Vulnerabilities > Improper Control of Generation of Code ('Code Injection')

DATE CVE VULNERABILITY TITLE RISK
2023-02-03 CVE-2023-24576 Code Injection vulnerability in Dell EMC Networker
EMC NetWorker may potentially be vulnerable to an unauthenticated remote code execution vulnerability in the NetWorker Client execution service (nsrexecd) irrespective of any auth used.
network
low complexity
dell CWE-94
critical
9.8
2023-02-03 CVE-2021-36424 Code Injection vulnerability in PHPwcms
An issue discovered in phpwcms 1.9.25 allows remote attackers to run arbitrary code via DB user field during installation.
network
low complexity
phpwcms CWE-94
critical
9.8
2023-02-01 CVE-2022-48093 Code Injection vulnerability in Seacms 12.7
Seacms v12.7 was discovered to contain a remote code execution (RCE) vulnerability via the ip parameter at admin_ ip.php.
network
low complexity
seacms CWE-94
7.2
2023-01-30 CVE-2022-48175 Code Injection vulnerability in Rukovoditel 3.2.1
Rukovoditel v3.2.1 was discovered to contain a remote code execution (RCE) vulnerability in the component /rukovoditel/index.php?module=dashboard/ajax_request.
network
low complexity
rukovoditel CWE-94
critical
9.8
2023-01-28 CVE-2021-4315 Code Injection vulnerability in Psiturk
A vulnerability has been found in NYUCCL psiTurk up to 3.2.0 and classified as critical.
network
low complexity
psiturk CWE-94
8.8
2023-01-26 CVE-2023-23619 Code Injection vulnerability in Lfprojects Modelina
Modelina is a library for generating data models based on inputs such as AsyncAPI, OpenAPI, or JSON Schema documents.
network
low complexity
lfprojects CWE-94
8.8
2023-01-26 CVE-2022-25894 Code Injection vulnerability in Uflo Project Uflo
All versions of the package com.bstek.uflo:uflo-core are vulnerable to Remote Code Execution (RCE) in the ExpressionContextImpl class via jexl.createExpression(expression).evaluate(context); functionality, due to improper user input validation.
network
low complexity
uflo-project CWE-94
critical
9.8
2023-01-21 CVE-2020-36655 Code Injection vulnerability in Yiiframework GII
Yii Yii2 Gii before 2.2.2 allows remote attackers to execute arbitrary code via the Generator.php messageCategory field.
network
low complexity
yiiframework CWE-94
8.8
2023-01-18 CVE-2022-34456 Code Injection vulnerability in Dell EMC Metro Node
Dell EMC Metro node, Version(s) prior to 7.1, contain a Code Injection Vulnerability.
network
low complexity
dell CWE-94
8.8
2023-01-17 CVE-2023-22731 Code Injection vulnerability in Shopware
Shopware is an open source commerce platform based on Symfony Framework and Vue js.
network
low complexity
shopware CWE-94
8.8