Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2022-08-17 CVE-2022-35516 Code Injection vulnerability in Dedecms
DedeCMS v5.7.93 - v5.7.96 was discovered to contain a remote code execution vulnerability in login.php.
network
low complexity
dedecms CWE-94
critical
9.8
2022-08-17 CVE-2022-36216 Code Injection vulnerability in Dedecms
DedeCMS v5.7.94 - v5.7.97 was discovered to contain a remote code execution vulnerability in member_toadmin.php.
network
low complexity
dedecms CWE-94
7.2
2022-08-16 CVE-2022-38193 Code Injection vulnerability in Esri Portal for Arcgis
There is a code injection vulnerability in Esri Portal for ArcGIS versions 10.8.1 and below that may allow a remote, unauthenticated attacker to pass strings which could potentially cause arbitrary code execution.
network
low complexity
esri CWE-94
critical
9.6
2022-08-15 CVE-2022-36262 Code Injection vulnerability in Taogogo Taocms 3.0.2
An issue was discovered in taocms 3.0.2.
network
low complexity
taogogo CWE-94
critical
9.8
2022-08-10 CVE-2022-30580 Code Injection vulnerability in Golang GO
Code injection in Cmd.Start in os/exec before Go 1.17.11 and Go 1.18.3 allows execution of any binaries in the working directory named either "..com" or "..exe" by calling Cmd.Run, Cmd.Start, Cmd.Output, or Cmd.CombinedOutput when Cmd.Path is unset.
local
low complexity
golang CWE-94
7.8
2022-08-02 CVE-2022-34625 Code Injection vulnerability in Mealie Project Mealie 1.0.0
Mealie1.0.0beta3 was discovered to contain a Server-Side Template Injection vulnerability, which allows attackers to execute arbitrary code via a crafted Jinja2 template.
network
low complexity
mealie-project CWE-94
7.2
2022-08-01 CVE-2022-36799 Code Injection vulnerability in Atlassian Jira Data Center and Jira Server
This issue exists to document that a security improvement in the way that Jira Server and Data Center use templates has been implemented.
network
low complexity
atlassian CWE-94
7.2
2022-07-30 CVE-2022-30083 Code Injection vulnerability in Elliegrid 3.4.1
EllieGrid Android Application version 3.4.1 is vulnerable to Code Injection.
network
low complexity
elliegrid CWE-94
critical
9.8
2022-07-28 CVE-2022-37009 Code Injection vulnerability in Jetbrains Intellij Idea
In JetBrains IntelliJ IDEA before 2022.2 local code execution via a Vagrant executable was possible
local
low complexity
jetbrains CWE-94
7.8
2022-07-22 CVE-2022-25759 Code Injection vulnerability in Convert-Svg-Core Project Convert-Svg-Core
The package convert-svg-core before 0.6.2 are vulnerable to Remote Code Injection via sending an SVG file containing the payload.
network
low complexity
convert-svg-core-project CWE-94
critical
9.8