a common remote execution authorization can use a vulnerable interface to execute an application function to perform actions which they would not normally be permitted to perform.
network
low complexity
sap CWE-94
6.3
2023-04-07 CVE-2023-1947 Code Injection vulnerability in Taogogo Taocms 3.0.2
A vulnerability was found in taoCMS 3.0.2.
network
low complexity
taogogo CWE-94
critical
9.8